Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-091Mutating webhook times out only on large Pod specsSmall workloads admit fine, but larger ones fail because the webhook path includes a proxy with a body-size setting lower than the API server request.KubernetesAdvanced18 minProK8S-1264Pods resolve names intermittentlyK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced18 minProK8S-1269Pods resolve names intermittentlyCluster DNS appears green in dashboards, but application pods on certain nodes still time out when resolving service or external names.KubernetesAdvanced18 minProK8S-1275Pods schedule normally but lose persistent IP assignmentPods begin failing to start with networking errors on nodes that still appear lightly loaded from a compute perspective.KubernetesAdvanced18 minProK8S-151The ingress controller trusts X-Forwarded-Proto from the external load balancer, but an internal hop rewrites it and secure redirects begin loopingTLS is terminated correctly, yet downstream protocol awareness is now inconsistent across hops.KubernetesAdvanced18 minProK8S-125The kubelet credential provider cache expires before the node refreshes its cloud identity, and private registry pulls fail only after several hoursNew pods work immediately after boot, but later image pulls break because two credential lifecycles drift apart.KubernetesAdvanced18 minProK8S-192A route binds to the right listener while a cross-namespace backend reference is still unauthorized during a failover rehearsalThe object graph looks connected and the security boundary still prevents end-to-end flow. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced19 minProK8S-1246A Service has endpoints and pods are Ready but requests still failA newly introduced node class hosts healthy pods, but clients reaching those pods still time out while the same Service works from older nodes.KubernetesAdvanced19 minProK8S-1251A Service has healthy pods and endpoints but requests still failA new node group joins an EKS cluster and only pods placed there start failing for Service traffic despite being fully Ready.KubernetesAdvanced19 minProK8S-1243A StatefulSet pod restarts forever after rescheduleA stateful workload reschedules after a node event and later fails repeatedly with permission errors on the data path.KubernetesAdvanced19 minProK8S-1253A StatefulSet volume reattaches after reschedule but write access still failsAfter a node failure, a stateful workload restarts on another node and immediately fails on file permissions despite the volume attaching cleanly.KubernetesAdvanced19 minProK8S-1248A StatefulSet volume reattaches successfully but startup still failsAfter a node event, a stateful workload comes back on another node and immediately fails with permission errors against an attached data volume.KubernetesAdvanced19 minProK8S-073Ephemeral-storage eviction startsThe nodes still have CPU and memory, but pods get evicted because local ephemeral storage fills when retry-heavy request logging lands in emptyDir volumes.KubernetesAdvanced19 minProK8S-1229Image pulls fail only on one node groupA new node group joins and only workloads scheduled there begin showing image pull failures for a private registry.KubernetesAdvanced19 minProK8S-1256Pods in a private EKS subnet enter ImagePullBackOffA new private node group joins EKS and only workloads pulling from ECR begin failing despite valid image references and node IAM roles.KubernetesAdvanced19 minProK8S-092Projected CA bundle on one namespace lags and only that team's jobs fail outbound TLS validationCluster TLS trust is mostly healthy, but one namespace still mounts an older CA bundle and its jobs reject the new upstream certificate path.KubernetesAdvanced19 minProK8S-101StatefulSet ordinal restarts collide with the PodDisruptionBudget and quorum never reforms after node maintenanceOne replica keeps waiting for another to recover, but eviction protections prevent the exact restart sequence the quorum algorithm needs.KubernetesAdvanced19 minProK8S-1255A new node group becomes Ready but only pods there failA replacement or expansion node group joins the cluster and only workloads placed there begin failing on startup or networking operations.KubernetesAdvanced20 minProK8S-1250A node group becomes Ready but some workloads still failA fresh node group joins an EKS cluster and only pods landing there begin failing on startup or networking operations.KubernetesAdvanced20 minProK8S-1245A node group looks healthy but a subset of pods still cannot startA new node group joins an EKS cluster and only some workloads start failing after placement on the new instances.KubernetesAdvanced20 minPro