Agent skill

Collecting Cockroachdb Operator Escalation Packet

by cockroachdb in cockroachdb/helm-charts

Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…

Apache-2.0Auto-check passedDevOps & Cloud

Install Collecting Cockroachdb Operator Escalation Packet

skills CLI
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .claude/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
collecting-cockroachdb-operator-escalation-packet
GitHub stars
105
Token cost
~5.1k tokens
SKILL.md length
876 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…

  • Works in 7 steps: Context and Version Inventory → Resource Specifications and Status → Logs → …
  • General diagnosis cannot resolve an operator-managed CockroachDB Helm issue
  • SKILL.md covers When to Use This Skill, Safety Considerations, Execution Discipline and Required Inputs, plus 9 more sections
  • Calls kubectl, jq and curl

What it does

Collecting Cockroachdb Operator Escalation Packet is an agent skill from cockroachdb/helm-charts. Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps, metrics, and a customer action timeline. Use when general diagnosis cannot resolve an operator-managed CockroachDB Helm issue or before restarting a stuck operator.

Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and…

It sits in DevOps & Cloud, covering Container orchestration and Async programming. It works with Kubernetes. The repository describes itself as: Helm charts for cockroachdb. The licence is Apache-2.0.

When your agent uses it

  • General diagnosis cannot resolve an operator-managed CockroachDB Helm issue
  • Before restarting a stuck operator

Example prompts

  • “Use the collecting-cockroachdb-operator-escalation-packet skill to collect a complete CockroachDB Operator escalation packet for TSC/TSE or…”
  • “/collecting-cockroachdb-operator-escalation-packet”

Requirements

  • Compatibility (from SKILL.md): CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and CockroachDB namespace; pprof and metrics collection require port-forward access to the operator Deployment.

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Context and Version Inventory
  2. Resource Specifications and Status
  3. Logs
  4. Operation-Specific Evidence
  5. Operator pprof and Metrics
  6. Timeline
  7. Escalation Summary

What it can do on your machine

Read from SKILL.md and the folder at commit 26e44ff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • jq
    • curl
    • helm
    • node
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, curl and helm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and CockroachDB namespace; pprof and metrics collection require port-forward access to the operator Deployment.

    From compatibility in the SKILL.md frontmatter.

Context cost

Collecting Cockroachdb Operator Escalation Packet loads about 5.1k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 876 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cockroachdb/helm-charts at commit 26e44ff, republished under its Apache-2.0 licence (© cockroachdb). 876 words, ~5,114 tokens.

Download SKILL.mdSave it as .claude/skills/collecting-cockroachdb-operator-escalation-packet/SKILL.md (or your agent's skills folder).
name
collecting-cockroachdb-operator-escalation-packet
description
Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps, metrics, and a customer action timeline. Use when general diagnosis cannot resolve an operator-managed CockroachDB Helm issue or before restarting a stuck operator.
compatibility
CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and CockroachDB namespace; pprof and metrics collection require port-forward access to the operator Deployment.
metadata.author
cockroachdb
metadata.version
1.0

Collecting CockroachDB Operator Escalation Packet

Collects the artifacts needed for TSC/TSE or operator-team escalation. Use this after basic diagnosis identifies an unresolved operator, Kubernetes, migration, upgrade, scale, DNS, PVC, or certificate issue. Keep collection read-only unless the customer explicitly approves a mitigation.

When to Use This Skill

  • A customer needs to escalate an operator-managed CockroachDB Helm issue to TSC
  • The operator is running but not reconciling and logs/status do not explain why
  • A rollout, upgrade, migration, or scale operation is stuck
  • Operator logs do not explain the failure
  • TSC needs consistent artifacts before advising restart, rollback, manual decommission, or status repair

Safety Considerations

  • Collect this packet before restarting, scaling, or deleting the operator during active operations.
  • Do not delete CrdbNode, PVC, Secret, service, version checker job, or StatefulSet resources while collecting data.
  • Do not print private key contents. Collect only Secret names, keys, certificate metadata, expiry, issuer, subject, and SANs.
  • Do not manually edit CrdbCluster.status.
  • Do not run cockroach init on an existing cluster.
  • If the operator is paused or disabled, record that state before changing anything.

