Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-1441A PodMonitor stops matching one tenant after a post-render step strips the release label only in that namespaceTargets are healthy, but one rendered namespace no longer satisfies the PodMonitor selector.KubernetesIntermediate11 minProK8S-1421A Prometheus Operator rollout keeps one workload uns scrapedA Prometheus Operator rollout keeps one workload uns scraped focuses on Observability Pipeline and asks the reader to isolate the key signal in Prometheus. Prometheus scraping gaps often come from per-environment render differe...KubernetesIntermediate11 minProK8S-1431A Prometheus Operator upgrade leaves one workload darkOne tenant loses monitoring after a Helm post-renderer rollout while every other namespace continues to scrape correctly.KubernetesIntermediate11 minProK8S-1411A Prometheus scrape target disappears (podmonitor-selector-relied-on-legacy-mirrored-namespace-label)A Prometheus scrape target disappears (podmonitor-selector-relied-on-legacy... focuses on Observability Pipeline and asks the reader to isolate the key signal in Prometheus. Monitoring selectors can depend on label mirroring behav...KubernetesIntermediate11 minProK8S-1420A rollback automation chooses the wrong StatefulSet revisionA rollback automation chooses the wrong StatefulSet revision focuses on rollback-strategy and asks the reader to isolate the key signal in Kubernetes. StatefulSet history can be deceptive when partitioned rollouts intentionally leave part...KubernetesIntermediate11 minProK8S-1410A rollback automation picks the wrong ReplicaSetA rollback automation picks the wrong ReplicaSet focuses on Deployment Governance and asks the reader to isolate the key signal in Kubernetes. Rollout helpers that depend on annotations can break when controllers prune or compact older his...KubernetesIntermediate11 minProK8S-1440A StatefulSet rollback helper chooses the wrong revisionA StatefulSet rollback helper chooses the wrong revision focuses on rollback-strategy and asks the reader to isolate the key signal in Kubernetes. StatefulSet rollbacks can be misleading when partitions intentionally preserve mixed versions...KubernetesIntermediate11 minProK8S-1430A StatefulSet rollback tool chooses the wrong revisionA StatefulSet rollback tool chooses the wrong revision focuses on rollback-strategy and asks the reader to isolate the key signal in Kubernetes. StatefulSet history is tricky when partitions preserve intentional mixed-version states insid...KubernetesIntermediate11 minProK8S-1448A Velero restore completes and workloads still failRestored custom resources fail admission until a controller restart.KubernetesIntermediate11 minProK8S-1388A cert-manager DNS01 challenge keeps creating TXT records in the wrong zoneA cert-manager DNS01 challenge keeps creating TXT records in the wrong zone focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. DNS01 failures often come from conflicting zone normal...KubernetesIntermediate12 minProK8S-1434A cert-manager DNS01 renewal passes staging and fails productionA cert-manager DNS01 renewal passes staging and fails production focuses on runtime-isolation and asks the reader to isolate the key signal in Kubernetes. Ephemeral challenge pods are especially sensitive to hardening paths that long-lived...KubernetesIntermediate12 minProK8S-1424A cert-manager DNS01 renewal works in staging and fails in productionA cert-manager DNS01 renewal works in staging and fails in production focuses on runtime-isolation and asks the reader to isolate the key signal in Kubernetes. Hardening can break solver pods through file-path restrictions long before it break...KubernetesIntermediate12 minProK8S-1414A cert-manager renewal passes staging and fails productionA cert-manager renewal passes staging and fails production focuses on runtime-isolation and asks the reader to isolate the key signal in Kubernetes. Hardening changes on challenge pods can remove mounted credentials paths even whe...KubernetesIntermediate12 minProK8S-1356A Grafana dashboard for kube-state-metrics goes blankA label normalization cleanup lands and later Kubernetes workload dashboards lose hierarchy views even though the source targets remain up.KubernetesIntermediate12 minProK8S-1393A Karpenter or autoscaler scale-from-zero path stallsA Karpenter or autoscaler scale-from-zero path stalls focuses on Deployment Governance and asks the reader to isolate the key signal in Kubernetes. Provisioning decisions can be made on an earlier pod shape than the one you inspect later.KubernetesIntermediate12 minProK8S-1366A kube-state-metrics dashboard goes blankA monitoring cleanup normalizes labels and later dashboard panels for deployments and statefulsets go empty despite healthy scrapes.KubernetesIntermediate12 minProK8S-1376A kube-state-metrics dashboard goes blankA label cleanup normalizes metric sets and later deployment or StatefulSet dashboards render empty despite healthy scrapes.KubernetesIntermediate12 minProK8S-1391A metrics pipeline looks healthy and kube-state-metrics dashboards still miss...A metrics pipeline looks healthy and kube-state-metrics dashboards still... focuses on runtime-configuration and asks the reader to isolate the key signal in grafana. Monitoring regressions after chart upgrades often come from selector voc...KubernetesIntermediate12 minProK8S-1360A PodDisruptionBudget looks correct and voluntary evictions still stallA PodDisruptionBudget looks correct and voluntary evictions still stall focuses on Deployment Governance and asks the reader to isolate the key signal in Kubernetes. Disruption budgets interact with rollout and autoscaling limits as one s...KubernetesIntermediate12 minProK8S-1370A PodDisruptionBudget looks safe and node drains still stallA drain or upgrade stalls after autoscaling and rollout tuning were changed independently across teams.KubernetesIntermediate12 minPro