CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-1354A cert-manager renewal job stays Pending (webhook-networkpolicy-still-whitelisted-old-apiserver-cidr)A cert-manager renewal job stays Pending (webhook-networkpolicy-still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Admission and webhook traffic often comes from a control-plane CIDR...KubernetesIntermediate14 minProK8S-1326A cert-manager renewal succeeds and the new certificate never reaches the appA certificate rotates successfully in cluster state and the application continues presenting the old material until a restart.KubernetesIntermediate14 minProK8S-1338A Cilium upgrade keeps policy enforcement and breaks one NodePort pathA Cilium upgrade keeps policy enforcement and breaks one NodePort path focuses on network-segmentation and asks the reader to isolate the key signal in Kubernetes. Partial CNI rollouts can create path-specific behavior differences th...KubernetesIntermediate14 minProK8S-1313A CronJob fires twice (cronjob-duplicate-run-after-eviction)A CronJob fires twice (the key signal) focuses on incident-response and asks the reader to isolate the key signal in Kubernetes. Cluster scheduling guarantees do not replace application-level idempotency for CronJobs.KubernetesIntermediate14 minProK8S-1294A custom metrics HPA reads values successfully but never scalesA workload is migrated between namespaces and autoscaling appears frozen even though the metric backend is healthy.KubernetesIntermediate14 minProK8S-1334A node drain hangs even though replicas are healthyA maintenance window begins and a single namespace blocks node drains with admission errors unrelated to application health.KubernetesIntermediate14 minProK8S-1329A Pod logs DNS timeouts only on fresh nodesA Pod logs DNS timeouts only on fresh nodes focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. Node-specific DNS failures often point to bootstrap order rather than to cluster-wide resolver health.KubernetesIntermediate14 minProK8S-1300A sidecar log shipper silently drops linesA logging change lands and one workload begins losing the first or last lines around every rotation event.KubernetesIntermediate14 minProK8S-1344A StatefulSet pod comes up and fails readinessA StatefulSet pod comes up and fails readiness focuses on runtime-configuration and asks the reader to isolate the key signal in Kubernetes. Stateful recovery can fail on identity artifacts even when the raw data volume is fine.KubernetesIntermediate14 minProK8S-1322A StatefulSet pod stays Pending after force deletionAn operator force deletes a stuck StatefulSet pod during an incident and later the replacement remains Pending with attach-related events.KubernetesIntermediate14 minProK8S-1288An HPA sees CPU correctly but still never scalesAn application chart is refactored, CPU spikes are visible, and the HPA appears idle without errors.KubernetesIntermediate14 minProK8S-1308An ingress controller never reloads one new configA platform team separates controller and configuration namespaces and later one class of ingress settings silently stops applying.KubernetesIntermediate14 minProK8S-1301An initContainer loops on DNS for a dependency that already existsA rollout creates both a dependency service and a consuming workload, and only the first few pods never recover from DNS failures.KubernetesIntermediate14 minProK8S-153A node selector matches the new GPU node pool label, but taints were added during bootstrap and the workload never lands thereThe scheduler finds the right nodes by label, yet another admission rule still excludes them.KubernetesIntermediate15 minProK8S-128A service account has automount disabled, and the init job that fetches configuration from the cluster API never receives credentialsMain workload logic is fine, but the initialization phase assumes access to a token that policy has intentionally removed.KubernetesIntermediate15 minProK8S-134Node-local DNS cache serves NXDOMAIN for a Service that was created moments later, and one node keeps the bad answer through the rolloutThe Service exists now, but one resolver path still trusts the earlier negative cache result.KubernetesIntermediate15 minProK8S-158The service account token audience is restricted correctly, but the in-cluster dashboard still requests the default audience and loses API accessIdentity hardening worked, yet one client was never updated to the narrowed trust contract.KubernetesIntermediate15 minProK8S-132A cloned PersistentVolume inherits the wrong reclaim policy and deleting the test claim removes the only remaining copyThe clone appears safe for testing, but one lifecycle flag still ties cleanup to the underlying data fate.KubernetesIntermediate16 minProK8S-150A ConfigMap reload sidecar watches inode changes, but the projected volume updates by symlink swap and the app never reloadsConfiguration changes exist in the pod, yet the watcher logic does not observe the form of filesystem mutation Kubernetes actually uses.KubernetesIntermediate16 minProK8S-1242A CronJob fires on schedule but no useful work happensA copied CronJob template looks valid and still fails every execution when it tries to access cluster or cloud APIs.KubernetesIntermediate16 minPro