Execution Discipline

  • Execute one step at a time and inspect the output before moving on. Do not run the packet collection in parallel; earlier results determine which operation-specific sections are relevant.
  • Run every step in the same shell session. Packet collection depends on OPERATOR_NAMESPACE, CRDB_NAMESPACE, CRDBCLUSTER, and the CRDB_*_PATH exports set in Step 1; opening a new shell drops those variables and downstream jq/kubectl calls will read from the wrong object or emit empty artifacts.
  • Keep collection read-only unless the user explicitly approves a mutating action for the target cluster.
  • Never infer a CrdbCluster object name from a Helm release, service name, or CockroachDB image/version string. List CrdbCluster objects and use the exact metadata.name.
  • Before reading version-sensitive CrdbCluster fields, save the live CRD YAML and derive field paths from the served CRD schema for the object's apiVersion.
  • Do not run interactive kubectl exec shells, kubectl debug, port-forwards, pprof/metrics collection, or commands that use external images in production unless the user approves them. If impact or policy is unclear, involve TSE or the operator team first.
  • Do not patch, annotate, delete, restart, scale, drain, decommission, or run helm upgrade as part of packet collection.

Required Inputs

  • Operator namespace and Helm release
  • CockroachDB namespace, Helm release, and discovered CrdbCluster.metadata.name
  • Kubernetes context and cluster/provider
  • Current operation: install, upgrade, scale up/down, cert rotation, migration, routine maintenance, or recovery
  • Current and target CockroachDB image, if an upgrade is involved
  • Customer timeline: what changed, what commands were run, and what was already tried

Packet Layout

Ask the customer to gather outputs into a single directory:

bash
mkdir -p crdb-operator-escalation

Use clear filenames, for example operator-logs.txt, crdbcluster.yaml, events.txt, goroutine_dump.txt, and metrics_dump.txt.

Step 1: Context and Version Inventory

bash
export OPERATOR_NAMESPACE="<operator-namespace>"
export OPERATOR_RELEASE="<operator-release>"
export CRDB_NAMESPACE="<cockroachdb-namespace>"
export CRDB_HELM_RELEASE="<cockroachdb-release>"

kubectl config current-context > crdb-operator-escalation/kube-context.txt
kubectl version --short > crdb-operator-escalation/kubernetes-version.txt

helm -n "$OPERATOR_NAMESPACE" status "$OPERATOR_RELEASE" > crdb-operator-escalation/operator-helm-status.txt 2>&1 || true
helm -n "$OPERATOR_NAMESPACE" history "$OPERATOR_RELEASE" > crdb-operator-escalation/operator-helm-history.txt 2>&1 || true
helm -n "$CRDB_NAMESPACE" status "$CRDB_HELM_RELEASE" > crdb-operator-escalation/crdb-helm-status.txt 2>&1 || true
helm -n "$CRDB_NAMESPACE" history "$CRDB_HELM_RELEASE" > crdb-operator-escalation/crdb-helm-history.txt 2>&1 || true

kubectl -n "$OPERATOR_NAMESPACE" get deploy cockroach-operator -o jsonpath='{.spec.template.spec.containers[0].image}{"\n"}' > crdb-operator-escalation/operator-image.txt
kubectl get crd crdbclusters.crdb.cockroachlabs.com crdbnodes.crdb.cockroachlabs.com -o wide > crdb-operator-escalation/crds.txt
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o yaml > crdb-operator-escalation/crdbclusters-crd.yaml
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o json > crdb-operator-escalation/crdbclusters-crd.json
kubectl get crd crdbnodes.crdb.cockroachlabs.com -o yaml > crdb-operator-escalation/crdbnodes-crd.yaml

kubectl -n "$CRDB_NAMESPACE" get crdbcluster -o json | jq -r '
  .items[]
  | [.metadata.name, .apiVersion, (.metadata.labels["app.kubernetes.io/instance"] // ""), (.metadata.generation | tostring)]
  | @tsv
' > crdb-operator-escalation/crdbcluster-candidates.tsv

