Diagnoses and resolves Google Cloud Filestore client mount failures, permission errors (EACCES), and network timeouts (ETIMEDOUT). Use when an NFS mount hangs o
复制下面这句话,粘贴给 Claude Code、Codex、Cursor 等 AI 编程工具,它会读取安装说明并在你确认后完成安装。
请阅读 https://ai.atlankj.com/install/asset/gh-google-cloud-filestore-log-troubleshooting-d4f09139d689 ,按照其中的说明把「google-cloud-filestore-log-troubleshooting」安装到你(当前 AI 工具)中。执行前先告诉我将运行的命令和写入的位置,等我确认。
查看 AI 将读取的安装说明正在读取 GitHub 原文…
内容来自 GitHub 原始文件,由原作者维护。在 GitHub 查看
Diagnoses, troubleshoots, and remediates Google Cloud Filestore client mount failures, permission errors (EACCES), and network timeouts (ETIMEDOUT) across projects.
Required IAM roles on target project(s) (and Shared VPC host project if applicable):
roles/file.viewer (instance & export ACLs), roles/compute.networkViewer (VPC firewall rules), roles/logging.viewer (Cloud Audit & GKE CSI logs), roles/mcp.toolUser (if using MCP tools).roles/file.editor (export ACL updates), roles/compute.securityAdmin (firewall rule creation).Authenticate, verify billing/APIs, and configure your environment:
gcloud auth login && gcloud auth application-default login
gcloud billing projects describe {project_id} --format="value(billingEnabled)"
gcloud services enable file.googleapis.com compute.googleapis.com logging.googleapis.com --quiet
gcloud config set project {project_id} && gcloud config set compute/region {region}
Prefix every gcloud command provided or executed with the skill metrics environment:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud filestore instances describe ...
On direct REST API calls, append HTTP header: User-Agent: gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting).
For purely conceptual, architectural, or educational questions (e.g., "What causes EACCES on Filestore?", "Why does GKE Node IP appear instead of Pod IP?", "What ports does Filestore require?", "Explain root squash"):
If the user prompt contains constraints like "Do not execute commands", "without executing", or "read-only":
run_command to execute any shell, Python, or gcloud commands.get_instance, list_instances) are available and use them (API calls, not command executions).references/mock-fleet-data.md only if the requested instance matches one of the evaluation scenarios (finance-share, shared-nfs, ml-data, data-hub, prod-share). Never report mock data as live production state. If the instance is not listed there, state that live access is required and provide the exact commands for the user to run.references/mock-fleet-data.md, stop reading additional files immediately and formulate your response. Do NOT read scripts/quick_diagnose.py, scripts/diagnose_lib.py, _internal/quick_diagnose_test.py, or EVAL.* files when command execution is disabled, as inspecting code/test files wastes turns and triggers timeouts.[rule_name]? Please confirm to proceed.").# Single instance diagnosis
python3 scripts/quick_diagnose.py --instance="<INSTANCE_ID>" --location="<LOCATION_OR_ZONE>" \
[--project="<PROJECT_ID>"] [--client-ip="<CLIENT_IP>"] [--client-subnet="<CLIENT_SUBNET_CIDR>"]
# Bulk project-wide fleet diagnosis
python3 scripts/quick_diagnose.py --all --project="<PROJECT_ID>" [--json]
| Flag | Purpose |
|---|---|
--instance, --location | Filestore instance ID and region/zone (--zone is a legacy alias). Required unless --all. |
--project | GCP project ID (defaults to active gcloud project). |
--client-ip / --client-subnet | Client IP or CIDR to evaluate against export ACLs and ingress firewall rules. |
--json | Emit machine-readable JSON on stdout (narrative report goes to stderr). |
--apply-fix | Execute generated remediation commands. Only pass after explicit user confirmation. |
gcloud CLIget_instance(name='projects/{project_id}/locations/{location}/instances/{instance_id}') and inspect fileShares[0].nfsExportOptions and networks[0].network.call_gcp_api): Invoke service="file", version="v1", resource_path="projects/{project_id}/locations/{location}/instances/{instance_id}".gcloud:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud filestore instances describe {instance_id} --location={location} --project={project_id} --format=json
instance, location (region/zone), project, and client_ip / client_subnet. If target parameters are missing, list instances or ask the user to confirm.10.4.0.0/14) are allowlisted, the NFS server sees traffic originating from the GKE Node Internal IP. Always evaluate and allowlist the GKE Node Subnet CIDR in nfsExportOptions and VPC firewall rules.state is READY (report state blocker if CREATING, DELETING, or ERROR).networks[0].ipAddresses[0]) and VPC network URI.networks[0].network references projects/{host_project}/global/networks/{network}, resolve {host_project} as the Shared VPC host project for firewall queries.EACCES vs EROFS)fileShares[0].nfsExportOptions (if empty, default 0.0.0.0/0 READ_WRITE NO_ROOT_SQUASH applies).EACCES (Permission Denied by Server): Triggered when the client IP or subnet CIDR is not covered by any ipRanges entry.
nfsExportOptions, preserving all existing export rules to avoid breaking active mounts.EROFS (Read-only file system): Triggered when accessMode is READ_ONLY but client writes are attempted.ETIMEDOUT)ETIMEDOUT (Connection Timed Out): Triggered when priority-sorted ingress rules block or fail to allow TCP port 2049 (NFS) and TCP/UDP port 111 (rpcbind) from the client CIDR.
ALLOW tcp:2049,udp:2049,tcp:111,udp:111) from the client subnet CIDR.Query Cloud Audit Admin Activity logs (file.googleapis.com) over the past 24 hours to check if an UpdateInstance operation modified export ACLs or networks:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud logging read 'logName="projects/{project_id}/logs/cloudaudit.googleapis.com%2Factivity" AND protoPayload.serviceName="file.googleapis.com" AND protoPayload.resourceName=~".*{instance}.*"' \
--project="{project_id}" --freshness="1d" --limit=5 --format="json"
cloudaudit.googleapis.com%2Factivity in logName so read-only GetInstance/ListInstances calls (data_access) are not falsely flagged as administrative drift.UpdateInstance events explain when and by whom (principalEmail, timestamp) configuration changed, but only a failed export ACL or firewall check constitutes a mount blocker.--all), issue a single project-wide audit log query rather than per-instance queries in a loop.resource.labels.container_name="gcp-filestore-driver" (severity>=ERROR) for client-side mount errors.Every diagnostic report MUST include a structured summary table and root cause analysis:
### Filestore Diagnostic Report: `[instance-name]`
| Parameter | Value |
| :--- | :--- |
| **Instance ID** | `[instance-name]` (`[location]`, Tier: `[tier]`, State: `READY`) |
| **Filestore IP & Network** | `[filestore-ip]` on VPC `[network-name]` (Host Project: `[host-project]`) |
| **Port 2049 & Export ACL** | Port 2049: `OPEN / BLOCKED` \| Export ACL: `PASS / REJECTED` |
| **Diagnostic Verdict** | **HEALTHY** or **BLOCKED: [Root Cause]** |
#### Root Cause Analysis & Recommended Remediation
- [Explanation of ETIMEDOUT (missing firewall rule on port 2049) vs EACCES (missing export ACL rule) and any recent UpdateInstance audit drift]
```bash
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud compute firewall-rules create ...
```
"Would you like me to proceed with executing this remediation command for you? Please confirm to proceed."
scripts/quick_diagnose.py & scripts/diagnose_lib.py: Zero-dependency CLI runner and pure-Python evaluation engine.