Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-020After a secret rotation, only certain Pods keep using the old credentialA situation where the secret was rotated but, with no rollout trigger, only some workloads still reference the old value.KubernetesIntermediate23 minProK8S-007A metrics pipeline problem where scaling does not rise even though an HPA is attachedTracks the metrics flow in a situation where resource usage is high but the autoscaler does not react.KubernetesAdvanced26 minProK8S-003Interpreting backoffLimit in a batch workload where the Job never finishesAn advanced problem that connects the batch failure retry policy with the container exit code to find the root cause.KubernetesAdvanced27 minProK8S-010A StatefulSet PVC stuck Pending, stalling the rolloutA problem where a stateful workload does not come up because StorageClass, access mode, and capacity conditions do not match.KubernetesAdvanced28 minProK8S-1199kubectl port-forward works but ingress still failsA team confirms the app with kubectl port-forward and assumes ingress must be fine. The actual failure sits earlier in the edge-hostname or path-rewrite chain.KubernetesIntermediate18 minProK8S-009Only certain APIs return 404 due to an Ingress path-rewrite rule mismatchCovers a path-rewrite problem where health checks pass but only real user requests fail.KubernetesIntermediate24 minProK8S-017Readiness time spikes sharply after a service-mesh sidecar is attachedA situation where the proxy initialization, rather than the application itself, becomes the bottleneck and lengthens startup.KubernetesIntermediate24 minProCICD-110Argo CD ignoreDifferences hides drift in service account annotations and the workload loses cloud identity on syncGit and cluster appear in sync, yet the runtime identity broke because a diff-ignore rule masked the exact annotation that binds the pod to its cloud role.CI/CDAdvanced18 minProCICD-094Argo CD sync succeeds but a namespace label policy silently strips the network exemption labelThe app is deployed cleanly, yet the workload breaks because a cluster policy rewrites the namespace labels the app depends on for networking.CI/CDAdvanced18 minProK8S-090Node reboot storm leaves CSI node plugin healthy but volume mounts failThe plugin pods appear up after recovery, but mounts still fail because kubelet is looking for a registration endpoint that the updated plugin no longer exposes in the same path.KubernetesAdvanced20 minProK8S-086Cluster Autoscaler ignores pending podsPods stay pending and autoscaling never reacts because the requested local storage profile cannot fit any node shape in the expansion group.KubernetesAdvanced21 minProK8S-097CSI snapshot restore completes but the filesystem UUID collision confuses the bootstrap scriptStorage comes back online, yet the app still fails because the restored filesystem identity collides with a value the startup logic treats as unique.KubernetesAdvanced21 minProK8S-066Projected service account token audience mismatch breaks external Vault authThe pod has a valid token, but external auth still fails because the verifier expects a different audience than the projected token request generated.KubernetesAdvanced21 minProK8S-081Readiness passes but Envoy sidecar cannot reach the control plane after a trust bundle splitThe app container is healthy, yet traffic still fails because the sidecar lost trust in the mesh control plane after the certificate bundle changed unevenly.KubernetesAdvanced21 minProK8S-068FailurePolicy Ignore lets pods start without the required security sidecarThe cluster stays available during webhook trouble, but production traffic later fails because workloads launched without the sidecar contract the platform assumes.KubernetesAdvanced22 minProK8S-028Node drain hangs on long-lived connection podsMaintenance starts correctly, but eviction never finishes because connection draining and termination hooks take too long.KubernetesIntermediate22 minProK8S-087OIDC provider issuer URL rotates and every projected token verifier in the cluster rejects new tokensToken projection still works, but consumers fail because the issuer trust path and JWKS discovery URL changed underneath long-lived verifiers.KubernetesAdvanced22 minProK8S-076VolumeSnapshot restore binds to the wrong PVC lineage after a cloned recovery testThe snapshot data is valid, but a later restore attaches to the wrong expectation chain because snapshot content and clone naming were reused too casually during testing.KubernetesAdvanced22 minProCICD-071Argo CD prune deletes a shared secretThe sync itself succeeds, but a cleanup step removes a namespace-scoped secret that another workload still depends on because ownership boundaries were not encoded safely.CI/CDAdvanced23 minProK8S-062Stale VolumeAttachment object blocks PVC reattach after a node lossThe replacement node is ready, but the workload never mounts its volume because the storage control path still believes the old attachment is active.KubernetesAdvanced23 minPro