Inspect crdbcluster-candidates.tsv. If it is empty, stop object-specific packet collection and report that no live CrdbCluster exists in the namespace. You may collect CrdbNode owner references and labels as teardown evidence, but do not treat those values as a replacement for a discovered CrdbCluster. If more than one CrdbCluster exists in the namespace, select the target by metadata.name; do not use a CockroachDB version or image tag as the object name.

bash
export CRDBCLUSTER="<metadata.name-from-crdbcluster-candidates.tsv>"
test -n "$CRDBCLUSTER"

kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o yaml > crdb-operator-escalation/crdbcluster.yaml
kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o json > crdb-operator-escalation/crdbcluster.json

export CRDBCLUSTER_API_VERSION="$(jq -r '.apiVersion | split("/")[-1]' crdb-operator-escalation/crdbcluster.json)"
export CRDBCLUSTER_SCHEMA_JSON=crdb-operator-escalation/crdbcluster-schema.json
jq -e --arg version "$CRDBCLUSTER_API_VERSION" '
  .spec.versions[] | select(.name == $version) | .schema.openAPIV3Schema
' crdb-operator-escalation/crdbclusters-crd.json > "$CRDBCLUSTER_SCHEMA_JSON"

crdb_schema_has() {
  jq -e --arg path "$1" '
    def has_schema_path($schema; $parts):
      if ($parts | length) == 0 then true
      elif (($schema.properties? // {}) | has($parts[0])) then
        has_schema_path($schema.properties[$parts[0]]; $parts[1:])
      else false
      end;
    has_schema_path(.; $path | split("."))
  ' "$CRDBCLUSTER_SCHEMA_JSON" >/dev/null
}

crdb_first_schema_path() {
  for schema_path in "$@"; do
    if crdb_schema_has "$schema_path"; then
      printf '%s\n' "$schema_path"
      return 0
    fi
  done
  printf '\n'
}

export CRDB_MODE_PATH="$(crdb_first_schema_path spec.mode)"
export CRDB_REGIONS_PATH="$(crdb_first_schema_path spec.regions)"
export CRDB_DESIRED_IMAGE_PATH="$(crdb_first_schema_path spec.template.spec.image spec.image.name spec.image)"
export CRDB_OBSERVED_GENERATION_PATH="$(crdb_first_schema_path status.observedGeneration)"
export CRDB_RECONCILED_PATH="$(crdb_first_schema_path status.reconciled)"
export CRDB_READY_NODES_PATH="$(crdb_first_schema_path status.readyNodes)"
export CRDB_STATUS_IMAGE_PATH="$(crdb_first_schema_path status.image status.crdbcontainerimage)"
export CRDB_STATUS_VERSION_PATH="$(crdb_first_schema_path status.version)"
export CRDB_ACTIONS_PATH="$(crdb_first_schema_path status.actions status.operatorActions)"
export CRDB_CONDITIONS_PATH="$(crdb_first_schema_path status.conditions)"

printf '%s\n' \
  "apiVersion=$CRDBCLUSTER_API_VERSION" \
  "mode=$CRDB_MODE_PATH" \
  "regions=$CRDB_REGIONS_PATH" \
  "desiredImage=$CRDB_DESIRED_IMAGE_PATH" \
  "observedGeneration=$CRDB_OBSERVED_GENERATION_PATH" \
  "reconciled=$CRDB_RECONCILED_PATH" \
  "readyNodes=$CRDB_READY_NODES_PATH" \
  "statusImage=$CRDB_STATUS_IMAGE_PATH" \
  "statusVersion=$CRDB_STATUS_VERSION_PATH" \
  "actions=$CRDB_ACTIONS_PATH" \
  "conditions=$CRDB_CONDITIONS_PATH" \
  > crdb-operator-escalation/crdbcluster-schema-paths.txt

Get the CockroachDB version from a Ready pod:

bash
kubectl -n "$CRDB_NAMESPACE" exec <ready-crdb-pod> -c cockroachdb -- \
  /cockroach/cockroach version > crdb-operator-escalation/crdb-version.txt 2>&1
Show full SKILL.md (344 more words)Show less

