CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-519A pod security standard allows one base imageA pod security standard allows one base image focuses on kubernetes-access-and-policy and asks the reader to isolate Permission Denied. 실무에서는 permission-denied 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate18 minProK8S-469A ServiceAccount token audience is correct for the main API callA ServiceAccount token audience is correct for the main API call focuses on kubernetes-access-and-policy and asks the reader to isolate Auth and Session Failure. 실무에서는 auth-and-session-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate18 minProK8S-168A sidecar takes over networking after the application already passed its first startup probe during a failover rehearsalHealth looks good once, but the final runtime path is not the one the probe validated. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate18 minProK8S-240An HPA reads CPU from the main container while the injected sidecar consumes most of the real workload headroom during a failover rehearsalThe autoscaler sees one process and the pod's real bottleneck lives somewhere else. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.KubernetesIntermediate18 minProK8S-1191Init container failsA public manifest pattern was updated to simplify ConfigMap structure. The init container still expects the old key and the pod now dies before app startup.KubernetesIntermediate18 minProK8S-1211Readiness never stabilizesA service keeps flapping during boot and the team only increases delay seconds.KubernetesIntermediate18 minProK8S-1225Startup probe keeps failingA workload with a proxy sidecar fails startup probes even though the application container itself is healthy.KubernetesIntermediate18 minProK8S-1230The init container waits forever for DNSA pod design assumes later-stage network policy or sidecar setup before the init step has even finished.KubernetesIntermediate18 minProK8S-484A gateway API route is admitted (404 and Rewrite Mismatch)A gateway API route is admitted (404 and Rewrite Mismatch) focuses on cluster-networking-and-service-discovery and asks the reader to isolate 404 and Rewrite Mismatch in NGINX. 실무에서는 404-and-rewrite-mismatch 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶...KubernetesIntermediate19 minProK8S-539A gateway API route is admitted (404 and Rewrite Mismatch)A gateway API route is admitted (404 and Rewrite Mismatch) focuses on cluster-networking-and-service-discovery and asks the reader to isolate 404 and Rewrite Mismatch in NGINX. 실무에서는 404-and-rewrite-mismatch 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶...KubernetesIntermediate19 minProK8S-557A NetworkPolicy permits the application pathA NetworkPolicy permits the application path focuses on cluster-networking-and-service-discovery and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate19 minProK8S-518A pod security standard allows one base imageA pod security standard allows one base image focuses on kubernetes-access-and-policy and asks the reader to isolate Permission Denied. 실무에서는 permission-denied 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate19 minProK8S-529A ServiceAccount token audience is correct for the main API callA ServiceAccount token audience is correct for the main API call focuses on kubernetes-access-and-policy and asks the reader to isolate Auth and Session Failure. 실무에서는 auth-and-session-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate19 minProK8S-1197CrashLoopBackOff is caused by a startup script reading a secret mount path that moved after a Helm refactorThe app container restarts endlessly because a startup script still references the old secret mount location even though the chart now projects the secret elsewhere.KubernetesIntermediate19 minProK8S-1202CrashLoopBackOff looks like app failure but the init script exitsA startup pattern from community posts assumes a mounted file is ready immediately. On first boot, the script reads an empty value and exits before the app can start.KubernetesIntermediate19 minProK8S-589A ServiceAccount token audience is correct for the main API callA ServiceAccount token audience is correct for the main API call focuses on kubernetes-access-and-policy and asks the reader to isolate Auth and Session Failure. 실무에서는 auth-and-session-failure 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate20 minProK8S-1194kubectl exec works but the in-cluster service call still times outA public policy example was adapted to production. Debug access into the pod works, but normal service calls still time out because the policy does not allow the actual source path.KubernetesIntermediate20 minProK8S-1184Service has healthy pods but zero usable endpointsA public answer suggests checking selectors first. Selectors are correct, but readiness is the real gate keeping endpoints empty.KubernetesIntermediate20 minProK8S-051StatefulSet recovery stallsOnly one ordinal is unhealthy, but the whole recovery path stops because PodManagementPolicy still enforces ordered readiness.KubernetesIntermediate20 minProK8S-697A pod security standard allows one base imageA pod security standard allows one base image focuses on kubernetes-access-and-policy and asks the reader to isolate Permission Denied. 실무에서는 permission-denied 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesIntermediate21 minPro