CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-1238An ingress route looks valid but one hostname still returns 404After adding or upgrading an ingress controller, one hostname starts returning the wrong response even though the Ingress object itself looks unchanged.KubernetesAdvanced20 minProCICD-088Argo CD health check stays degradedThe resource is actually working, but the GitOps controller still blocks promotion because its custom health logic only understands the older API shape.CI/CDAdvanced20 minProK8S-084DaemonSet update stallsThe update strategy looks conservative, but rollout progress stops because the current unavailable state of the tainted group already exceeds the allowed update budget.KubernetesAdvanced20 minProK8S-095Pod anti-affinity keeps a restore blockedCapacity exists, but strict anti-affinity rules stop recovery because the surviving node already runs the same workload family.KubernetesAdvanced20 minProK8S-1219ALB controller says permissions are correct but one action still failsAn ALB controller works enough to create some resources but repeatedly fails one reconciliation action.KubernetesAdvanced21 minProK8S-1221CoreDNS pods are Running but queries still failA cluster keeps CoreDNS in Running state after scaling, but name resolution fails only after pods land on a new node group.KubernetesAdvanced21 minProK8S-1208Managed node group reports join failure while nodes already appear Ready in the clusterThe console still shows a failure, but kubectl shows Ready nodes, sending the team into the wrong troubleshooting path.KubernetesAdvanced21 minProK8S-1227The ALB controller creates the load balancer but target registration failsAn Ingress object becomes active but downstream target health stays red after registration.KubernetesAdvanced21 minProCICD-067Argo Rollouts analysis never promotesTraffic and pods look healthy, yet automated promotion never happens because the analysis provider keeps evaluating metrics for an old release label set.CI/CDAdvanced22 minProK8S-1223IRSA works for most AWS calls but one SDK path still falls back to node credentialsA pod can access one AWS service through IRSA but another code path still appears to use the node role.KubernetesAdvanced22 minProK8S-1217Managed node joins successfully but service traffic still failsA scale event adds healthy nodes but a portion of traffic still fails immediately after.KubernetesAdvanced22 minProK8S-1215Target group health is green but some client traffic still blackholesAn NLB-backed service passes health checks overall, but a portion of client traffic still disappears during scale changes.KubernetesAdvanced22 minProK8S-1212IRSA annotation is present but STS still denies AssumeRoleA pod with the correct service account still gets access denied after an auth migration.KubernetesAdvanced23 minProK8S-1209One ingress route still breaks WebSocket upgradesA platform keeps WebSockets behind ingress plus an edge proxy and only one upgraded route returns 400.KubernetesAdvanced23 minProK8S-1185PodDisruptionBudget blocks node drainA public hardening guide recommended a conservative PDB. Later, replica counts dropped, but the old minAvailable still blocks every drain.KubernetesAdvanced23 minProK8S-088StatefulSet ordinal reuses a stale PVC and replays old node identity into the quorum clusterThe pod comes up, but the distributed system behaves incorrectly because the restored ordinal is carrying a PVC from a previous logical member.KubernetesAdvanced23 minProCICD-061Argo CD app-of-apps sync waves leave the platform upgrade stuck on a child dependencyThe root application looks healthy, but one child app never becomes ready because the sync ordering assumes a dependency finished before its CRDs actually became usable.CI/CDAdvanced24 minProK8S-1200Controller pod runs but never actsA controller upgrade follows public guidance. The pod restarts cleanly, but reconciliations stop because the leader-election path cannot update its lease object.KubernetesAdvanced24 minProK8S-1205Controller starts fine after upgrade but CRD drift makes new objects fail validation on only one clusterThe controller image upgrade succeeds, but one cluster still rejects new objects because its CRD version or schema was not updated along with the controller.KubernetesAdvanced24 minProK8S-1195Draining one node silently breaks a local-path workload that was never truly portableA maintenance drain appears routine, but one workload fails badly because it depended on local storage behavior that was never made portable across nodes.KubernetesAdvanced24 minPro