Step 2: Resource Specifications and Status

bash
kubectl -n "$OPERATOR_NAMESPACE" get deploy,pod,svc,endpoints -o wide > crdb-operator-escalation/operator-resources.txt
kubectl -n "$OPERATOR_NAMESPACE" describe deploy cockroach-operator > crdb-operator-escalation/operator-deploy-describe.txt
kubectl -n "$OPERATOR_NAMESPACE" describe pods -l app=cockroach-operator > crdb-operator-escalation/operator-pods-describe.txt
kubectl -n "$OPERATOR_NAMESPACE" get deploy cockroach-operator -o yaml > crdb-operator-escalation/operator-deploy.yaml

kubectl -n "$CRDB_NAMESPACE" describe crdbcluster "$CRDBCLUSTER" > crdb-operator-escalation/crdbcluster-describe.txt
kubectl -n "$CRDB_NAMESPACE" get crdbnodes -o yaml > crdb-operator-escalation/crdbnodes.yaml
kubectl -n "$CRDB_NAMESPACE" describe crdbnodes > crdb-operator-escalation/crdbnodes-describe.txt
kubectl -n "$CRDB_NAMESPACE" get pod,svc,endpoints,pvc,pdb -o wide > crdb-operator-escalation/crdb-resources-wide.txt
kubectl -n "$CRDB_NAMESPACE" describe pods -l app.kubernetes.io/name=cockroachdb > crdb-operator-escalation/crdb-pods-describe.txt
kubectl -n "$CRDB_NAMESPACE" describe pvc > crdb-operator-escalation/pvc-describe.txt
kubectl -n "$CRDB_NAMESPACE" describe pdb > crdb-operator-escalation/pdb-describe.txt
kubectl -n "$CRDB_NAMESPACE" get events --sort-by=.lastTimestamp > crdb-operator-escalation/events.txt

Summarize key cluster status:

bash
jq \
  --arg modePath "$CRDB_MODE_PATH" \
  --arg regionsPath "$CRDB_REGIONS_PATH" \
  --arg desiredImagePath "$CRDB_DESIRED_IMAGE_PATH" \
  --arg observedGenerationPath "$CRDB_OBSERVED_GENERATION_PATH" \
  --arg reconciledPath "$CRDB_RECONCILED_PATH" \
  --arg readyNodesPath "$CRDB_READY_NODES_PATH" \
  --arg statusImagePath "$CRDB_STATUS_IMAGE_PATH" \
  --arg statusVersionPath "$CRDB_STATUS_VERSION_PATH" \
  --arg actionsPath "$CRDB_ACTIONS_PATH" \
  --arg conditionsPath "$CRDB_CONDITIONS_PATH" \
  '
  def value($path): if $path == "" then null else getpath($path | split(".")) end;
  {
  apiVersion,
  name: .metadata.name,
  schemaPaths: {
    mode: $modePath,
    regions: $regionsPath,
    desiredImage: $desiredImagePath,
    observedGeneration: $observedGenerationPath,
    reconciled: $reconciledPath,
    readyNodes: $readyNodesPath,
    statusImage: $statusImagePath,
    statusVersion: $statusVersionPath,
    actions: $actionsPath,
    conditions: $conditionsPath
  },
  mode: value($modePath),
  nodes: (value($regionsPath) // [] | map(.nodes)),
  regions: value($regionsPath),
  desiredImage: value($desiredImagePath),
  generation: .metadata.generation,
  observedGeneration: value($observedGenerationPath),
  reconciled: value($reconciledPath),
  readyNodes: value($readyNodesPath),
  statusImage: value($statusImagePath),
  statusVersion: value($statusVersionPath),
  actions: value($actionsPath),
  conditions: value($conditionsPath),
  labels: .metadata.labels,
  annotations: .metadata.annotations
}' crdb-operator-escalation/crdbcluster.json > crdb-operator-escalation/crdbcluster-summary.json

kubectl -n "$CRDB_NAMESPACE" get crdbnodes \
  -o 'custom-columns=NAME:.metadata.name,GENERATION:.metadata.generation,OBSERVED:.status.observedGeneration,DECOMMISSION:.status.decommission,REVISION:.metadata.annotations.crdb\.cockroachlabs\.com/clusterNodeRevision,NODE_ID:.status.nodeID' \
  > crdb-operator-escalation/crdbnodes-summary.txt

