CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-069Cross-node gRPC calls failIntra-node traffic is clean, but larger cross-node requests hang because one node pool uses a smaller effective MTU than the other path expects.KubernetesAdvanced24 minProK8S-071PodDisruptionBudget and topology spread leave no legal recovery layout after an AZ outageThe workload had enough replicas before the outage, but after one zone disappears the remaining rules make every recovery option violate either spread or disruption guarantees.KubernetesAdvanced24 minProK8S-026PriorityClass keeps critical jobs alive but starves batch queueThe urgent workload policy solves one problem and silently creates another by preventing lower-priority queues from ever catching up.KubernetesAdvanced27 minProK8S-023Admission webhook blocks only one namespace pathAdmission webhook blocks only one namespace path is a hands-on troubleshooting drill. Most workloads apply normally, but a webhook policy rejects a specific namespace because labels and defaults diverge. Kubernetes Ingress and Traffic needs to be checked by narrowing scope, re...KubernetesAdvanced28 minProK8S-1599An IRSA mapping is fixed and one pod still fails STSOne pod still fails STS after an IRSA mapping fix.KubernetesAdvanced9 minProK8S-1609An IRSA mapping is fixed and one pod still fails STSOne pod still fails STS after an IRSA mapping fix.KubernetesAdvanced9 minProK8S-1601A Cilium restore succeeds and one node still tags flows wrongOne node still tags flows wrong after a Cilium restore.KubernetesAdvanced10 minProK8S-1583A Gateway API listener is correct and one envoy pod still routes oldOne gateway pod still routes old traffic after listener refactoring.KubernetesAdvanced10 minProK8S-1593A Gateway API route changes and one listener still serves the old backendOne listener still serves the old backend after a Gateway API route change.KubernetesAdvanced10 minProK8S-1603A Gateway listener change is correct and one pod still routes oldOne gateway pod still routes old after a listener change.KubernetesAdvanced10 minProK8S-1610A mesh egress restriction is correct and one proxy still allows the old SANOne proxy still allows the old SAN after mesh egress fixes.KubernetesAdvanced10 minProK8S-1600A mesh egress restriction updates and one proxy still allows the old hostOne proxy still allows the old host after mesh egress restriction updates.KubernetesAdvanced10 minProK8S-1577A Prometheus remote-write queue drains and one shard still backpressuresOne remote-write shard continues to backpressure after tuning.KubernetesAdvanced10 minProK8S-1579An IRSA issuer changes and one DaemonSet still loses credentialsOne DaemonSet loses credentials after IRSA issuer migration.KubernetesAdvanced10 minProK8S-1589An IRSA service account is corrected and one node still fails STSOne node still fails STS after IRSA service account corrections.KubernetesAdvanced10 minProK8S-1569An IRSA token file rotates and one DaemonSet still loses AWS accessA DaemonSet loses AWS access only on nodes where an init copy path still runs.KubernetesAdvanced10 minProK8S-1581A Cilium endpoint restore works and one node still denies trafficOne node still denies traffic after endpoint restore and label normalization.KubernetesAdvanced11 minProK8S-1591A Cilium node restore completes and one service still routes wrongOne node still routes wrong after Cilium restore and CIDR recycling.KubernetesAdvanced11 minProK8S-1509A Gateway API canary route attaches and all traffic still lands on stableCanary weights never take effect on one controller revision after a Gateway API migration.KubernetesAdvanced11 minProK8S-1499A Gateway API canary route looks correct and 100 percent of traffic still lands on stableCanary weight changes never take effect after moving from Ingress to Gateway API on one controller revision.KubernetesAdvanced11 minPro