Auth and Session Failure
164 incident problems that show up as “Auth and Session Failure”.
먼저 읽을 가이드
추천 문제
All problems (164)
SECURITY-282A trust policy validates the new OIDC issuer while one condition key still matches the old claim path during a failover rehearsalThe provider migration is half-complete and federated access still fails on the detail that matters. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-168An emergency account bypasses the first control while a downstream session rule still revokes it too early during a failover rehearsalThe break-glass path escapes one identity gate and remains constrained by another. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-110Argo CD ignoreDifferences hides drift in service account annotations and the workload loses cloud identity on syncGit and cluster appear in sync, yet the runtime identity broke because a diff-ignore rule masked the exact annotation that binds the pod to its cloud role.CI/CDAdvanced18 minProSECURITY-078JIT provisioning creates duplicate accounts after the immutable identity key changesFederation remains healthy, but every login now spawns another local account because the stable identity key changed from email to a new immutable identifier.SecurityAdvanced18 minProSECURITY-107mTLS client identity maps to the wrong tenantCertificates are valid, yet authorization fails because the parser extracts a different identity field than the policy engine expects.SecurityAdvanced18 minProCICD-102OIDC exchange fails only in reusable workflowsA shared workflow refactor succeeds for linting but deployment breaks because the federated identity provider expects a different token audience than the child workflow emits.CI/CDAdvanced18 minProSECURITY-216Runtime credential caches keep serving access long after central revocation completed during a failover rehearsalThe security team acts quickly and the runtime still lives in the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-079Secrets Manager rotation succeeds but the application keeps reading the old current version stageThe rotation Lambda finishes, yet the service still fails login because the stage labels and the consumer refresh path are out of sync.SecurityAdvanced18 minProSECURITY-085Session revocation works centrally but one edge node continues accepting the old JWT until its cache expiresThe revoke event is recorded correctly, yet some requests still succeed because one verifier node has not refreshed its token or key cache.SecurityAdvanced18 minProSECURITY-091SSO works but step-up MFA never triggersPrimary authentication succeeds, yet privileged actions remain exposed because the application is still reading an outdated assurance claim.SecurityAdvanced18 minProCICD-168A reusable workflow assumes a broader OIDC scope than the caller actually grants during a failover rehearsalThe shared logic is valid, but the effective token permissions are still narrower than the deployment step needs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProSECURITY-081Conditional Access excludes the break-glass user but not the device-registration prerequisiteThe emergency account is excluded from the main policy, yet login still fails because an upstream prerequisite step is governed by a different device rule set.SecurityAdvanced19 minProSECURITY-093Secrets rotation updates the database user but leaves a cached connection pool authenticating with the old passwordThe new credential is valid, yet outages continue because the application pool never discarded existing sessions that still reuse the previous password flow.SecurityAdvanced19 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProSECURITY-083KMS grant allows encrypt but one rotated alias points the application to a key without decrypt permissionThe secret path still looks valid, yet runtime failures begin because the alias now resolves to a different key than the policy and grants were built for.SecurityAdvanced20 minProSECURITY-100Vault seal migration completes on the leader but one standby still advertises stale recovery key requirementsThe cluster seems healthy, yet operational confusion persists because one standby node still reflects the previous seal-state assumptions after migration.SecurityAdvanced20 minProNETWORK-078Anycast service becomes unstable after an IGP cost change moves stateful clients across sitesThe anycast design still advertises correctly, but a cost change shifts clients to another site that does not hold the expected state continuity.NetworkAdvanced21 minProK8S-066Projected service account token audience mismatch breaks external Vault authThe pod has a valid token, but external auth still fails because the verifier expects a different audience than the projected token request generated.KubernetesAdvanced21 minProSECURITY-062SIEM correlation deduplicates brute-force alerts and hides the real spray scopeAnalysts see only a few incidents, but the attack is much wider because the correlation rule collapses repeated signals into one coarse event group.SecurityAdvanced21 minPro