CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-1464A CoreDNS loop appears on one Ubuntu node poolCoreDNS loop warnings start only after one worker image line moves to a newer Ubuntu release.KubernetesIntermediate10 minProK8S-1485A CSI restore mounts fine and the app still sees readonly filesA restored workload mounts its volume and still cannot write after a storage-side restore into a reused path.KubernetesIntermediate10 minProK8S-1476A CSI volume mounts and the app still cannot writeA stateful app fails to write only after a restore into a reused mount path with subPath enabled.KubernetesIntermediate10 minProK8S-1426A Grafana Agent deployment keeps one namespace darkA Grafana Agent deployment keeps one namespace dark focuses on Observability Pipeline and asks the reader to isolate the key signal in grafana. Operator watch filters can exclude newly labeled namespaces for longer than teams expe...KubernetesIntermediate10 minProK8S-1436A Grafana Agent operator misses one namespaceA Grafana Agent operator misses one namespace focuses on Observability Pipeline and asks the reader to isolate the key signal in grafana. Operator onboarding gaps can come from late label injection missing the first informer snaps...KubernetesIntermediate10 minProK8S-1419A host-network ingress addon starts rejecting trafficA host-network ingress addon starts rejecting traffic focuses on edge-routing and asks the reader to isolate the key signal in Kubernetes. Host-networked addons can fail because of node-side cleanup helpers that know old ports but not ne...KubernetesIntermediate10 minProK8S-1429A host-network ingress addon stays Ready and one new health endpoint never...A host-network ingress addon stays Ready and one new health endpoint never... focuses on edge-routing and asks the reader to isolate the key signal in Kubernetes. Host-networked addon failures can be caused by background host cleanup loops...KubernetesIntermediate10 minProK8S-1439A host-network ingress addon stays Ready and one new health port still failsA host-network ingress addon stays Ready and one new health port still fails focuses on edge-routing and asks the reader to isolate the key signal in Kubernetes. Host-network addon regressions often come from node-level port management, not p...KubernetesIntermediate10 minProK8S-1558An admission webhook cert rotates and one API server still reports x509 errorsOnly one API server reports x509 webhook errors after certificate rotation.KubernetesIntermediate10 minProK8S-1568An admission webhook manifest is updated and one namespace still ignores itOne namespace still ignores the webhook after the manifest was hardened.KubernetesIntermediate10 minProK8S-1478An Istio AuthorizationPolicy allows JWT traffic and still blocks browser clientsBrowsers fail against a service while direct token-bearing requests from curl still succeed.KubernetesIntermediate10 minProK8S-1469An Istio WebSocket path keeps the TCP session and still loses authNormal API calls pass and WebSocket upgrades lose authentication after a routing cleanup.KubernetesIntermediate10 minProK8S-1462A cert-manager DNS01 challenge hits the right zone and still failsWildcard issuance fails for one delegated subzone while the provider confirms the TXT record is present.KubernetesIntermediate11 minProK8S-1444A cert-manager DNS01 challenge loopsIssuance breaks only after a hardened runtime class rollout.KubernetesIntermediate11 minProK8S-1453A cert-manager HTTP01 challenge works on the base gateway and fails on the...A cert-manager HTTP01 challenge works on the base gateway and fails on the... focuses on certificate-rotation and asks the reader to isolate the key signal in Kubernetes. HTTP01 failures in canaries often come from mesh routing layers rat...KubernetesIntermediate11 minProK8S-1456A Gatekeeper mutation adds the default storage class and the scheduler still...A Gatekeeper mutation adds the default storage class and the scheduler... focuses on policy-as-code and asks the reader to isolate the key signal in Kubernetes. Helpful defaulting policies can create impossible scheduling combinat...KubernetesIntermediate11 minProK8S-1416A Grafana Agent DaemonSet stays healthy and one node never forwards logsA Grafana Agent DaemonSet stays healthy and one node never forwards logs focuses on Observability Pipeline and asks the reader to isolate the key signal in grafana. DaemonSet logging issues often come from node-image-specific log pat...KubernetesIntermediate11 minProK8S-1396A Grafana Agent Operator pipeline still scrapes pods and one tenant loses...A Grafana Agent Operator pipeline still scrapes pods and one tenant loses... focuses on incident-response and asks the reader to isolate the key signal in grafana. Operator behavior can diverge temporarily across controller instances...KubernetesIntermediate11 minProK8S-1406A Grafana Agent operator rollout leaves one namespace unmonitoredA Grafana Agent operator rollout leaves one namespace unmonitored focuses on Observability Pipeline and asks the reader to isolate the key signal in grafana. Operator watch caches can miss freshly added selector labels for longer than teams...KubernetesIntermediate11 minProK8S-1390A PodDisruptionBudget is respected and a maintenance drain still never...A PodDisruptionBudget is respected and a maintenance drain still never... focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. Successful eviction policy does not guarantee practical drain completion within your...KubernetesIntermediate11 minPro