> Markdown version of [/videos/769-debugging-go-from-zero-to-kubernetes?t=1268](https://www.wearedevelopers.com/videos/769-debugging-go-from-zero-to-kubernetes?t=1268). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Debugging Go: from zero to Kubernetes Struggling to troubleshoot isolated Go applications in Kubernetes? Learn how to leverage ephemeral containers and Delve for secure, live debugging without disrupting production traffic. - **Speakers:** Michele Caci - **Event:** World Congress 2023 - **Published:** October 6, 2023 - **Duration:** 25:36 - **URL:** https://www.wearedevelopers.com/videos/769-debugging-go-from-zero-to-kubernetes ## Summary Live debugging allows developers to interact with and understand running applications in real time, serving as both a troubleshooting mechanism and a learning tool for code execution. Transitioning from local debugging to containerized environments introduces complexity due to strict process isolation. Using Delve, the standard Go debugger, developers can bridge this gap by securely attaching to running applications across local, Docker, and Kubernetes environments. While demonstrated with Go, the underlying container and orchestration principles—such as injecting language-specific debuggers alongside compiled source code—apply universally to other environments like Java or C++. Debugging inside a Docker container requires breaking standard isolation boundaries. This involves running a secondary debugger container equipped with the `SYS_PTRACE` Linux capability and sharing the process namespace of the target application container. Moving to Kubernetes, directly embedding a large debugger image into a persistent deployment wastes compute resources and inflates attack surfaces. Instead, developers should leverage Kubernetes ephemeral containers via the `kubectl debug` command. This approach injects a temporary debugging container into a running pod, seamlessly applying the necessary debugging profiles and targeting the shared process namespace without permanently altering the base deployment configuration. Operating debuggers in live environments demands strict precautions, as debuggers disrupt application execution by taking control of the active process. In production or shared environments, it is critical to manipulate Kubernetes service selectors to safely route real user traffic away from the pod being actively debugged, pairing this with conditional breakpoints to filter state. Furthermore, optimizing builds by disabling CGO (`CGO_ENABLED=0`) can prevent external C-library conflicts when attaching the debugger. Ultimately, while logs, traces, and metrics are essential for data-driven observability, ephemeral container debugging provides the targeted, real-time interactivity needed to resolve complex, cluster-level behaviors safely. **Keywords:** delve go debugger, kubernetes ephemeral containers, docker container debugging, sys_ptrace linux capability, shared process namespaces, live debugging techniques, kubectl debug command, go application troubleshooting, kubernetes service selectors, remote debugging configuration, cloud native observability, cgo_enabled optimization ## Chapters 1. **Core principles of live debugging and data-driven tools** (01:16) — Live execution tracking complements logs and metrics by interacting directly with the running application. 1. **Risks of attaching debuggers in production environments** (04:14) — Disrupting real traffic can cause production incidents unless traffic is properly redirected or conditional breakpoints are applied. 1. **Running local debugging sessions with Delve** (05:19) — Compiling code and attaching to processes via a command-line interface allows direct control over the execution flow. 1. **Configuring dual Docker containers for Go debugging** (07:31) — Isolating the application and debugger into separate containers requires copying source code alongside specific tooling. 1. **Enabling Linux capabilities and sharing process namespaces** (12:06) — The sys_ptrace capability and process namespace sharing allow an isolated debugger container to trace external application processes. 1. **Deploying multi-container debugging pods in Kubernetes** (16:04) — Adding a debugger container directly to a deployment configuration wastes cluster resources if permanently attached. 1. **Using ephemeral containers with kubectl debug** (18:59) — Injecting temporary ephemeral containers into running pods enables on-demand debugging without altering deployment configurations. 1. **Summarizing the Kubernetes live debugging workflow** (21:08) — Live debuggers are complementary tools that augment standard monitoring by exposing underlying runtime execution logic. 1. **Strategies for port forwarding and traffic redirection** (22:30) — Community questions cover local port forwarding, disabling compiler optimizations, and selectively routing test traffic to debug pods. ## Related Moments - [Debugging serverless container applications in Kubernetes production environments](https://www.wearedevelopers.com/videos/243-serverless-native-java-with-quarkus) (from "Serverless-Native Java with Quarkus") - [Debugging challenges in scaled cloud deployments](https://www.wearedevelopers.com/videos/527-debugging-schrodinger-s-app) (from "Debugging Schrödinger's App") - [Injecting ephemeral debug containers into running Kubernetes pods](https://www.wearedevelopers.com/videos/100188-diagnostic-tooling-how-to-get-insights-from-your-net-services-hosted-in-kubernetes-containers) (from "Diagnostic Tooling: How to get insights from your .NET services hosted in Kubernetes containers?") - [Introduction to live debugging and code hot swapping](https://www.wearedevelopers.com/videos/100321-swapping-code-losing-memory-a-jvm-deep-dive) (from "Swapping Code, Losing Memory: A JVM Deep Dive") - [Debugging challenges inside closed source cloud native environments](https://www.wearedevelopers.com/videos/797-cloud-as-the-new-mainframe-why-the-cloud-hype-does-not-reflect-the-dev-reality) (from "Cloud as the new mainframe: why the cloud hype does not reflect the dev reality") - [Addressing local development challenges with Podman Desktop](https://www.wearedevelopers.com/videos/1133-containers-and-kubernetes-made-easy-deep-dive-into-podman-desktop-and-new-ai-capabilities) (from "Containers and Kubernetes made easy: Deep dive into Podman Desktop and new AI capabilities") ## Related Articles - [Building AI Solutions with Rust and Docker](https://www.wearedevelopers.com/magazine/494-building-ai-solutions-with-rust-and-docker) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Devs vs. Marketers, COBOL and Copilot, Make Live Coding Easy and more - The Best of LIVE 2025 - Part 3](https://www.wearedevelopers.com/magazine/663-devs-vs-marketers-cobol-and-copilot-make-live-coding-easy-and-more-the-best-of-live-2025-part-3) - [AI-Powered Debugging: The Future of Fixing Your Code](https://www.wearedevelopers.com/magazine/553-ai-powered-debugging-the-future-of-fixing-your-code) ## Related Jobs - [Senior Security Engineer, Docker Desktop](https://www.wearedevelopers.com/jobs/48457-senior-security-engineer-docker-desktop) at **Docker, Inc.** - [Software Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/1940513-software-engineer-infrastructure-platform) at **Docker, Inc.** - [Senior Software Engineer, Infrastructure](https://www.wearedevelopers.com/jobs/48459-senior-software-engineer-infrastructure) at **Docker, Inc.** - [Principal Software Engineer, Docker Hardened Images](https://www.wearedevelopers.com/jobs/48453-principal-software-engineer-docker-hardened-images) at **Docker, Inc.** - [Senior Software Engineer, Secure Build](https://www.wearedevelopers.com/jobs/48461-senior-software-engineer-secure-build) at **Docker, Inc.** - [Software Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/2004010-software-engineer-infrastructure-platform) at **Docker, Inc.**