Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-1327A DaemonSet appears healthy and one node family never gets the agentA fleet adds a new node pool image and later one DaemonSet quietly skips those nodes while remaining healthy elsewhere.KubernetesAdvanced15 minProK8S-1392A Gatekeeper policy looks unchanged and one namespace starts failing admissionA Gatekeeper policy looks unchanged and one namespace starts failing admission focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Admission drift can hide in CRD conversion...KubernetesAdvanced15 minProK8S-1402A Gatekeeper policy rollout works on most requests and one API server still...A Gatekeeper policy rollout works on most requests and one API server still... focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Control-plane partial restarts can leave admission and conversion behavi...KubernetesAdvanced15 minProK8S-1367A kube-proxy migration to IPVS mostly works and one node blackholes service trafficA cluster networking optimization is rolled out and later only one node intermittently drops service traffic even though the migration reported success.KubernetesAdvanced15 minProK8S-1377A kube-proxy migration to IPVS mostly works and one node blackholes service trafficA network optimization rollout completes and later one node alone intermittently drops service traffic.KubernetesAdvanced15 minProK8S-1347A kube-proxy migration to IPVS passes and one service blackholes trafficA kube-proxy migration to IPVS passes and one service blackholes traffic focuses on network-segmentation and asks the reader to isolate the key signal in Kubernetes. Mode migrations can fail asymmetrically even when the daemonset rollout...KubernetesAdvanced15 minProK8S-1399A kube-proxy replacement migration works on worker nodes and one control...A kube-proxy replacement migration works on worker nodes and one control... focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. Pod path success does not prove host-network exception beha...KubernetesAdvanced15 minProK8S-1357A kubeadm worker join passes and pods cannot pull imagesA kubeadm worker join passes and pods cannot pull images focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. Successful node join does not prove the node runtime inherited the same registry assumptio...KubernetesAdvanced15 minProK8S-1345A kubelet certificate rotation succeeds and nodes still flip NotReadyA certificate maintenance window completes and afterward node readiness or metrics become inconsistent despite successful kubelet rotation.KubernetesAdvanced15 minProK8S-1353A kubelet eviction storm begins (eviction-threshold-hit-on-imagefs-not-dashboard-rootfs)A kubelet eviction storm begins (eviction-threshold-hit-on-imagefs-not... focuses on incident-response and asks the reader to isolate the key signal in Kubernetes. Storage health dashboards can be misleading if they do not align with kub...KubernetesAdvanced15 minProK8S-1333A Loki ingestion path stays healthy and dashboards still miss one tenantA Loki ingestion path stays healthy and dashboards still miss one tenant focuses on Identity And Access and asks the reader to isolate the key signal in grafana. Multi-tenant observability bugs often come from query path identity, not from ing...KubernetesAdvanced15 minProK8S-1325A projected service account token looks valid and a custom API aggregation...A projected service account token looks valid and a custom API aggregation... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. In Kubernetes auth, a valid token can still be unusable if its aud...KubernetesAdvanced15 minProK8S-1337A Prometheus remote write queue stays green and one downstream alert never...A Prometheus remote write queue stays green and one downstream alert never... focuses on Deployment Governance and asks the reader to isolate the key signal in grafana. A healthy local dashboard does not prove the remote alert pipe...KubernetesAdvanced15 minProK8S-1359A PVC snapshot restore looks complete and the app still corrupts writesA PVC snapshot restore looks complete and the app still corrupts writes focuses on incident-response and asks the reader to isolate the key signal in Kubernetes. Friendly snapshot names can mask wrong lineage in multi-tenant or repe...KubernetesAdvanced15 minProK8S-1384A Rancher-managed cluster upgrade completes and one node pool never rejoinsA Rancher-managed cluster upgrade completes and one node pool never rejoins focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Managed cluster reconnect failures often live in agent bootstra...KubernetesAdvanced15 minProK8S-1389A service mesh egress gateway looks healthy and outbound TLS still failsA service mesh egress gateway looks healthy and outbound TLS still fails focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Mesh trust rotations can fail asymmetrically when some namespa...KubernetesAdvanced15 minProK8S-1385A StatefulSet with local PVs keeps one pod PendingA StatefulSet with local PVs keeps one pod Pending focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. Storage binding failures often come from stale locality metadata surviving longer than the no...KubernetesAdvanced15 minProK8S-1363A webhook certificate is valid and admission still times outA webhook certificate is valid and admission still times out focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Webhook health from pods does not prove the apiserver can reach the same endpoint.KubernetesAdvanced15 minProK8S-1373A webhook certificate is valid and admission still times outA webhook certificate is valid and admission still times out focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Pod reachability is not proof of apiserver reachability for admission webhooks.KubernetesAdvanced15 minProK8S-1335An EKS workload reaches AWS APIs and still fails one secret fetchAn EKS workload reaches AWS APIs and still fails one secret fetch focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Cross-cluster portability often fails at subtle identity defaults rather than at obvio...KubernetesAdvanced15 minPro