Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-1586A CoreDNS rewrite fix lands and one namespace still resolves stale namesOne namespace still resolves stale names after a CoreDNS rewrite fix.KubernetesIntermediate8 minProK8S-1596A CoreDNS rewrite is fixed and one namespace still resolves stale namesOne namespace still resolves stale names after a CoreDNS rewrite fix.KubernetesIntermediate8 minProK8S-1576A CoreDNS rewrite rule changes and one service still resolves the old suffixOne service keeps resolving the old suffix after a CoreDNS rewrite update.KubernetesIntermediate8 minProK8S-1574A signerName update lands and one cert request still waitsOne certificate request stays pending after signerName standardization.KubernetesIntermediate8 minProK8S-1598A webhook config is updated and one API server still ignores the new timeoutOne API server still ignores a new webhook timeout after config updates.KubernetesIntermediate8 minProK8S-1588A webhook timeout is lowered and one API server still waitsOne API server still waits too long after webhook timeout reduction.KubernetesIntermediate8 minProK8S-1608A webhook timeout update lands and one API server still waitsOne API server still waits too long after a webhook timeout update.KubernetesIntermediate8 minProK8S-1483A CoreDNS autopath optimization speeds most lookups and one namespace loopsA migrated namespace sees intermittent DNS loops after autopath optimization is enabled cluster-wide.KubernetesIntermediate9 minProK8S-1516A CoreDNS change is applied and one namespace still resolves stale IPsOnly one namespace behind one node-local cache keeps seeing stale service IPs after a CoreDNS update.KubernetesIntermediate9 minProK8S-1474A CoreDNS negative cache hides a fixed ServiceA service recovers, yet callers keep failing for several minutes because the negative DNS result is still cached.KubernetesIntermediate9 minProK8S-1496A CoreDNS rollout succeeds and pods still resolve stale service IPsOnly pods behind one node-local DNS cache keep resolving a retired service IP after a CoreDNS rollout.KubernetesIntermediate9 minProK8S-1506A CoreDNS rollout succeeds and pods still resolve stale service IPsOnly pods behind one node-local cache keep resolving a retired service IP after a DNS rollout.KubernetesIntermediate9 minProK8S-1526A CoreDNS update rolls out and one namespace still resolves stale endpointsOnly one namespace sees stale endpoints after a CoreDNS update.KubernetesIntermediate9 minProK8S-1536A CoreDNS update rolls out and one namespace still resolves stale endpointsOnly one namespace sees stale endpoints after a CoreDNS update.KubernetesIntermediate9 minProK8S-1578A namespaceSelector update lands and one webhook still ignores a namespaceOne webhook ignores a namespace after a selector label rename.KubernetesIntermediate9 minProK8S-1566A NodeLocal DNSCache restart succeeds and one namespace still gets NXDOMAINOne namespace sees NXDOMAIN only after search suffix changes.KubernetesIntermediate9 minProK8S-1556A NodeLocal DNSCache rollout completes and one namespace still resolves stale service IPsOne namespace sees intermittent traffic to an old service IP after DNS cache rollout.KubernetesIntermediate9 minProK8S-1494A cert-manager renewal updates the secret and ingress still serves the old certificateGateway API traffic keeps serving an old cert after a secret renewal that works fine on classic Ingress.KubernetesIntermediate10 minProK8S-1504A cert-manager renewal updates the secret and the gateway still serves the old certificateGateway API traffic serves the old cert after secret renewal while classic ingress updates fine.KubernetesIntermediate10 minProK8S-1400A cleanup job deletes old ReplicaSets and one rollback becomes impossibleA cleanup job deletes old ReplicaSets and one rollback becomes impossible focuses on Deployment Governance and asks the reader to isolate the key signal in Kubernetes. Operational rollback tooling often depends on annotations and histor...KubernetesIntermediate10 minPro