Challenge Medium

Reach a Distroless Container's Debug Endpoint From a Sidecar Container

A distroless container serves a debug interface on its own loopback address. Can you reach this debug endpoint using nothing but standard Docker commands?

The app-1 container runs an HTTP API server built into a distroless image. The public API is exposed on port 8080, and the same process also serves a debug interface on 127.0.0.1:15000 inside the container. Your task is to query the debug endpoint and find out the instance ID it reports.

There are a few obstacles on the way. The image has no shell and no HTTP client, so docker exec has nothing to run. The 127.0.0.1 address of the debug interface belongs to the container's own network namespace, so the host's curl cannot reach it either. Finally, your user on this machine cannot use sudo, so entering the container's namespace with host tools like nsenter is not an option.

What you can do is use Docker itself: start a sidecar container that brings its own tools and shares the network namespace of app-1 and query the internal debug endpoint from it.

Hint 1: There is more than one localhost

Each container runs in its own network namespace with its own loopback interface. A process can reach 127.0.0.1:15000 of app-1 only if it runs in the same network namespace.

Hint 2: How to reproduce "docker exec" with "docker run"

The docker run command can place a new container into the namespaces of an already running container instead of creating new ones for it:

Debugging tools such as cdebug, docker debug, and Kubernetes ephemeral containers are built on the same idea.

Hint 3: Which image to use for the sidecar

Any image with an HTTP client will do. busybox and alpine ship wget, and curlimages/curl ships curl.