Skip to main content

GCE Rescue

V2 CI PyPI version Python License

Rescue unbootable Google Compute Engine VMs by swapping disks on the same VM — no new instance created, same IP, no data loss. Creates a safety snapshot before any changes.

Auto-fix path: The repair command reads serial console output, identifies the boot failure, and applies a fix automatically end to end.

Rescue path: When auto-fix is not available for the detected issue, the rescue command swaps your broken boot disk with a rescue disk and attaches the original boot disk as a secondary disk, providing a rescue environment for manual repair. Once fixed, the restore command puts your fixed boot disk back.

gce-rescue diagnose my-vm --zone=us-central1-a    # What's wrong?
gce-rescue repair my-vm --zone=us-central1-a      # Auto-fix it

GCE Rescue Workflow

Note: GCE Rescue is not an officially supported Google Cloud product. The Google Cloud Support team maintains this repository.

Requirements: Python >= 3.9, gcloud CLI, roles/compute.instanceAdmin.v1 IAM role.

Installation

Google Cloud Shell (recommended)

Open Cloud Shell — Python, gcloud, and authentication are already set up.

pip install gce-rescue

Verify the installation:

gce-rescue -h

If gce-rescue is not found after install, start a new shell session or run:

export PATH="$HOME/.local/bin:$PATH"
Local Machine

Linux / macOS

curl -sSL https://raw.githubusercontent.com/GoogleCloudPlatform/gce-rescue/main/install.sh | bash

May require sudo if Python or pip is not installed.

Windows (run PowerShell as Administrator)

irm https://raw.githubusercontent.com/GoogleCloudPlatform/gce-rescue/main/install.ps1 | iex

The installers handle all prerequisites (Python, gcloud, PATH, authentication) and will prompt before installing anything.


Install from source (requires Python >= 3.9, gcloud CLI, Git)

git clone https://github.com/GoogleCloudPlatform/gce-rescue.git
cd gce-rescue
pip install .

Usage

Start with diagnose — understand what's wrong (safe, read-only)

gce-rescue diagnose VM_NAME --zone=ZONE

Auto-fix available? — let repair handle it automatically

gce-rescue repair VM_NAME --zone=ZONE

Already know the fix? — supply your own fix script (skips diagnosis)

gce-rescue repair VM_NAME --zone=ZONE --fix-script=fix.sh

Ideal for large-scale events where many VMs share one known fix: the script runs against the mounted boot disk, then the VM is restored and boot-verified automatically. Add --quiet for automation.

Need manual access? — enter rescue mode, fix it yourself

gce-rescue rescue VM_NAME --zone=ZONE

# SSH/RDP in, fix the issue on /mnt/sysroot

gce-rescue restore VM_NAME --zone=ZONE
Command What it does Modifies VM?
diagnose Identifies boot errors from serial console output No
repair Diagnoses and fixes boot issues automatically Yes
rescue Provides a rescue environment for investigation via SSH/RDP Yes
restore Reverses rescue, puts your fixed boot disk back Yes

All operations create a snapshot before changes, roll back automatically on failure, and can resume if interrupted.

Sample output: diagnose
$ gce-rescue diagnose my-vm --zone=us-central1-a
Diagnosis: my-vm (us-central1-a)
Status:    RUNNING
OS:        Linux (debian-12-bookworm, x86_64, Free)
Result:    Found 1 boot error(s)

  [fstab_bad_uuid] Bad UUID in /etc/fstab (critical)
    Line: UUID=abcd-1234  /data  ext4  defaults  0  2
    Fix:  Remove or correct the fstab entry, then reboot

  Recommended: gce-rescue repair my-vm --zone=us-central1-a

Authentication

Environment Setup
Cloud Shell Pre-authenticated, nothing to do
GCE VM (with service account) Automatic via metadata server
GCE VM (without compute scopes) gcloud auth application-default login
Local machine gcloud auth application-default login

More info: Application Default Credentials

Flags

Flag Description
--zone GCP zone (required)
--project GCP project (default: current gcloud config)
--no-snapshot Skip safety snapshot (faster)
--rescue-image Custom rescue disk image URL (must match VM's OS family + architecture). Useful for restricted-image org policies or hardened rescue environments. Available for rescue and repair.
--fix-script Path to a custom fix script (bash on Linux, PowerShell on Windows) to run against the affected disk after it is mounted — skips diagnosis. With repair the VM is restored and boot-verified afterwards; with rescue it stays in rescue mode for inspection. The affected disk is mounted at /mnt/sysroot on Linux; on Windows its partitions get drive letters from D: onward (iterate non-C: volumes rather than assuming D:).
--verification-timeout Seconds to wait for the rescue VM startup script to complete (serial console marker). Overrides the OS-aware default (Linux: 300, Windows: 600). Raise it for slow-booting VMs. Available for rescue and repair.
--quiet No confirmation prompts (for automation)
--format Output format: json, yaml, table

