CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-1262Cluster autoscaler sees unschedulable pods but never scalesK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced16 minProK8S-1303Leader election looks healthy until the controller is Helm-migratedA controller is reinstalled or moved between namespaces and begins flapping without an obvious RBAC denial.KubernetesAdvanced16 minProK8S-1315Loki ingestion is healthy and dashboards are empty for one tenantLoki ingestion is healthy and dashboards are empty for one tenant focuses on Identity And Access and asks the reader to isolate the key signal in grafana. Empty dashboards can be a tenant identity mismatch even when ingestion is healthy.KubernetesAdvanced16 minProK8S-1307The metrics adapter serves custom metrics but the HPA still failsA service rename or chart refactor leaves autoscaling frozen even though direct adapter requests look healthy.KubernetesAdvanced16 minProK8S-159A canary Service routes to the right pods, but topology spread on the new ReplicaSet sends all canary capacity to one zone and synthetic tests misjudge global readinessTraffic experiments are statistically misleading because one zone now dominates the canary population.KubernetesAdvanced17 minProCICD-138A deployment circuit breaker watches the startup probe, but the one-off migration pod shares the same label and trips the release incorrectlyApplication pods are healthy, yet rollout halts because the failure budget includes a different workload type with a separate lifecycle.CI/CDAdvanced17 minProK8S-1320A kubelet authentication issue appears only on Windows nodesA mixed-node cluster upgrades and only Windows nodes begin showing authentication failures against the API server path.KubernetesAdvanced17 minProK8S-1265A LoadBalancer Service works from inside the cluster but external traffic...A LoadBalancer Service works from inside the cluster but external traffic... focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. Success from inside the cluster can hide that the backend applies different policy...KubernetesAdvanced17 minProK8S-1270A LoadBalancer Service works from inside the cluster but external traffic...A LoadBalancer Service works from inside the cluster but external traffic... focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. Success from inside the cluster can hide that the backend applies different policy...KubernetesAdvanced17 minProK8S-131A NetworkPolicy allows the outbound proxy but still blocks OCSP and CRL endpoints, so strict clients fail external TLS validationEgress seems mostly open, yet revocation checks cannot complete because only the primary proxy path was modeled.KubernetesAdvanced17 minProK8S-1291A node group looks healthy but fresh pods hit image pull timeoutsA cluster scales to a new node group and only workloads landing there begin failing image pulls.KubernetesAdvanced17 minProK8S-1285A node group scales out but new pods still fail CNI allocationEKS nodes come up successfully and pods still hit IP allocation failures while another subnet in the VPC shows plenty of free space.KubernetesAdvanced17 minProK8S-1283A PodDisruptionBudget looks permissive enough but cluster upgrades still stallA managed cluster upgrade stalls on one workload even though operators believe the PodDisruptionBudget should allow at least one eviction.KubernetesAdvanced17 minProK8S-1293A PVC remains PendingA stateful set scales one more replica and the claim exists but the pod never reaches Running.KubernetesAdvanced17 minProK8S-140After an upgrade, the kubelet image credential provider binary path changes, and pulls from the private registry fail on the new nodes onlyLegacy nodes keep working, but fresh workers cannot execute the helper that mints registry credentials.KubernetesAdvanced17 minProK8S-1279An external-dns update looks successful but users still hit the wrong load balancerA cluster migration changes DNS and the automation pipeline reports success while real traffic continues to resolve the former endpoint.KubernetesAdvanced17 minProK8S-1299An ingress controller pod is healthy but its target group never updatesA controller chart is upgraded and later ingress state stops reconciling even though the pods remain healthy.KubernetesAdvanced17 minProK8S-1297An IRSA role works in one namespace but fails in anotherA chart upgrade lands and one namespace loses AWS API access while another using the same role keeps working.KubernetesAdvanced17 minProK8S-1273Cluster autoscaler sees pending pods but still refuses to scaleTainted workloads remain Pending even though more nodes should solve the problem and the autoscaler deployment appears healthy.KubernetesAdvanced17 minProK8S-1305Grafana Loki reads logs and still misses new alertsA log platform migrates to object storage and alerting becomes unreliable despite apparently valid credentials and buckets.KubernetesAdvanced17 minPro