Step 3: Logs

Collect full recent logs, not filtered snippets:

bash
kubectl -n "$OPERATOR_NAMESPACE" logs -l app=cockroach-operator --tail=500 > crdb-operator-escalation/operator-logs.txt 2>&1
kubectl -n "$OPERATOR_NAMESPACE" logs -l app=cockroach-operator --previous --tail=500 > crdb-operator-escalation/operator-previous-logs.txt 2>&1 || true

For each CockroachDB pod:

bash
kubectl -n "$CRDB_NAMESPACE" logs <crdb-pod> -c cockroachdb --tail=500 > crdb-operator-escalation/<crdb-pod>-cockroachdb.log 2>&1
kubectl -n "$CRDB_NAMESPACE" logs <crdb-pod> -c cockroachdb --previous --tail=500 > crdb-operator-escalation/<crdb-pod>-cockroachdb-previous.log 2>&1 || true
kubectl -n "$CRDB_NAMESPACE" logs <crdb-pod> -c cert-reloader --tail=100 > crdb-operator-escalation/<crdb-pod>-cert-reloader.log 2>&1 || true

Step 4: Operation-Specific Evidence

Upgrade
bash
jq \
  --arg desiredImagePath "$CRDB_DESIRED_IMAGE_PATH" \
  --arg statusImagePath "$CRDB_STATUS_IMAGE_PATH" \
  --arg statusVersionPath "$CRDB_STATUS_VERSION_PATH" \
  --arg actionsPath "$CRDB_ACTIONS_PATH" \
  --arg conditionsPath "$CRDB_CONDITIONS_PATH" \
  '
  def value($path): if $path == "" then null else getpath($path | split(".")) end;
  {
  apiVersion,
  name: .metadata.name,
  desiredImagePath: $desiredImagePath,
  desiredImage: value($desiredImagePath),
  statusImagePath: $statusImagePath,
  statusImage: value($statusImagePath),
  statusVersionPath: $statusVersionPath,
  statusVersion: value($statusVersionPath),
  actionsPath: $actionsPath,
  actions: value($actionsPath),
  conditionsPath: $conditionsPath,
  conditions: value($conditionsPath),
  annotations: .metadata.annotations,
}' crdb-operator-escalation/crdbcluster.json > crdb-operator-escalation/upgrade-status.json

kubectl -n "$CRDB_NAMESPACE" get jobs -o wide > crdb-operator-escalation/jobs.txt
kubectl -n "$CRDB_NAMESPACE" get pods -o 'custom-columns=NAME:.metadata.name,IMAGE:.spec.containers[0].image,PHASE:.status.phase' > crdb-operator-escalation/pod-images.txt
kubectl -n "$CRDB_NAMESPACE" describe job <version-checker-job> > crdb-operator-escalation/version-checker-job.txt 2>&1 || true
kubectl -n "$CRDB_NAMESPACE" logs -l job-name=<version-checker-job> > crdb-operator-escalation/version-checker-logs.txt 2>&1 || true

Include current and target CRDB image and whether any version checker job or pod was deleted.

Scale Down or Decommission
bash
kubectl -n "$CRDB_NAMESPACE" exec <ready-crdb-pod> -c cockroachdb -- \
  /cockroach/cockroach node status --decommission > crdb-operator-escalation/node-decommission-status.txt 2>&1

kubectl -n "$CRDB_NAMESPACE" get crdbnodes -o json | jq '[.items[] | select(.status.decommission != null and .status.decommission != "")] | {count: length, nodes: [.[] | {name: .metadata.name, decommission: .status.decommission}]}' \
  > crdb-operator-escalation/decommissioning-crdbnodes.json

Include original and target node count, whether multiple nodes changed at once, and whether manual drain/decommission was attempted.

