Skip to content
Development
Skill

/google-cloud-filestore-log-troubleshooting

Diagnoses and resolves Google Cloud Filestore client mount failures, permission errors (EACCES), and network timeouts (ETIMEDOUT). Use when an NFS mount hangs or fails from a Compute Engine VM, GKE pod, Cloud Run service, or Vertex AI workload, when `mount.nfs` reports

From plugin
google-skills
20k147 skills1 MCP
Install
$ npx -y skills add google/skills --skill google-cloud-filestore-log-troubleshooting --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/google-cloud-filestore-log-troubleshooting

Context preview

The summary Claude sees to decide when to auto-load this skill.

Diagnoses and resolves Google Cloud Filestore client mount failures, permission errors (EACCES), and network timeouts (ETIMEDOUT). Use when an NFS mount hangs or fails from a Compute Engine VM, GKE pod, Cloud Run service, or Vertex AI workload, when `mount.nfs` reports

SKILL.md

google-cloud-filestore-log-troubleshooting.SKILL.md
name: google-cloud-filestore-log-troubleshooting
metadata:
  category: Storage
description: >-
  Diagnoses and resolves Google Cloud Filestore client mount failures,
  permission errors (EACCES), and network timeouts (ETIMEDOUT). Use when an NFS
  mount hangs or fails from a Compute Engine VM, GKE pod, Cloud Run service, or
  Vertex AI workload, when `mount.nfs` reports "Connection timed out" or "access
  denied by server", when checking whether VPC ingress firewall rules or
  `nfsExportOptions` allow a client IP, or when a previously working Filestore
  share suddenly stops mounting after an administrative change. Don't use for
  Cloud Storage (GCS) buckets, Persistent Disk, or Cloud NetApp Volumes, and
  don't use for Filestore capacity scaling or backup and export-policy auditing.

<!-- disableFinding(LINE_OVER_80) -->

Google Cloud Filestore Log-Based Troubleshooting

Diagnoses, troubleshoots, and remediates Google Cloud Filestore client mount failures, permission errors (`EACCES`), and network timeouts (`ETIMEDOUT`) across projects.

Prerequisites & Quick Start

Required IAM roles on target project(s) (and Shared VPC host project if applicable):

  • **Read**: `roles/file.viewer` (instance & export ACLs), `roles/compute.networkViewer` (VPC firewall rules), `roles/logging.viewer` (Cloud Audit & GKE CSI logs), `roles/mcp.toolUser` (if using MCP tools).
  • **Write (Remediation only)**: `roles/file.editor` (export ACL updates), `roles/compute.securityAdmin` (firewall rule creation).

Authenticate, verify billing/APIs, and configure your environment:

gcloud auth login && gcloud auth application-default login
gcloud billing projects describe {project_id} --format="value(billingEnabled)"
gcloud services enable file.googleapis.com compute.googleapis.com logging.googleapis.com --quiet
gcloud config set project {project_id} && gcloud config set compute/region {region}

Attribution

Prefix every `gcloud` command provided or executed with the skill metrics environment:

CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud filestore instances describe ...

On direct REST API calls, append HTTP header: `User-Agent: gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)`.

Conceptual & Informational Queries (CRITICAL)

For purely conceptual, architectural, or educational questions (e.g., "What causes EACCES on Filestore?", "Why does GKE Node IP appear instead of Pod IP?", "What ports does Filestore require?", "Explain root squash"):

  • **Rule**: **Answer immediately using pre-trained knowledge and the workflow rules below.** Answering directly minimizes tool latency and token usage when the user only seeks architectural guidance.
  • **Constraint**: **Do not execute external tool calls or API requests** for basic knowledge questions.

Handling "No-Command" Constraints (CRITICAL)

If the user prompt contains constraints like "Do not execute commands", "without executing", or "read-only":

  • **Rule**: **Strictly avoid calling `run_command`** to execute any shell, Python, or `gcloud` commands.
  • **Discovery**:

1. First, check if Filestore MCP tools (`get_instance`, `list_instances`) are available and use them (API calls, not command executions). 2. If MCP tools are unavailable, read `references/mock-fleet-data.md` **only if** the requested instance matches one of the evaluation scenarios (`finance-share`, `shared-nfs`, `ml-data`, `data-hub`, `prod-share`). Never report mock data as live production state. If the instance is not listed there, state that live access is required and provide the exact commands for the user to run. 3. **Fast-Path Stop Rule**: Once you locate the target instance in `references/mock-fleet-data.md`, **stop reading additional files immediately** and formulate your response. Do **NOT** read `scripts/quick_diagnose.py`, `scripts/diagnose_lib.py`, `_internal/quick_diagnose_test.py`, or `EVAL.*` files when command execution is disabled, as inspecting code/test files wastes turns and triggers timeouts. 4. Explain the required diagnostic steps and output the exact attributed commands for manual execution.

  • **Mandatory User Confirmation Requirement**: Even when command execution is disabled or the user asks only for recommendations, your response **MUST STILL end with a clear question prompting the user for explicit confirmation** before applying any remediation (e.g., *"Would you like me to proceed with creating the VPC ingress firewall rule `[rule_name]`? Please confirm to proceed."*).

Multi-Runtime Execution Options

Option 1: Bundled Python CLI Script (Recommended for CLI / Terminal Agents)

# Single instance diagnosis
python3 scripts/quick_diagnose.py --instance="<INSTANCE_ID>" --location="<LOCATION_OR_ZONE>" \
    [--project="<PROJECT_ID>"] [--client-ip="<CLIENT_IP>"] [--client-subnet="<CLIENT_SUBNET_CIDR>"]

# Bulk project-wide fleet diagnosis
python3 scripts/quick_diagnose.py --all --project="<PROJECT_ID>" [--json]

| Flag | Purpose | | :--- | :--- | | `--instance`, `--location` | Filestore instance ID and region/zone (`--zone` is a legacy alias). Required unless `--all`. | | `--project` | GCP project ID (defaults to active `gcloud` project). | | `--client-ip` / `--client-subnet` | Client IP or CIDR to evaluate against export ACLs and ingress firewall rules. | | `--json` | Emit machine-readable JSON on stdout (narrative report goes to stderr). | | `--apply-fix` | Execute generated remediation commands. **Only pass after explicit user confirmation.** |

Option 2: Filestore MCP Tools / REST API / `gcloud` CLI

  • **MCP Tools**: Call `get_instance(name='projects/{project_id}/locations/{location}/instances/{instance_id}')` and inspect `fileShares[0].nfsExportOptions` and `networks[0].network`.
  • **Native REST API (`call_gcp_api`)**: Invoke `service="file"`, `version="v1"`, `resource_path="projects/{project_i
Read more
Ships withgoogle-skills

This repository contains Agent Skills for Google products and technologies, including Google Cloud.

Get the whole plugin

Other skills on google-skills.