Certification955 problems· 24 reviewed

CKA

955 incident response problems that help with CKA prep.

All problems (955)

K8S-1247A CronJob schedules correctly but the pod still cannot reach the APIA scheduled maintenance job is cloned from another hardened template and later fails only when it tries to contact cluster or cloud APIs.KubernetesIntermediate16 minProK8S-1252A CronJob starts on schedule but the pod cannot call the APIA maintenance CronJob cloned from another workload begins failing only when it reaches the point that needs API or cloud credentials.KubernetesIntermediate16 minProK8S-1237A Deployment reports Available but traffic still failsA chart refactor or app rename deploys cleanly, but one Service or Ingress path goes dark immediately after.KubernetesIntermediate16 minProK8S-147A Deployment uses maxUnavailable zero, but node pressure evicts old pods anyway and the rollout briefly drops below the intended floorThe rollout strategy is conservative, yet external eviction pressure overrides the update assumptions.KubernetesIntermediate16 minProK8S-363A gateway API route is admitted while one backend reference still points to a namespace alias only the old ingress controller understood during a staged decommissionThe route object looks valid and one controller-specific assumption no longer applies. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesIntermediate16 minProK8S-144A headless Service returns pod A records correctly, but one Java client caches the first answer forever and never balances after scale-outCluster DNS is accurate, yet one library's lookup behavior defeats the intended design.KubernetesIntermediate16 minProK8S-381A NetworkPolicy permits the application path while node-local DNS forwarding now uses a different source identity than the rule expected during a staged decommissionApp traffic is allowed, yet name resolution fails because the helper path no longer matches policy assumptions. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesIntermediate16 minProK8S-399A pod security standard allows one base image while a debug ephemeral container now violates the restricted contract during incident response during a staged decommissionSteady-state workloads comply, but the emergency troubleshooting path does not. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesIntermediate16 minProK8S-351A ServiceAccount token audience is correct for the main API call while an admission sidecar now forwards the same token to a different verifier during a staged decommissionThe pod identity works in one place and fails when reused in a path with a stricter audience check. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesIntermediate16 minProK8S-155An app depends on downward API labels, but the rollout controller changes the label key and the pod keeps reading an empty file without crashingThe deployment succeeds, yet the runtime configuration silently degrades because one metadata contract changed.KubernetesIntermediate16 minProK8S-124An ingress rewrite rule strips the trailing slash from the websocket path and only interactive sessions fail while health checks stay greenThe service looks healthy through normal probes, yet upgraded connections hit a subtly different path contract.KubernetesIntermediate16 minProK8S-270An inotify-based sidecar watches the wrong inode set after a projected ConfigMap update swaps symlinks during a failover rehearsalConfiguration changes are present while the watcher logic never sees the right file system events. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate16 minProK8S-139HPA scale-down stabilization holds extra replicas during a rollout, and the Deployment budget never frees enough capacity for the next revisionNothing is obviously broken, but overlapping controller safety windows create a deadlock on available resources.KubernetesIntermediate16 minProK8S-318A ConfigMap hot reload works for the main container while a sidecar cached the previous schema and never reopens the mounted files during a failover rehearsalThe pod has new config, but not every process inside the pod has new understanding. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-1228A ConfigMap key exists but the app still crashesAn application restart was skipped because the team expected the mounted config file to update in place after a ConfigMap edit.KubernetesIntermediate17 minProK8S-198A conservative rollout budget still loses availability when cluster pressure starts evicting old pods during a failover rehearsalDeployment math is correct, yet platform pressure changes the effective availability story. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-234A CSI expansion updates the block device size while the filesystem inside the pod still reports the old geometry during a failover rehearsalThe storage control plane moved forward and the in-pod view of usable capacity did not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-336A custom metric adapter reports current values while the HPA history window is still full of high samples and scale-down never happens when expected during a failover rehearsalThe metric is honest now, but the autoscaling controller still reasons over a past you forgot to inspect. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-300A headless Service gives every pod address while the client library still randomizes from a stale cached subset after scale-down during a failover rehearsalService discovery is accurate and the client keeps dialing endpoints that no longer exist. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-1239A pod reads the updated Secret but the sidecar still failsA workload rotates a trust bundle and one sidecar keeps failing outbound TLS connections until a full restart happens.KubernetesIntermediate17 minPro