Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-216A local storage workload looks healthy until scale-down removes the only node that satisfies its locality during a failover rehearsalCompute capacity remains while schedulability disappears because the data stayed behind. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-136A mutating webhook uses timeoutPolicy Ignore, and objects slip through partially mutated so only some pods receive the expected sidecar configurationAdmission no longer blocks, but workload behavior diverges because the mutation contract is no longer deterministic under latency.KubernetesAdvanced18 minProK8S-141A node drain respects the PodDisruptionBudget, but a custom controller recreates helper pods instantly and the drain never convergesKubernetes is behaving correctly, yet another controller keeps replenishing the very pods maintenance is trying to evict.KubernetesAdvanced18 minProK8S-160A node image upgrade enables cgroup v2, and one Java workload starts misreporting heap limits so the HPA scales on the wrong utilization basisThe app still runs, but runtime memory accounting changed with the node image and distorts autoscaling decisions.KubernetesAdvanced18 minProK8S-123A restored PersistentVolume keeps node affinity for the old zone and the replacement pod never mounts in the new region segmentRestore succeeded in storage terms, but scheduling and attach logic still reflect the source topology.KubernetesAdvanced18 minProK8S-174A restored volume exists while the workload still points at the old claim or template reference during a failover rehearsalRecovery created the right storage object, but the app path remains bound to the previous one. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-294A Secret store CSI volume refreshes correctly while an init-container copied the old value into a writable path the app still uses during a failover rehearsalThe secret source is fresh, yet the application keeps reading a stale shadow copy it created earlier. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-228A service mesh auth policy trusts a namespace label that is added only after pod admission during a failover rehearsalThe policy is correct in the steady state while admission-time decisions happen before the required metadata exists. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-138A snapshot restore keeps the old filesystem UUID and the init script mounts the wrong device path after failoverStorage recovered, but one host-level assumption about device identity now points at the wrong volume.KubernetesAdvanced18 minProK8S-264A source-range rule trusts node addresses while externalTrafficPolicy Local leaves one zone with no eligible ingress path during a failover rehearsalThe load balancer policy is correct and locality changes which nodes can actually receive traffic. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-345A topology spread rule looks balanced while one tainted node pool is the only place the emergency fallback pods are actually allowed to run during a staged decommissionDistribution appears fair until a failure forces the scheduler into the only domain with compatible taints. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesAdvanced18 minProK8S-252A validating admission policy allows creates and blocks updatesThe same resource shape is accepted once and rejected later due to one deterministic-looking comparison that is not actually stable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-324A validating policy allows create requests while an update path generated by a controller now violates a field immutability assumption during a failover rehearsalThe original manifest shape is valid, but the controller's own later mutation path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-204An autoscaler trusts a queue-depth metric that remains stale long after backlog is gone during a failover rehearsalScaling keeps behaving as if yesterday's pressure still exists because freshness is not part of the metric contract. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesAdvanced18 minProK8S-156An externalSecrets controller refreshes the Secret, but the mounted CSI volume caches the previous version and the app sees mixed credentialsSecret state is updated centrally, yet different delivery paths serve different generations at runtime.KubernetesAdvanced18 minProK8S-1241An HPA scales the Deployment but latency stays badA canary rollout adds autoscaling and operators later find that the scaled pods do not actually receive the traffic they were meant to absorb.KubernetesAdvanced18 minProK8S-1235An init job fixes permissions but the main container still failsA pod initializes successfully on some restarts and fails on others depending on the relative timing of the CSI mount and init logic.KubernetesIntermediate18 minProK8S-130cert-manager renews the Secret, but the mounted Java keystore never reloads and TLS clients keep seeing the expired chainThe cluster certificate resource is healthy, yet the workload runtime still serves stale credentials from an application-level cache.KubernetesAdvanced18 minProK8S-111Gateway API reports the HTTPRoute as accepted but the listener hostname mismatch prevents any real attachmentStatus conditions look promising, yet traffic never arrives because the route was accepted by the controller but not bound to the intended hostname listener.KubernetesAdvanced18 minProK8S-107Image filesystem eviction thresholds are configured, but node pressure is actually on rootfs and kubelet never evicts the bloated log directoryThe node shows pressure symptoms, yet eviction does not trigger because the exhausted partition is not the one covered by the active threshold.KubernetesAdvanced18 minPro