Update check

At the end of rescue, restore, diagnose, and repair, the CLI checks PyPI (https://pypi.org/pypi/gce-rescue/json) for a newer release and prints an upgrade notice to stderr if one exists. The check runs at most once every 24 hours (cached in ~/.config/gce-rescue/version-check.json), never delays or fails a command, and is skipped entirely with --quiet, with machine-readable --format values, or when the environment variable GCE_RESCUE_DISABLE_VERSION_CHECK=1 is set — use the variable in restricted networks where outbound calls to pypi.org are unwanted.

Features

Feature Description
Linux + Windows Auto-detects OS, uses appropriate rescue environment
Boot Diagnostics Serial console analysis for fstab, GRUB, kernel, filesystem errors
Auto-Repair Automated fix for fstab errors (more categories planned)
Custom Fix Scripts Bring your own fix (--fix-script) for known issues at scale — no diagnosis needed
Automatic Rollback Operations roll back on failure
Session Recovery Resume or rollback interrupted operations
Safety Snapshots Backup snapshot before any changes (default)
ARM64 Support Automatic architecture detection

Permissions

roles/compute.instanceAdmin.v1 includes all permissions needed for every command.

Command Minimum Role
diagnose roles/compute.viewer
rescue, restore, repair roles/compute.instanceAdmin.v1
gcloud projects add-iam-policy-binding PROJECT_ID \
    --member="user:EMAIL" \
    --role="roles/compute.instanceAdmin.v1"
Full permissions matrix
Permission diagnose repair rescue restore
compute.projects.get x x x x
compute.instances.get x x x x
compute.instances.getSerialPortOutput x x x
compute.instances.stop x x x
compute.instances.start x x x
compute.instances.attachDisk x x x
compute.instances.detachDisk x x x
compute.instances.setMetadata x x x
compute.disks.create x x
compute.disks.delete x x x
compute.disks.get x x x
compute.disks.createSnapshot x* x*
compute.snapshots.create x* x*
compute.snapshots.get x* x*
compute.snapshots.list x x
compute.snapshots.delete x* x*

* Skippable with --no-snapshot

V1 Legacy

V1 is available as gce-rescue-v1 for backward compatibility:

gce-rescue-v1 -n VM_NAME -z ZONE -p PROJECT

See the V1 documentation for details.

Uninstall

pip uninstall gce-rescue

# Linux/macOS (if installed via install script)
rm -rf ~/.gce-rescue

Contact

GCE Rescue Team: gce-rescue-dev@google.com

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

gce_rescue-2.4.0.tar.gz (312.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

gce_rescue-2.4.0-py3-none-any.whl (383.9 kB view details)

Uploaded Python 3

File details

Details for the file gce_rescue-2.4.0.tar.gz.

File metadata

  • Download URL: gce_rescue-2.4.0.tar.gz
  • Upload date:
  • Size: 312.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for gce_rescue-2.4.0.tar.gz
Algorithm Hash digest
SHA256 c0c5394bab64b7634f7c5b7565394a9c165aa958c39b255d4cc86ed2b7795837
MD5 59a64ca694e8d51120293b8244b8af44
BLAKE2b-256 c2c7454ff8d5cd2462a554dfedcd51ffa84fa2e9922a2a183786f971a64dc05d

See more details on using hashes here.

Provenance

The following attestation bundles were made for gce_rescue-2.4.0.tar.gz:

Publisher: publish.yml on GoogleCloudPlatform/gce-rescue

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file gce_rescue-2.4.0-py3-none-any.whl.

File metadata

  • Download URL: gce_rescue-2.4.0-py3-none-any.whl
  • Upload date:
  • Size: 383.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for gce_rescue-2.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b90f751a19da997149cfdc2f07ec22436472e28d05f46a848dc5a5efa1ccc311
MD5 ef10effeb0b1362179541032af2885f2
BLAKE2b-256 90c5013cc77c2ebb7cf06545cd349f636fbb562d8f3e00f1c78a5264b0292ac3

See more details on using hashes here.

Provenance

The following attestation bundles were made for gce_rescue-2.4.0-py3-none-any.whl:

Publisher: publish.yml on GoogleCloudPlatform/gce-rescue

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

2.5.0

2 files

This release

2.4.0 This release

2 files

2.3.1

2 files

2.3.0

2 files

2.2.0

2 files

2.1.0

2 files

2.0.1

2 files

2.0.0

2 files

0.4

2 files

0.3

2 files

0.0.2.post1

2 files

0.0.2

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page