Incident response guides
Signals to check first, command examples, common misdiagnoses, and recovery order. After reading, practice on a problem about the same failure.
How to check x509 unknown authority and missing intermediate certificatesAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when TLS verification fails because of chain, CA bundle, or trust store differences rather than the server certificate itself.Security3 min readHow to isolate an mTLS trust bundle mismatchAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the client certificate, server certificate, CA bundle, and sidecar reload timing differ and the handshake fails.Security3 min readHow to safely diagnose a WAF 403 false positiveAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when it looks like a permissions problem but a specific header, payload, or rule group is blocking legitimate requests.Security3 min readHow to split IAM, TLS, and WAF failures into a security operations flowAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when authentication, authorization, certificate, WAF, and audit log signals mix together and look like a single access failure.Security3 min readWhen login callbacks break due to proxy header differences between NGINX and AzureA search-oriented comparison guide covering reverse proxy header mismatches, secure callback failures, and proxy behavior differences between the NGINX and Azure paths.Security3 min read