CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-1387A Cilium host firewall rollout blocks node-local DNSA Cilium host firewall rollout blocks node-local DNS focuses on incident-response and asks the reader to isolate the key signal in Kubernetes. Host firewall rollouts require a different mental model from workload identity policy.KubernetesAdvanced14 minProK8S-1455A device plugin returns healthy after a node image rollback and the kubelet still refuses allocationsAllocations fail only on nodes rolled back to the previous image after a failed upgrade.KubernetesAdvanced14 minProK8S-1412A Gatekeeper constraint rejects only one object kindA Gatekeeper constraint rejects only one object kind focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Admission inconsistencies can be limited to one versioned path or kind even when the c...KubernetesAdvanced14 minProK8S-1432A Gatekeeper rollout looks healthy and one forbidden object still slipsA Gatekeeper rollout looks healthy and one forbidden object still slips focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Inconsistent policy enforcement can come from earlier admission fai...KubernetesAdvanced14 minProK8S-1442A Gatekeeper rule looks healthy and one forbidden object still landsForbidden resources appear only during admission load spikes.KubernetesAdvanced14 minProK8S-1422A Gatekeeper upgrade looks healthy and one team still creates forbidden...A Gatekeeper upgrade looks healthy and one team still creates forbidden... focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Inconsistent policy enforcement can come from earlier admiss...KubernetesAdvanced14 minProK8S-1409A host-networked observability daemon reaches its collectors and later loses...A host-networked observability daemon reaches its collectors and later... focuses on Observability Pipeline and asks the reader to isolate the key signal in cilium. Host-network pods often rely on policy exceptions that do not automaticall...KubernetesAdvanced14 minProK8S-1369A Hubble flow view shows allowed workload traffic and the app still failsOperators investigate a connectivity problem with Hubble and later discover the deny occurred outside the workload flow view they trusted.KubernetesAdvanced14 minProK8S-1379A Hubble workload view shows allowed traffic and the app still failsOperators rely on Hubble to debug traffic and later discover the actual block was outside the workload path it visualized.KubernetesAdvanced14 minProK8S-1403A node provisioning workflow applies a taint-removal patch and new workloads...A node provisioning workflow applies a taint-removal patch and new... focuses on scheduler-behavior and asks the reader to isolate the key signal in Kubernetes. Placement bugs can come from when a field becomes visible to the scheduler, not whe...KubernetesAdvanced14 minProK8S-1428A Velero restore brings back CRDs and one controller never stabilizesA Velero restore brings back CRDs and one controller never stabilizes focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Restore order can matter long after everything exists if early...KubernetesAdvanced14 minProK8S-1438A Velero restore brings back CRDs and one controller stays brokenA Velero restore brings back CRDs and one controller stays broken focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Restore-time webhook gaps can become persistent if controllers cache th...KubernetesAdvanced14 minProK8S-1418A Velero restore completes and one workload never stabilizesA Velero restore completes and one workload never stabilizes focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Restore timing bugs around CRDs often come from webhook reachability windows rat...KubernetesAdvanced14 minProK8S-1407An egress policy rollout using Cilium FQDN rules permits bootstrap traffic...An egress policy rollout using Cilium FQDN rules permits bootstrap traffic... focuses on network-policy and asks the reader to isolate the key signal in cilium. FQDN egress policies can look healthy during bootstrap and fail later...KubernetesAdvanced14 minProK8S-1405An OpenSearch cluster on Kubernetes keeps allocating shards into the wrong...An OpenSearch cluster on Kubernetes keeps allocating shards into the wrong... focuses on stateful-workloads and asks the reader to isolate the key signal in Opensearch. Topology-aware controllers can keep trusting stale pod metadata long afte...KubernetesAdvanced14 minProK8S-1435An OpenSearch nodeSet rename preserves PVCs and leaves one shard family...An OpenSearch nodeSet rename preserves PVCs and leaves one shard family... focuses on stateful-workloads and asks the reader to isolate the key signal in Opensearch. Stateful migrations can preserve topology hints on storage o...KubernetesAdvanced14 minProK8S-1415An OpenSearch operator recovers nodes (sequential-evictions-outpaced-opensearch-manager-set-reconciliation)An OpenSearch operator recovers nodes (sequential-evictions-outpaced... focuses on quorum-management and asks the reader to isolate the key signal in Opensearch. Stateful quorum systems can drift during rapid sequential evic...KubernetesAdvanced14 minProK8S-1425An OpenSearch stateful workload recovers (allocator-preferred-stale-pvc-topology-hint-after-nodeset-rename)An OpenSearch stateful workload recovers (allocator-preferred-stale-pvc... focuses on stateful-workloads and asks the reader to isolate the key signal in Opensearch. Stateful migrations can preserve stale topology hints on stor...KubernetesAdvanced14 minProK8S-1310Grafana Agent remote_write looks connected but drops a burst of cluster metricsMetrics ingestion resumes after pressure recovery, but dashboards never fill the missing historical gap from the outage window.KubernetesIntermediate14 minProK8S-1306Promtail tails files successfully until log rotation acceleratesA noisy cluster starts losing short-lived container logs even though Promtail itself reports no crash or auth error.KubernetesIntermediate14 minPro