Certification942 problems· 22 reviewed

AWS DevOps Engineer Professional

942 incident response problems that help with AWS DevOps Engineer Professional prep.

All problems (942)

CICD-010GitOps sync repeatedly failing due to a Helm values merge mistakeGitOps sync repeatedly failing (Rollout Stuck) is a hands-on troubleshooting drill. Covers a problem where per-environment values overlays get tangled and the GitOps tool keeps detecting drift. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, recent chan...CI/CDAdvanced27 minProCICD-019In a blue-green deploy, traffic is switched but the background worker stays on the old versionA situation where success was judged from the web-traffic switch alone, but the async worker remained on the previous version.CI/CDAdvanced28 minProCICD-005Jobs waiting forever due to a self-hosted runner label mismatchJobs waiting forever (Auth and Session Failure) is a hands-on troubleshooting drill. A scenario for tracking labels, groups, and permission scope when the runner is alive but jobs are not picked up. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, recent...CI/CDIntermediate19 minProCICD-020Only nightly builds failing due to a package registry rate limitA situation where it is fine during the day, but parallel builds pile up at certain hours and hit an external package registry limit.CI/CDIntermediate22 minProCICD-1191Private submodule checkout breaksA team copies a public submodule checkout recipe. The main repo checks out cleanly, but private submodules fail depending on whether the SSH agent was configured before or after checkout.CI/CDIntermediate22 minProCICD-1364A private registry behind NGINX handles login and small layers fineA private registry behind NGINX handles login and small layers fine focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Path-specific protection can succeed on auth and manifest routes while silently breaking long-l...CI/CDAdvanced15 minProCICD-097S3 static site deploy uploads the new assets but old signed URLs stay embedded in the manifestThe files exist in the bucket, yet clients keep failing because the generated manifest still references stale signed asset URLs from the previous build.CI/CDAdvanced16 minProCICD-133A blue-green DNS cutover succeeds, but the CDN origin pin remains on the old backend and a percentage of traffic never movesThe authoritative name points correctly, yet cached origin metadata upstream still holds users on the retired stack.CI/CDAdvanced18 minProCICD-155A blue-green switch updates the public ALB target group, but internal service discovery still resolves to the blue stack and background jobs keep writing thereThe front door moved cleanly, yet internal callers remain on the previous environment because they use a different discovery source.CI/CDAdvanced18 minProCICD-142A reusable workflow updates its permissions block, but the caller workflow still downgrades the token scope and deployment cannot assume the cloud roleThe shared workflow looks fixed, yet the effective identity is still too narrow because the caller constrains it further.CI/CDAdvanced18 minProCICD-110Argo CD ignoreDifferences hides drift in service account annotations and the workload loses cloud identity on syncGit and cluster appear in sync, yet the runtime identity broke because a diff-ignore rule masked the exact annotation that binds the pod to its cloud role.CI/CDAdvanced18 minProCICD-094Argo CD sync succeeds but a namespace label policy silently strips the network exemption labelThe app is deployed cleanly, yet the workload breaks because a cluster policy rewrites the namespace labels the app depends on for networking.CI/CDAdvanced18 minProCICD-102OIDC exchange fails only in reusable workflowsA shared workflow refactor succeeds for linting but deployment breaks because the federated identity provider expects a different token audience than the child workflow emits.CI/CDAdvanced18 minProCICD-113Signing verifies the tarball provenance but deployment consumes an OCI reference that was never attestedThe release report shows a verified artifact, but the runtime image came from a different reference path than the object the signing step covered.CI/CDAdvanced18 minProCICD-204A blue-green cutover moves public ingress while internal service discovery stays on the previous stack during a failover rehearsalPublic traffic shifts cleanly but batch or backend callers continue writing into the old environment. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-168A reusable workflow assumes a broader OIDC scope than the caller actually grants during a failover rehearsalThe shared logic is valid, but the effective token permissions are still narrower than the deployment step needs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-068CloudFront keeps serving stale index.html after a blue-green cutoverThe new environment is healthy, but users still load references to the old asset set because cache invalidation and origin switch ordering were not coordinated.CI/CDAdvanced19 minProCICD-079Mutable image tag makes an ECS rollback pull a newer build than the failed releaseThe rollback logic points at the previous task definition, yet the service still launches the wrong container because both revisions refer to the same mutable image tag.CI/CDAdvanced19 minProCICD-091Release manifest points at a digest that exists only in the staging registryThe promotion metadata looks valid, but production cannot pull the image because the referenced digest was never replicated to the target registry.CI/CDAdvanced19 minProCICD-078Canary analysis passes against cached CDN responses instead of the origin traffic it was meant to judgeThe rollout looks healthy by metric, but the analysis is reading cache-hit behavior and not the new origin path that users will actually exercise after promotion.CI/CDAdvanced20 minPro