Scale Up

Capture whether machines, Kubernetes nodes, disks, storage classes, topology spread constraints, or node labels changed:

bash
kubectl get nodes -L topology.kubernetes.io/region,topology.kubernetes.io/zone > crdb-operator-escalation/nodes-locality.txt
kubectl get storageclass > crdb-operator-escalation/storageclasses.txt
kubectl -n "$CRDB_NAMESPACE" get pvc -o wide > crdb-operator-escalation/pvc-wide.txt
Certificate Rotation
bash
kubectl -n "$CRDB_NAMESPACE" get secret,configmap | grep -E 'ca|node|client|tls|cert' > crdb-operator-escalation/cert-resources.txt || true
kubectl -n "$CRDB_NAMESPACE" get certificate,issuer,clusterissuer -o wide > crdb-operator-escalation/cert-manager-resources.txt 2>&1 || true

kubectl -n "$CRDB_NAMESPACE" get secret <node-tls-secret> -o jsonpath='{.data.tls\.crt}' | base64 -d | \
  openssl x509 -noout -dates -subject -issuer -ext subjectAltName > crdb-operator-escalation/node-cert-metadata.txt

Do not collect private key values.

Migration

Use debugging-cockroachdb-operator-migrations and attach its migration state output. Include source StatefulSet or v1alpha1 CrdbCluster, migration labels, migration phase, source ownerReferences, and migration controller logs.

Step 5: Operator pprof and Metrics

Collect these when the operator is running but not reconciling, logs/status do not explain why, or a worker may be blocked. In production or restricted environments, confirm with the customer, TSE, or the operator team before opening port-forwards.

In one terminal:

bash
kubectl -n "$OPERATOR_NAMESPACE" port-forward deployment/cockroach-operator 7080:7080

In another terminal:

bash
curl -s 'http://localhost:7080/debug/pprof/goroutine?debug=2' > crdb-operator-escalation/goroutine_dump.txt
curl -s 'http://localhost:7080/debug/pprof/goroutine?debug=1' > crdb-operator-escalation/goroutine_summary.txt
curl -s 'http://localhost:7080/debug/pprof/heap' > crdb-operator-escalation/heap.prof
curl -s 'http://localhost:7080/debug/pprof/profile?seconds=30' > crdb-operator-escalation/cpu.prof
curl -s 'http://localhost:7080/debug/pprof/mutex' > crdb-operator-escalation/mutex.prof

Metrics:

bash
kubectl -n "$OPERATOR_NAMESPACE" port-forward deployment/cockroach-operator 8080:8080
curl -s http://localhost:8080/metrics > crdb-operator-escalation/metrics_dump.txt
grep 'controller_runtime_reconcile_total' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/reconcile-total.txt || true
grep 'controller_runtime_reconcile_errors_total' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/reconcile-errors.txt || true
grep 'workqueue_depth' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/workqueue-depth.txt || true
grep 'workqueue_longest_running_processor_seconds' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/workqueue-longest-running.txt || true
grep 'workqueue_unfinished_work_seconds' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/workqueue-unfinished.txt || true

What TSC should inspect:

  • processNextWorkItem followed by Reconcile and a long-running call in goroutine_dump.txt
  • kube.(*Ctl).Exec, cockroach init, HTTP calls, or mutex waits with long durations
  • increasing workqueue_longest_running_processor_seconds
  • growing workqueue_depth
  • no reconcile count movement for a controller that should be active

Step 6: Timeline

Create crdb-operator-escalation/timeline.md with:

  • When the issue started
  • What operation was in progress
  • What docs or runbooks were followed
  • Whether VMs, Kubernetes nodes, disks, storage classes, certs, network policies, or Helm values changed
  • Every manual delete, patch, edit, restart, drain, decommission, or Helm command, in order
  • What is currently serving traffic and what is unavailable
  • Customer restrictions, such as no cluster-admin, no debug containers, no external images, or private registry only

Step 7: Escalation Summary

Return a concise summary with:

  1. Operation type and current impact
  2. Current operator and CockroachDB versions
  3. Current schema-grounded CrdbCluster mode, generation, observedGeneration, image, version, actions, and conditions
  4. Stuck resource or symptom
  5. Any unsafe operations already performed
  6. Missing artifacts, if any
  7. Whether pprof/metrics suggest a blocked worker

References

© cockroachdb, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet of cockroachdb/helm-charts.

