Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-1206Node instances are healthy in AWS but never join the clusterA team changes node provisioning with a launch template and custom image and the EC2 instances never join the cluster.KubernetesAdvanced24 minProK8S-052Readiness probe fails only after service mesh sidecar intercepts the health portThe container answers correctly on its native port, but the probe fails because the sidecar path or redirected port does not match the probe expectation.KubernetesAdvanced24 minProK8S-1201aws-auth still looks correct but kubelet bootstrap failsA cluster auth migration keeps the old mappings on paper, but node bootstrap starts failing because the node identity path has changed underneath.KubernetesAdvanced25 minProK8S-059PriorityClass protects system pods but starves customer workloads during node pressureThe cluster keeps critical control components alive as intended, but the chosen priority and preemption policy leave business workloads permanently unschedulable.KubernetesAdvanced25 minProK8S-1187PVC stays Pending after a chart cleanup removed the explicit storage classA StatefulSet worked before, but a chart refactor removed storageClassName and the cluster default no longer provisions compatible volumes.KubernetesAdvanced26 minProK8S-1189Admission webhook blocks all updatesA public webhook deployment pattern is applied, then cluster updates begin timing out because the control plane cannot reach the webhook service reliably.KubernetesAdvanced27 minProK8S-1196EKS auth migration breaks node accessA team follows EKS auth-mode migration guidance and deletes more aws-auth entries than intended. The cluster continues partly functioning but managed node groups stop behaving correctly.KubernetesAdvanced27 minProK8S-1181EKS CoreDNS stays PendingPublic EKS troubleshooting steps recommend restarting or scaling CoreDNS, but the real issue is that no eligible nodes exist for the pods.KubernetesAdvanced27 minProK8S-035Validating webhook rejects new workloads after certificate rotationThe webhook service is reachable, but admissions fail because the CABundle in the configuration no longer matches the serving certificate chain.KubernetesAdvanced27 minProK8S-054Volume attach succeeds but the pod never mountsThe control plane reports the volume attachment as healthy, yet the pod stays stuck on a subset of nodes because the node-side plugin is not present everywhere.KubernetesAdvanced27 minProK8S-1186AWS Load Balancer Controller never reconcilesA team follows AWS re:Post guidance for the load balancer controller. The pod starts, but reconciliation never happens because the controller identity path is wrong.KubernetesAdvanced28 minProK8S-060HPA and PodDisruptionBudget combine to deadlock a low-replica rolloutAutoscaling and disruption control each look reasonable alone, but together they prevent the deployment from making forward progress during an update.KubernetesAdvanced28 minProK8S-039StatefulSet scale-down keeps PVC data that contaminates the next ordinal reuseA later scale-up reuses the ordinal and attaches an old volume, causing the application to start with stale state that does not match the new deployment intent.KubernetesAdvanced28 minProK8S-029CSI driver recovers volume attach only after controller restartPersistent volume attachment gets stuck until the controller is restarted, pointing to an unhealthy reconciliation loop.KubernetesAdvanced29 minProK8S-1182Private registry pulls fail with x509 unknown authority after node image refreshOnly refreshed nodes fail to pull from the internal registry because the new node image no longer trusts the custom CA chain.KubernetesAdvanced29 minProK8S-1594A cert-manager DNS01 cleanup finishes and one order still waitsOne cert-manager order still waits after DNS01 hosted zone cleanup.KubernetesIntermediate8 minProK8S-1604A cert-manager order is valid and one challenge still waitsOne DNS challenge still waits after a hosted zone migration.KubernetesIntermediate8 minProK8S-1602A custom metrics fix is correct and one HPA still reads zeroOne HPA still reads zero after custom metrics fixes.KubernetesIntermediate8 minProK8S-1592A metrics adapter fix lands and one HPA still stays flatOne HPA still stays flat after metrics adapter corrections.KubernetesIntermediate8 minProK8S-1564A cert-manager HTTP01 solver is patched and one order still failsHTTP01 validation fails only on one ingress path after solver updates.KubernetesIntermediate9 minPro