vastai-debug-bundle

v2026.09.24

Collect a minimal, redacted Vast.ai diagnostic manifest that support can act on without exposing API keys, SSH material, workload secrets, or unnecessary customer data. Use when escalating a platform or workload fault. Trigger with: "build a Vast.ai debug bundle", "collect Vast.ai support evidence", "redact Vast.ai diagnostics".

GitHub
Install command
npx skhub add jeremylongshore/vastai-debug-bundle
Markdown
SKILL.md

Redacted Vast.ai Support Manifest

Overview

A useful bundle binds exact resource IDs, CLI version, timestamps, states, and redacted errors. It does not archive the entire environment, shell history, account profile, or secret-bearing generated curl commands.

Prerequisites

  • Incident window, affected instance/endpoint/workergroup IDs, and symptom
  • Evidence classification, retention period, support case owner, and approved destination
  • Redaction rules for API keys, URLs, emails, storage credentials, model inputs, and customer data

Instructions

Step 1: Freeze the collection plan

List each command, field, time range, and justification before reading data. Exclude environment dumps and home-directory archives.

Step 2: Collect control-plane facts

Record CLI version, redacted show user, structured instance or Serverless state, offer/template identity, and timestamps.

Step 3: Collect bounded logs

Retrieve only the relevant container, endpoint, or workergroup log window and filter known credential and payload fields.

Step 4: Capture request diagnostics safely

Use --explain or equivalent call metadata only when the output is reviewed for bearer tokens and query credentials before storage.

Step 5: Redact and inventory

Replace sensitive values consistently, retain resource IDs needed by support, and create file hashes plus a redaction attestation.

Step 6: Validate the bundle

Have a second pass search for key patterns, private keys, URLs with credentials, emails, and workload secrets before sharing.

Authentication

Prefer a read-only scoped key. Never store VAST_API_KEY, key-file contents, SSH private material, webhook secrets, cloud credentials, or Authorization headers in the bundle.

Tool Discipline

Use Read and Grep to inspect manifests, configuration, provider output, and existing tests before proposing a mutation. Use Write or Edit only for the approved plan, implementation, test, or redacted receipt; do not create, update, destroy, or fund Vast.ai resources without explicit operator approval.

Output

  • Collection scope and command manifest
  • Redacted evidence files with hashes and time bounds
  • Redaction attestation, retention date, and support handoff receipt

Return incident window, resource IDs, collected fields, excluded classes, file hashes, redaction result, and recipient.

Examples

A support manifest contains CLI version, one offline instance record, the last 100 redacted log lines, template hash, timestamps, and checksums; it excludes environment variables and generated Authorization headers.

Error Handling

FailureResponse
A secret detector firesQuarantine the bundle, rotate exposed credentials if necessary, and rebuild from source.
Requested data exceeds the incident windowExclude it unless the case owner documents a need.
Resource has already been destroyedUse retained external receipts; do not fabricate live state.
Support asks for raw credentialsRefuse and provide a redacted reproduction instead.

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/vastai-debug-bundle

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8