CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-288A PodDisruptionBudget is satisfied in aggregate while one topology domain has no remaining healthy replicas for a targeted drain during a failover rehearsalThe global count looks safe, but the local maintenance blast radius is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-1233A projected secret file exists but the app still sees the old valueA workload updates a secret successfully, yet the application keeps reading the initial secret value until a full restart.KubernetesIntermediate17 minProK8S-1244A readiness probe path exists but still failsA service mesh or auth sidecar is introduced and previously healthy readiness probes begin failing despite the app route being up.KubernetesIntermediate17 minProK8S-1249A readiness route exists but still failsA service mesh, auth proxy, or sidecar is introduced and previously healthy readiness checks begin failing despite the app route working normally for real clients.KubernetesIntermediate17 minProK8S-1254A readiness route exists but still failsAfter introducing a service mesh or auth proxy, previously healthy readiness checks begin failing despite the application still serving the route.KubernetesIntermediate17 minProK8S-258A stubDomain forwards internal names correctly while negative caching at node-local DNS hides newly created services during a failover rehearsalThe forwarding chain is right, but one layer remembers failure longer than the service lifecycle. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-127A very generous startup probe masks a crash loop during rollout, and autoscaling expands the broken ReplicaSet before anyone noticesThe app never becomes truly healthy, but the rollout budget is consumed on pods that are still within the startup grace window.KubernetesIntermediate17 minProK8S-180Cluster DNS is correct while one client runtime caches the first answer indefinitely during a failover rehearsalThe service discovery layer updates and the consuming library behaves as if nothing changed. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate17 minProK8S-1188ConfigMap changed successfully but the application never reloaded the new valueKubernetes object state updates correctly, yet the running process keeps old config because it only reads env vars or startup-time configuration.KubernetesIntermediate17 minProK8S-1207CrashLoopBackOff debugging misses the real stack traceA rollout hits CrashLoopBackOff and on-call engineers keep tailing logs from the current container only.KubernetesIntermediate17 minProK8S-1222Init container completes but the app still crashesAn init container creates generated config successfully and the app still starts without it.KubernetesIntermediate17 minProK8S-1204kubectl logs shows the symptom but not the causeA restart loop looks mysterious because current logs contain only probe or wrapper noise. The evidence that matters is in the previous instance that operators never inspected.KubernetesIntermediate17 minProK8S-1218Readiness remains false foreverA deployment copied a probe path from an older chart revision where an init step created the endpoint first.KubernetesIntermediate17 minProK8S-142The service mesh sidecar starts after the application, and the startup probe passes once before all outbound traffic begins failingInitialization timing hid the networking dependency because the first health check ran before the sidecar took control.KubernetesIntermediate17 minProK8S-479A gateway API route is admitted (404 and Rewrite Mismatch)A gateway API route is admitted (404 and Rewrite Mismatch) focuses on cluster-networking-and-service-discovery and asks the reader to isolate 404 and Rewrite Mismatch in NGINX. 실무에서는 404-and-rewrite-mismatch 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶...KubernetesIntermediate18 minProK8S-483A gateway API route is admitted (404 and Rewrite Mismatch)A gateway API route is admitted (404 and Rewrite Mismatch) focuses on cluster-networking-and-service-discovery and asks the reader to isolate 404 and Rewrite Mismatch in NGINX. 실무에서는 404-and-rewrite-mismatch 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶...KubernetesIntermediate18 minProK8S-497A NetworkPolicy permits the application pathA NetworkPolicy permits the application path focuses on cluster-networking-and-service-discovery and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate18 minProK8S-499A NetworkPolicy permits the application pathA NetworkPolicy permits the application path focuses on cluster-networking-and-service-discovery and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate18 minProK8S-501A NetworkPolicy permits the application pathA NetworkPolicy permits the application path focuses on cluster-networking-and-service-discovery and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate18 minProK8S-515A pod security standard allows one base imageA pod security standard allows one base image focuses on kubernetes-access-and-policy and asks the reader to isolate Permission Denied. 실무에서는 permission-denied 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate18 minPro