Lawliet LAWLIET
Book a demo

Diagnostics for support

When something is wrong on a site we cannot reach, screenshots answer one question at a time. ./lawliet diag collects everything support asks for first into one redacted file that can leave an air-gapped network.

Run it

sudo ./lawliet diag                         # last 1000 log lines per service
sudo ./lawliet diag --since 24h             # logs of the last 24 hours (30m, 7d, or a timestamp)
sudo ./lawliet diag --output /media/usb     # write it there instead
sudo ./lawliet diag --lines 5000            # more log lines per service
sudo ./lawliet diag --keep-emails           # keep e-mail addresses (redacted by default)

It writes lawliet-diag-<host>-<UTC time>.tar.gz in the installation directory, readable by root only. Send that file to [email protected] with the build id from ./lawliet status; nothing else is needed.

What is in it

FileWhat it holds
MANIFEST.txtEvery file in the archive, its size, and how many of each kind of redaction were made
bundle.txtThe bundle version and build id, and the deployment settings (mode, address, certificate kind)
env.redacted.env with every value not on a short safe list replaced by [redacted]
containers.txtDocker and Compose versions, each container's state, health and restart count
logs/<service>.logEach container's recent log, through the redaction filter
backend-errors.txtThe backend's recent errors, redacted
health.txtHealth and readiness, and the licence status (never the key)
tls.txtThe certificate in use: subject, issuer, names, validity and fingerprint (never the private key), and TRUSTED_HOSTS
system.txtOS, CPU, memory, disk, the time, time zone and whether NTP is synchronised
database.txtThe schema revision, agents by status, platform and version, agent clocks, and the last failed remote-deployment hosts with their reasons

The database itself is never included: counts and states only.

What is removed

A .env key whose name looks secret is never shown, even if someone adds it to the safe list. Every other file passes a filter that replaces every secret value from .env wherever it appears; tokens and API keys; passwords in URLs; private keys and licence strings; secret headers and password= or token= style values; and e-mail addresses unless --keep-emails is given.

The self-check

After building the archive and before writing it, diag searches every file name and every file for each secret value in .env and for any private key. If one is found it refuses: nothing is written, and it names the setting that would have leaked (never its value) and the file it was found in. Report that to support without the file.

./lawliet doctor

./lawliet doctor remains for a quick check on the server: health and build id, container state, the schema revision, configuration with every value redacted, row counts, recent logs and disk usage. It lists any address the certificate does not cover, and warns while encryption is off.