Open the folder on GitHubat commit 26e44ff

Compare with similar skills

Collecting Cockroachdb Operator Escalation Packet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Collecting Cockroachdb Operator Escalation Packet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Collecting Cockroachdb Operator Escalation Packet this skillcockroachdb/helm-charts105—~5.1kAutomated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from cockroachdb/helm-charts

  • Configuring Cockroachdb Helm Tls

    cockroachdb/helm-charts

    Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.

    105 GitHub stars~3.8k tokensUpdated 8 days ago
    Auto-check passed
  • Debugs CockroachDB Operator migration scenarios, including Helm StatefulSet to v1beta1 CrdbNode migration and public operator v1alpha1 to v1beta1 migration.

    105 GitHub stars~3.6k tokensUpdated 8 days ago
    Auto-check passed
  • Installing Cockroachdb With Helm

    cockroachdb/helm-charts

    Guides customer-facing installation of CockroachDB on Kubernetes using the CockroachDB split Helm charts and operator-managed v1beta1 resources.

    105 GitHub stars~3.4k tokensUpdated 8 days ago
    Auto-check passed
  • Diagnoses failed or unhealthy CockroachDB Helm chart deployments by checking Helm release state, operator health, CrdbCluster and CrdbNode status, pod readiness, RBAC, webhooks, TLS, upgrades…

    105 GitHub stars~6.8k tokensUpdated 8 days ago
    Auto-check passed
  • Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.

    105 GitHub stars~2k tokensUpdated 8 days ago
    Auto-check passed

Works with

Categories

Questions about Collecting Cockroachdb Operator Escalation Packet

What does Collecting Cockroachdb Operator Escalation Packet do?

Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…. Collecting Cockroachdb Operator Escalation Packet is an agent skill from cockroachdb/helm-charts. Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps, metrics, and a customer action timeline.

When should I use Collecting Cockroachdb Operator Escalation Packet?

Collecting Cockroachdb Operator Escalation Packet fits situations like: general diagnosis cannot resolve an operator-managed CockroachDB Helm issue; before restarting a stuck operator.

How do I install Collecting Cockroachdb Operator Escalation Packet in Claude Code?

Run `npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a claude-code`. Or copy the skill folder (skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet in cockroachdb/helm-charts) into .claude/skills/collecting-cockroachdb-operator-escalation-packet in your project. Claude Code loads it when a task matches its description.

How do I install Collecting Cockroachdb Operator Escalation Packet in Codex?

Run `npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a codex`. Or copy the skill folder (skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet in cockroachdb/helm-charts) into .agents/skills/collecting-cockroachdb-operator-escalation-packet in your project. Codex loads it when a task matches its description.

Can I use Collecting Cockroachdb Operator Escalation Packet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/collecting-cockroachdb-operator-escalation-packet, .gemini/skills/collecting-cockroachdb-operator-escalation-packet, .github/skills/collecting-cockroachdb-operator-escalation-packet and .opencode/skills/collecting-cockroachdb-operator-escalation-packet in your project.

What does Collecting Cockroachdb Operator Escalation Packet need to run?

Going by SKILL.md and its folder, Collecting Cockroachdb Operator Escalation Packet needs the command-line tools its instructions call (kubectl, jq, curl, helm, node and openssl). Compatibility (from SKILL.md): CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and CockroachDB namespace; pprof and metrics collection require port-forward access to the operator Deployment..

Does Collecting Cockroachdb Operator Escalation Packet access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Collecting Cockroachdb Operator Escalation Packet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Collecting Cockroachdb Operator Escalation Packet use?

Collecting Cockroachdb Operator Escalation Packet is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Collecting Cockroachdb Operator Escalation Packet use?

About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Collecting Cockroachdb Operator Escalation Packet?

Skills that share tags, products or a category with Collecting Cockroachdb Operator Escalation Packet: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Collecting Cockroachdb Operator Escalation Packet?

cockroachdb (a GitHub organization) maintains it in cockroachdb/helm-charts, which has 105 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 1, 2026.

Source: cockroachdb/helm-charts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.