← L2 Support: diagnose, mitigate, and escalate
03 / 6 · 40 MIN

Diagnosis by layer

Interpret service, DNS, HTTP, TLS, and resource states.

Concept and mechanism

Technical signals have specific meanings. In systemd, enable configures future activation according to the unit and does not start the service by itself. An active process can still return incorrect responses. In BIND dig, exit code zero includes an NXDOMAIN response: DNS replied, but the queried name was not found in that context. Record resolver, name, type, and response. By default, curl can finish without a transport error while receiving HTTP 500; inspect HTTP status and relevant content. Since curl 7.76.0, fail-with-body can retain the body while reporting HTTP errors. Keep these layers distinct when closing an incident.

Guided application

In a fictional TLS diagnosis using OpenSSL 3.5 s_client, the tool can continue after verification errors. Inspect output and validation policy; verify_return_error changes that behavior. Establishing a connection does not demonstrate certificate trust. On a filesystem, free data blocks do not exclude inode exhaustion; df -i observes a different dimension. In Kubernetes, Pending includes waiting for scheduling and container setup, including image downloads. Inspect events and specific state before attributing failure to the scheduler. These examples teach selection of the next observation without making production changes from a summary status alone.

IN PRACTICE

dig: exit 0 and NXDOMAIN; curl: exit 0 and HTTP 500. Meaning depends on the layer.

Common pitfalls

Enabled as active; zero exit as functional success; Pending as a single cause.

Related topics: Triage based on impact · Useful hypotheses and evidence · Operational mitigation and validation

Take this idea with you

Interpret each signal at its own layer and confirm the functional outcome.

Create account

Reference: curl command line manual · Operational support; PostgreSQL 18, OpenSSL 3.5 and BIND 9.20.29 examples; reviewed 2026-09-30