Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-143A CSI snapshot restore succeeds, but the application pod still mounts the old PVC name through a leftover volumeClaimTemplate referenceData recovery completed, yet workload recovery still points at the pre-incident storage object.KubernetesAdvanced17 minProK8S-154A custom mutating webhook adds a sidecar to every pod, but the Jobs that already specify restartPolicy OnFailure now exceed the expected init sequenceThe platform-wide injection works for services, yet batch semantics drift because the startup contract changed.KubernetesAdvanced17 minProK8S-369A drained node returns to service (Resource Exhaustion)A drained node returns to service (Resource Exhaustion) focuses on kubernetes-workload-reliability and asks the reader to isolate Resource Exhaustion. 실무에서는 resource-exhaustion 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesAdvanced17 minProK8S-393A multi-cluster failover record updates correctly while clients pinned to one HTTP/2 connection never rediscover the new backend set during a staged decommissionName resolution converges and long-lived streams keep the old world alive. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesAdvanced17 minProK8S-149A node-local registry mirror serves a cached schema1 image manifest, and only older worker images can still pull it after the upstream fixThe mirror preserved outdated registry behavior longer than the upstream did.KubernetesAdvanced17 minProK8S-357A PersistentVolume reattaches (Rollout Stuck)A PersistentVolume reattaches (Rollout Stuck) focuses on kubernetes-storage-and-state and asks the reader to isolate Rollout Stuck in AWS. 실무에서는 rollout-stuck 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesAdvanced17 minProK8S-157A pod restart budget is healthy, but the cluster autoscaler removes the only node with local PV affinity and the replacement pod cannot rescheduleCapacity remains, yet storage locality still pins recovery to a node that no longer exists.KubernetesAdvanced17 minProK8S-145A PodSecurity restricted namespace blocks the init container's chown workaround, and the volume owner never becomes writableThe app and volume are healthy in isolation, but the compatibility shim is no longer allowed to run.KubernetesAdvanced17 minProK8S-1260A Service exposes the app but external traffic still failsA Service exposes the app but external traffic still fails focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. A healthy Service and healthy pods do not prove the cloud load balancer can traverse the node-s...KubernetesIntermediate17 minProK8S-1257An EKS ingress stays pendingAn ingress or LoadBalancer Service never provisions even though the controller is installed and has permissions.KubernetesIntermediate17 minProK8S-137An external load balancer health check hits the NodePort before readiness gating is effective, and nodes enter rotation with no viable backendsInfrastructure sees open ports, but the application is not actually ready to serve traffic yet.KubernetesAdvanced17 minProK8S-148An HPA based on external queue depth scales up correctly, but scale-down never happensThe autoscaler is healthy, yet one observability component keeps a historical answer longer than expected.KubernetesAdvanced17 minProK8S-126EndpointSlice hints keep steering traffic to a drained zone until the controller catches up, and clients see retries long after evacuationDrain activity succeeded operationally, yet topology-aware routing continues sending some traffic into the old fault domain.KubernetesAdvanced17 minProK8S-135Pod Security Admission in restricted mode blocks the emergency hostPath-based debug pod the team uses during storage incidentsThe cluster is secure by default, but the incident workflow still depends on a pattern the policy now forbids.KubernetesAdvanced17 minProK8S-118PodDisruptionBudget healthy count looks satisfied but drain still blocks on an unready terminating podMaintenance cannot complete because a pod in termination keeps being counted in one state and excluded in another, confusing the disruption math.KubernetesAdvanced17 minProK8S-129Topology-aware routing and sticky sessions combine to create a hotspot on one zone after a scale eventNeither feature is individually wrong, but together they pin too much traffic to a shrinking endpoint subset.KubernetesAdvanced17 minProK8S-109ValidatingAdmissionPolicy denies updatesNew objects pass validation, but updates to older resources fail because the rule does not guard for legacy schemas missing the referenced field.KubernetesAdvanced17 minProK8S-210A cluster-wide mutation helps services and breaks a workload class with different lifecycle semantics during a failover rehearsalThe platform-level change is broadly useful while one specialized workload class cannot honor its assumptions. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-375A CSI snapshot restore succeeds while one init script repopulates the data directory from a stale side channel before the app starts during a staged decommissionRecovery works and the first-start path silently overwrites it. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesAdvanced18 minProK8S-121A DaemonSet surge update doubles the hostPort bind and the new pods never become Ready on half the nodesThe rollout strategy looks safer on paper, but the host-level port exclusivity means old and new pods cannot overlap.KubernetesAdvanced18 minPro