Skip to main content

What is debug mode?

Debug mode lets you deploy a separate instance of your container with SSH access and logging enabled. This gives you a way to inspect the enclave runtime, troubleshoot startup issues, and test configuration changes — without affecting your production container.

When to use debug mode

  • Container startup failures: SSH in to check why your application isn’t starting
  • Configuration issues: Verify that environment variables and secrets are set correctly
  • Runtime debugging: Inspect processes, network, and filesystem inside the enclave
  • Testing changes: Validate a new config or image is working as expected before deploying to production

How it works

Debug containers are fully independent instances. They run on a separate domain and have their own lifecycle, so you can deploy, update, and delete them without touching production instances.
Debug containers do not pass attestation. Tinfoil’s SecureClient will refuse to connect to a debug instance because debug enclaves are not confidential. This is by design as debug mode trades confidentiality for inspectability. Never inject production secrets or send production or otherwise sensitive data to a debug container.
A container named api can have both a production and a debug instance running simultaneously.

Deploying a debug container

  1. In the All Containers tab, click New Container
  2. Toggle Debug Mode on
  3. Select one or more SSH keys from your organization’s key list (see below)
  4. Configure the rest of the container as normal
  5. Click Deploy Container

Managing SSH keys

Before deploying a debug container, add your SSH public keys to the organization.

Adding keys

  1. Go to the SSH Keys tab in the Containers section
  2. Click Add SSH Key
  3. Paste your public key

Connecting via SSH

Once your debug container is running, the dashboard shows the SSH connection command on the container’s card. It looks like:
This gives you a shell inside the enclave where you can inspect running processes, check logs, verify environment variables, and debug your application.

Promoting to production

Once you’ve finished testing with a debug container, you can deploy it as a production enclave directly from the dashboard:
  1. On the debug container, click Update
  2. In the modal, select Deploy to prod
  3. The container deploys as a production enclave with the same configuration but with debug access and logging disabled
This uses a blue-green deployment — the debug container keeps running until the production instance is ready.

Using the CLI

The Tinfoil CLI handles the SSH key registry and the debug-mode deploy:
When two containers share a name (one debug, one production), --debug-mode selects the debug container. You can also use its UUID.