A developer wants to debug a running container in a Pod named 'web-app' in namespace 'dev'. Which command attaches an ephemeral container with the 'nicolaka/netshoot' image for network debugging?
kubectl debug injects an ephemeral container named debugger directly into the existing web-app pod using the nicolaka/netshoot image. Ephemeral containers share the pod’s network, IPC, and PID namespaces with the application container, allowing you to inspect its interfaces, sockets, and processes without modifying or restarting the original workload. This is the intended mechanism for bringing a debugging image into a running pod for interactive troubleshooting.
Why this answer
`kubectl debug` is the dedicated command for adding an ephemeral container to a running Pod for troubleshooting. The `--image=nicolaka/netshoot` flag specifies the network debugging image, and `-c debugger` names the ephemeral container. This allows the developer to attach to the Pod's network namespace without restarting or modifying the original container.
Exam trap
Kubernetes often tests the distinction between `kubectl debug` (for ephemeral containers) and `kubectl exec` (for existing containers), trapping candidates who think `exec` can add a new container with a different image.
How to eliminate wrong answers
Option B is wrong because `kubectl run` creates a standalone Pod, not an ephemeral container attached to an existing Pod; it does not share the network namespace of 'web-app'. Option C is wrong because `kubectl attach` attaches to a running container's stdio, not to a new container, and it does not support the `--image` flag. Option D is wrong because `kubectl exec` runs a command in an existing container, not a new container with a different image; the `--image` flag is invalid for `kubectl exec`.