A comprehensive collection of health check scripts for Kubernetes clusters. These scripts help diagnose issues, monitor component health, and ensure your cluster is running optimally.
# Clone the repository
git clone https://github.com/gstohl/kube-help.git
cd kube-help
# Make scripts executable
chmod +x *.sh
# Run all health checks
./kube-health-check.sh --all
# Run specific checks
./kube-health-check.sh cluster nodes storage
# List available checks
./kube-health-check.sh --listkubectlconfigured with cluster accessjqfor JSON parsing (most scripts)curlorwgetfor API checks- Bash 4.0 or higher
| Script | Description | Key Features |
|---|---|---|
check-k8s-health-enhanced.sh |
Comprehensive cluster health | 12 check categories, resource analysis, recommendations |
check-node-health.sh |
Node health and resources | Resource usage, pod distribution, kernel analysis |
check-kubelet.sh |
Kubelet component health | Node conditions, pod capacity, eviction detection |
check-kube-proxy.sh |
Kube-proxy analysis | Mode detection (iptables/IPVS), rule verification |
check-etcd.sh |
etcd cluster health | Member status, performance metrics, backup checks |
check-coredns.sh |
CoreDNS health | DNS resolution tests, cache analysis, metrics |
check-metrics-server.sh |
Metrics server status | Resource metrics, HPA functionality |
| Script | Description | Key Features |
|---|---|---|
check-containerd.sh |
Container runtime health | Version compatibility, image pull errors, disk pressure |
check-k8s-versions.sh |
Version compatibility | Component version skew, upgrade paths, deprecations |
| Script | Description | Key Features |
|---|---|---|
check-pod-security.sh |
Pod security analysis | Security context, RBAC, compliance scoring (0-100) |
check-certificates.sh |
Certificate health | Expiration warnings, webhook certs, TLS validation |
check-image-registry.sh |
Image registry health | Pull secrets, authentication, security analysis |
| Script | Description | Key Features |
|---|---|---|
check-storage-health.sh |
Persistent storage | PV/PVC analysis, CSI drivers, capacity planning |
check-longhorn.sh |
Longhorn storage | Volume health, replica status, disk usage |
| Script | Description | Key Features |
|---|---|---|
check-network-connectivity.sh |
Network connectivity | Live testing, MTU analysis, policy impact |
check-hostport-conflicts.sh |
Host port conflicts | Port collision detection, scheduling issues |
check-nginx-ingress.sh |
NGINX Ingress | Controller health, configuration, SSL |
check-cilium.sh |
Cilium CNI | Endpoint health, network policies, IPAM |
check-cilium-envoy.sh |
Cilium Envoy proxy | L7 policies, proxy configuration |
| Script | Description | Key Features |
|---|---|---|
check-loki.sh |
Loki logging system | Log ingestion, storage, Promtail status |
check-cert-manager.sh |
cert-manager | Certificate resources, ACME status, renewal |
The kube-health-check.sh script orchestrates all health checks:
# Run all checks
./kube-health-check.sh --all
# Run specific checks
./kube-health-check.sh cluster nodes storage security
# Save output to file
./kube-health-check.sh --all --output health-report.txt
# Run checks in parallel (experimental)
./kube-health-check.sh --all --parallel
# Verbose output
./kube-health-check.sh --all --verbosecluster- Enhanced cluster healthnodes- Node health and resourcesstorage- Persistent storage healthnetwork- Network connectivity testsecurity- Pod security and compliancecontainerd- Container runtime healthversions- Version compatibilitykubelet- Kubelet healthkube-proxy- Kube-proxy analysiscertificates- Certificate healthregistry- Image registry healthlonghorn- Longhorn storagenginx- NGINX ingress controllerloki- Loki logging systemcilium- Cilium CNIcilium-envoy- Cilium Envoy proxyetcd- etcd key-value storecoredns- CoreDNSmetrics- Metrics servercert-manager- cert-managerhostport- Host port conflicts
All scripts use color-coded output for easy reading:
- π’ Green - Healthy/Success
- π‘ Yellow - Warning/Attention needed
- π΄ Red - Error/Critical issue
- π΅ Blue - Information
- β - Check passed
- β - Warning condition
- β - Check failed
# Quick cluster health check
./check-k8s-health-enhanced.sh# Check all storage components
./kube-health-check.sh storage longhorn# Run security-focused checks
./kube-health-check.sh security certificates registry# Test network connectivity
./check-network-connectivity.sh
# Check for port conflicts
./check-hostport-conflicts.sh# Check component versions
./check-k8s-versions.sh
# Check container runtime
./check-containerd.shkube-health-check.sh (Master Script)
βββ Core Checks
β βββ check-k8s-health-enhanced.sh
β βββ check-node-health.sh
β βββ check-kubelet.sh
βββ Network Checks
β βββ check-network-connectivity.sh
β βββ check-kube-proxy.sh
β βββ check-nginx-ingress.sh
βββ Storage Checks
β βββ check-storage-health.sh
β βββ check-longhorn.sh
βββ Security Checks
β βββ check-pod-security.sh
β βββ check-certificates.sh
β βββ check-image-registry.sh
βββ Component Checks
βββ check-etcd.sh
βββ check-coredns.sh
βββ check-metrics-server.sh
- Scripts use read-only kubectl commands
- No modifications are made to cluster resources
- Network tests create temporary test pods (auto-cleaned)
- Sensitive information is not logged or exposed
# Ensure scripts are executable
chmod +x *.sh# Install kubectl or ensure it's in PATH
which kubectl# Ensure kubectl is configured with proper permissions
kubectl auth can-i get pods --all-namespaces# Install jq
# macOS: brew install jq
# Linux: apt-get install jq / yum install jqFeel free to submit issues and enhancement requests!
- Fork the repository
- Create your feature branch (
git checkout -b feature/new-check) - Commit your changes (
git commit -m 'Add new health check') - Push to the branch (
git push origin feature/new-check) - Create a Pull Request
This project is open source and available under the MIT License.
- Built with assistance from Claude
- Inspired by Kubernetes best practices and operational experience
- Community feedback and contributions
Note: These scripts are provided as-is for diagnostic purposes. Always review the output and recommendations in the context of your specific environment.