AWS DevOps Engineer Professional
942 incident response problems that help with AWS DevOps Engineer Professional prep.
Read first
When the CI cache restores the wrong dependency graphAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when package.json, the lockfile, and artifacts no longer agree even after a cache hit.CI/CD3 min readWhen GitHub Actions succeeds but only the rollout failsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the build logs look fine but the failure surfaces only on the target deploy cluster or runtime.CI/CD3 min readThe checking order when GitHub Actions succeeds but only the deploy failsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the workflow is green but the failure happens only in the rollout, promotion, or health check stage.CI/CD3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
CICD-001Finding the real failure point in GitHub Actions build logsA training scenario for isolating the true cause from logs where npm dependency conflicts and cache traces are mixed together.ReviewedCI/CDIntermediate20 minFreeCICD-002Recovering a container deployment where the latest tag blocks rollbackCovers how to redesign a safe rollback structure in a pipeline that has no image versioning strategy.ReviewedCI/CDAdvanced25 minProCICD-007Builds failingA scenario that narrows down the root cause, centered on realigning the cache key strategy and lockfile consistency, in the situation of builds failing because the cache key gets tangled after a Node version upgrade.ReviewedCI/CDBeginner16 minFreeCICD-009Deployment failingA scenario that narrows down the root cause, centered on checking the permission-policy difference by event type, in the situation of a deployment failing because the secret is empty only on tag releases.ReviewedCI/CDIntermediate21 minFreeCICD-021Build cache key mismatch after lockfile updateA pipeline stays green on one branch and fails on another because the dependency cache key no longer matches the lockfile layout.ReviewedCI/CDBeginner17 minFreeCICD-031GITHUB_TOKEN read-only default blocks release provenance uploadThe workflow can build and test successfully, but the release job fails when it tries to publish attestations or update release metadata with a narrower token scope.ReviewedCI/CDIntermediate21 minPro
All problems (942)
npm ci fails with EUSAGE: only the PR that edited package.jsonnpm ci fails with EUSAGE: only the PR that edited package.json is a hands-on troubleshooting drill. Fix the lock file when npm ci refuses to install. ci-cd-workflow-debugging needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무...ReviewedCI/CDBeginner3 minFreeDocker build cache not used: npm ci reruns even when only the README changedDocker build cache not used: npm ci reruns even is a hands-on troubleshooting drill. Order Dockerfile steps so the dependency layer stays cached. build-cache-hygiene needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 build...ReviewedCI/CDBeginner3 minFreegit push rejected (fetch first): a push that worked 30 minutes agogit push rejected (fetch first): a push that worked 30 minutes ago is a hands-on troubleshooting drill. Know what 'fetch first' means and why --force is the wrong fix. repository-access needs to be checked by narrowing scope, recent change, and the current live signal before r...ReviewedCI/CDBeginner3 minFreeActions fails only on fork PRs: Username and password requiredActions fails only on fork PRs: Username and password required is a hands-on troubleshooting drill. Know why repository secrets are not passed to pull requests from forks. pull-request-security needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedCI/CDBeginner3 minFreeSelf-hosted runner: No space left on device in the middle of buildsSelf-hosted runner: No space left on device in the middle of builds is a hands-on troubleshooting drill. Find what fills a long-lived runner's disk. GitHub Runner Hygiene needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는...ReviewedCI/CDBeginner3 minFreedocker build invalid reference format: the image tag is empty in GitHub Actionsdocker build invalid reference format: the image tag is empty in GitHub... is a hands-on troubleshooting drill. Learn how values pass between GitHub Actions steps. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, recent change, and the current live signa...ReviewedCI/CDBeginner3 minFreeCICD-009Deployment failingA scenario that narrows down the root cause, centered on checking the permission-policy difference by event type, in the situation of a deployment failing because the secret is empty only on tag releases.ReviewedCI/CDIntermediate21 minFreeCICD-103Helm post-renderer strips readiness probes from the canary manifest and Argo CD approves a broken rolloutThe application renders cleanly, but the post-processing step removes health checks from just the canary variant so progressive delivery never sees a meaningful gate.ReviewedCI/CDIntermediate18 minFreeCICD-001Finding the real failure point in GitHub Actions build logsA training scenario for isolating the true cause from logs where npm dependency conflicts and cache traces are mixed together.ReviewedCI/CDIntermediate20 minFreeCICD-064Helm post-upgrade hook Job never completes and blocks the release promotion gateThe chart renders correctly, but the deployment never settles because a hook job keeps restarting and Helm treats the upgrade as unfinished.ReviewedCI/CDIntermediate20 minFreeCICD-007Builds failingA scenario that narrows down the root cause, centered on realigning the cache key strategy and lockfile consistency, in the situation of builds failing because the cache key gets tangled after a Node version upgrade.ReviewedCI/CDBeginner16 minFreeCICD-116Registry cleanup deletes the rollback tag that the audit manifest still references as the approved fallback releaseThe platform kept the primary image, but rollback fails because governance artifacts still point at a tag the registry retention job already removed.ReviewedCI/CDIntermediate16 minFreeCICD-109Self-hosted runner label matches the build queue but the runner misses the Docker socket mount and image builds fail only thereThe job lands on the intended runner group, yet one fleet member lacks the host capability the workflow assumes every labeled runner provides.ReviewedCI/CDIntermediate16 minFreeCICD-021Build cache key mismatch after lockfile updateA pipeline stays green on one branch and fails on another because the dependency cache key no longer matches the lockfile layout.ReviewedCI/CDBeginner17 minFreeCICD-038Publish workflow never startsA formatting or version-bump workflow commits successfully, but the downstream publish workflow never runs because the triggering push used the repository token.ReviewedCI/CDBeginner16 minFreeCICD-1612A Docker image push failsOne image push fails right after a secret rename.ReviewedCI/CDBeginner6 minFreeCICD-1611A GitHub Actions deploy is skippedOne deployment gate still points to the branch name used before renaming main.ReviewedCI/CDBeginner6 minFreeCICD-1615A Helm release uses old valuesOne CI release uses old values after a file rename.ReviewedCI/CDBeginner7 minFreeCICD-1616A Terraform apply fails in one workspaceOne Terraform workspace still fails after environment slug cleanup.ReviewedCI/CDBeginner7 minFreedocker push: denied: requested access to the resource is denieddocker push: denied: requested access to the resource is denied is a hands-on troubleshooting drill. Check which registry an image tag actually points to before debugging credentials. GitHub Container Image Delivery needs to be checked by narrowing scope, recent change, and th...ReviewedCI/CDBeginner14 minFree