Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-1495A StatefulSet rollout pauses foreverA StatefulSet can not resume after node replacement even though the CSI node plugin reports the volume healthy.KubernetesAdvanced12 minProK8S-1500A Velero restore completes and one namespace never schedulesRestored workloads remain Pending only in namespaces whose tenant class labels were changed before backup.KubernetesAdvanced12 minProK8S-1510A Velero restore completes and one namespace never schedulesRestored workloads remain Pending only in namespaces whose tenant class changed before backup.KubernetesAdvanced12 minProK8S-1488A Velero restore completes and the workload still failsA restored cluster recovers objects and pods still fail during init after a control plane issuer change.KubernetesAdvanced12 minProK8S-1465An IPVS service keeps sending traffic to a drained nodeTraffic continues to hit a drained backend for several minutes after a rollout with externalTrafficPolicy Local.KubernetesAdvanced12 minProK8S-1348A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to-https-by-global-annotation)A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary ingress objects can inherit global behaviors that break...KubernetesIntermediate13 minProK8S-1427A Cilium FQDN policy allows bootstrap package downloads and blocks long-lived...A Cilium FQDN policy allows bootstrap package downloads and blocks long... focuses on dns and asks the reader to isolate the key signal in cilium. FQDN policies can look correct at startup and still fail later when a differe...KubernetesAdvanced13 minProK8S-1417A Cilium FQDN policy allows image pulls and blocks a later gRPC dependencyA Cilium FQDN policy allows image pulls and blocks a later gRPC dependency focuses on dns and asks the reader to isolate the key signal in cilium. FQDN policies can diverge when different stages of the pod lifecycle query through...KubernetesAdvanced13 minProK8S-1437A Cilium FQDN policy allows startup downloads and blocks steady-state gRPCA Cilium FQDN policy allows startup downloads and blocks steady-state gRPC focuses on dns and asks the reader to isolate the key signal in cilium. FQDN policy issues can appear only after sidecars or alternate resolvers expo...KubernetesAdvanced13 minProK8S-1452A Cilium node-local redirect keeps readiness green and still breaks source-IP...A Cilium node-local redirect keeps readiness green and still breaks source... focuses on Service Discovery and asks the reader to isolate the key signal in cilium. Service redirects can change enforcement identity even when requests st...KubernetesAdvanced13 minProK8S-1466A CSI snapshot restore mounts cleanly and the app still sees stale dataA rollback appears complete, yet one stateful workload continues reading old blocks until the pod is recreated.KubernetesAdvanced13 minProK8S-1318A DaemonSet upgrade seems fine until one node class loses logsA node image refresh lands and later only some nodes stop yielding host logs while the collector DaemonSet still reports Ready.KubernetesIntermediate13 minProK8S-1450A StatefulSet rollback looks done and one canary stays on the new specA rollback completes and one member still shows the newer behavior.KubernetesAdvanced13 minProK8S-1457A Velero CSI restore recreates PVCs and one workload still failsA CSI-based restore partially succeeds and one workload remains stuck recreating its PVC.KubernetesAdvanced13 minProK8S-1408A Velero restore looks successful and the app still never comes readyA Velero restore looks successful and the app still never comes ready focuses on backup-restore and asks the reader to isolate the key signal in Kubernetes. Restore tooling can omit keys it classifies as generated metadata even when applications...KubernetesAdvanced13 minProK8S-1445An OpenSearch StatefulSet keeps pinning shards to the wrong zoneShard balancing stays wrong after storage migration.KubernetesAdvanced13 minProK8S-1382A cert-manager CA injector updates one namespace and misses anotherA cert-manager CA injector updates one namespace and misses another focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Injection drift can come from label schema changes that silently drop one object...KubernetesAdvanced14 minProK8S-1394A cert-manager HTTP01 solver pod comes up and challenges still failA cert-manager HTTP01 solver pod comes up and challenges still fail focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Challenge traffic may reach a different address family than the one o...KubernetesAdvanced14 minProK8S-1397A Cilium FQDN policy allows package mirrors and node bootstrap still failsA Cilium FQDN policy allows package mirrors and node bootstrap still fails focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. FQDN policy allows are only effective after the observation path has se...KubernetesAdvanced14 minProK8S-1447A Cilium FQDN policy allows startup traffic and blocks steady-state pullsImage pulls succeed at startup and fail later after node-local DNS takes over.KubernetesAdvanced14 minPro