What is debug mode?
Debug mode lets you deploy a separate instance of your container with SSH access and logging enabled. This gives you a way to inspect the enclave runtime, troubleshoot startup issues, and test configuration changes — without affecting your production container.When to use debug mode
- Container startup failures: SSH in to check why your application isn’t starting
- Configuration issues: Verify that environment variables and secrets are set correctly
- Runtime debugging: Inspect processes, network, and filesystem inside the enclave
- Testing changes: Validate a new config or image is working as expected before deploying to production
How it works
Debug containers are fully independent instances. They run on a separate domain and have their own lifecycle, so you can deploy, update, and delete them without touching production instances.
A container named
api can have both a production and a debug instance running simultaneously.
Deploying a debug container
- In the All Containers tab, click New Container
- Toggle Debug Mode on
- Select one or more SSH keys from your organization’s key list (see below)
- Configure the rest of the container as normal
- Click Deploy Container
Managing SSH keys
Before deploying a debug container, add your SSH public keys to the organization.Adding keys
- Go to the SSH Keys tab in the Containers section
- Click Add SSH Key
- Paste your public key
Connecting via SSH
Once your debug container is running, the dashboard shows the SSH connection command on the container’s card. It looks like:Promoting to production
Once you’ve finished testing with a debug container, you can deploy it as a production enclave directly from the dashboard:- On the debug container, click Update
- In the modal, select Deploy to prod
- The container deploys as a production enclave with the same configuration but with debug access and logging disabled
Using the CLI
The Tinfoil CLI handles the SSH key registry and the debug-mode deploy:--debug-mode selects the debug container. You can also use its UUID.
