Symptom84 problems· 11 reviewed

404 and Rewrite Mismatch

84 incident problems that show up as “404 and Rewrite Mismatch”.

All problems (84)

SECURITY-149A CloudFront signed URL policy covers the main asset host, but a redirect to the image host drops the signature scope and private media leaks a 403 loopThe control is present, yet the delivery path crosses hostnames that do not share the same authorization contract.SecurityAdvanced17 minProSECURITY-092Cloud WAF blocks the admin API path only after a new JSON field increases rule score above thresholdThe endpoint worked before, but the updated payload shape now trips a scoring-based rule model that was previously below the block threshold.SecurityAdvanced17 minProCICD-133A blue-green DNS cutover succeeds, but the CDN origin pin remains on the old backend and a percentage of traffic never movesThe authoritative name points correctly, yet cached origin metadata upstream still holds users on the retired stack.CI/CDAdvanced18 minProSECURITY-210An authorization token is valid for one delivery host while the content path crosses into another during a failover rehearsalAuthorization is scoped correctly and the asset path does not stay where the token applies. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-068CloudFront keeps serving stale index.html after a blue-green cutoverThe new environment is healthy, but users still load references to the old asset set because cache invalidation and origin switch ordering were not coordinated.CI/CDAdvanced19 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProCICD-076Cross-region artifact replication lags and the disaster-recovery deploy uses a partial releaseThe promotion completed in the primary region, but the DR environment pulls an incomplete artifact set because replication finished for the manifest before every dependent object arrived.CI/CDAdvanced21 minProCICD-029Monorepo path filter misses shared library changesMonorepo path filter misses shared library changes is a hands-on troubleshooting drill. Only some services rebuild because the path filter ignores a shared package that affects multiple deployments. GitHub Rollback and Rollout needs to be checked by narrowing scope, recent cha...CI/CDAdvanced26 minProSECURITY-027Egress proxy bypass remains possible through one legacy hostnameMost outbound traffic now uses the secured path, but an overlooked legacy name still resolves around the expected control point.SecurityAdvanced27 minProK8S-023Admission webhook blocks only one namespace pathAdmission webhook blocks only one namespace path is a hands-on troubleshooting drill. Most workloads apply normally, but a webhook policy rejects a specific namespace because labels and defaults diverge. Kubernetes Ingress and Traffic needs to be checked by narrowing scope, re...KubernetesAdvanced28 minProSECURITY-015Emergency blocklist rule causes asymmetric egress failureEmergency blocklist rule causes asymmetric egress failure is a hands-on troubleshooting drill. A rapid security response closes the obvious path but unexpectedly breaks return traffic for a dependent service flow. Azure Incident Response Operations needs to be checked by narro...SecurityAdvanced28 minProNETWORK-026Latency spike follows asymmetric routing after failoverLatency spike follows asymmetric routing (Timeouts and Latency) is a hands-on troubleshooting drill. Traffic technically succeeds, but the response path changes after failover and introduces an expensive detour. DNS and Routing needs to be checked by narrowing scope, recent ch...NetworkAdvanced28 minProSECURITY-003WAF rule deployment blocks admin API but misses the real attack pathA hotfix rule stops valid management traffic while the malicious request pattern still finds an unprotected endpoint.SecurityAdvanced28 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProSECURITY-103A CSP nonce is generated at the edge, but the application template reuses a stale fragment and browsers block one script bundleThe response headers look correct, yet execution fails because a cached HTML fragment still contains yesterday's nonce value.SecurityAdvanced17 minProK8S-105Ingress canary header routing works for HTTP but gRPC requests ignore the split and all traffic stays on stableThe progressive delivery rule appears valid, but the gRPC path follows a different routing evaluation than the header-based HTTP test path.KubernetesAdvanced17 minProCICD-101Preview environment cleanup job deletes the release candidate namespace before smoke tests startA pull request environment vanishes moments before validation because the cleanup workflow no longer waits for the downstream smoke test status.CI/CDAdvanced17 minProK8S-146A Gateway API route binds to the correct listener, but the backendRef points at a Service in another namespace without the required ReferenceGrantEverything looks connected until cross-namespace security rules are evaluated.KubernetesAdvanced18 minProK8S-080Ingress controller leader election lease stayed in the old namespace after a migrationThe new controller deploys cleanly, yet only one replica ever reconciles because the election objects still point at the namespace pattern from the previous release.KubernetesAdvanced18 minProK8S-151The ingress controller trusts X-Forwarded-Proto from the external load balancer, but an internal hop rewrites it and secure redirects begin loopingTLS is terminated correctly, yet downstream protocol awareness is now inconsistent across hops.KubernetesAdvanced18 minPro