# Diagnostics & Debugging

Keel writes a diagnostic trace for each command to the rotating log at `~/.keel/logs/keel.log` and captures panics. Use `keel debug` to investigate a problem or prepare a bug report.

```bash
# Show recent diagnostic log entries (last 50 lines by default)
keel debug logs
keel debug logs -n 200
keel debug logs --follow        # stream new entries as they are written
keel debug logs --all

# Print the path to the log file
keel debug path

# Print version, platform, and log diagnostics for bug reports
keel debug info
```

## Verbose and cautious modes

Two project-level settings control command output. They apply to every environment and can be overridden for one invocation.

- **verbose** prints each action as it happens.
- **cautious** previews state-changing actions and asks for confirmation.

```bash
keel settings                       # list current values
keel settings get cautious
keel settings set cautious true

keel deploy --verbose               # override for a single run
keel up --cautious
```

You can also toggle both from the dashboard's settings overlay (`s`), which persists the change to `keel.yml`.

## Recovering from an interrupted operation

An interrupted `keel up` or `keel destroy` (Ctrl-C, lost connection, canceled CI job) can leave a state lock held or resources untracked. `keel rescue` diagnoses and repairs both — see [Interruptions & Rescue](./rescue).

## What's in the log — and what isn't

The debug log records AWS calls, subprocess invocations, and errors. It excludes MFA seeds, `otpauth://` URIs, SSM secret values, and access keys.
