Auth and Session Failure
164 incident problems that show up as “Auth and Session Failure”.
먼저 읽을 가이드
추천 문제
All problems (164)
SECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProK8S-087OIDC provider issuer URL rotates and every projected token verifier in the cluster rejects new tokensToken projection still works, but consumers fail because the issuer trust path and JWKS discovery URL changed underneath long-lived verifiers.KubernetesAdvanced22 minProSECURITY-065Vault periodic token stops renewingThe workload starts normally, but long-lived sessions fail hours later because the renewal path assumed a parent-child token chain that no longer exists.SecurityAdvanced22 minProCICD-071Argo CD prune deletes a shared secretThe sync itself succeeds, but a cleanup step removes a namespace-scoped secret that another workload still depends on because ownership boundaries were not encoded safely.CI/CDAdvanced23 minProSECURITY-090Vault unseal succeeds but one performance standby still serves stale auth configuration after leader failoverThe cluster looks healthy again, yet some login paths still fail because a standby node continues using old auth backend settings after control-plane leadership changed.SecurityAdvanced23 minProSECURITY-038CDN caches an authenticated error pageThe login path itself is correct, but one personalized failure response gets cached at the edge and leaks confusing content to later users.SecurityAdvanced24 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProNETWORK-125Policy-based routing on the SVI forces user traffic toward a firewall but also bypasses the local DHCP relay pathSecurity steering works, but address assignment becomes unstable because a local service path was not exempted from the policy.NetworkIntermediate15 minProSECURITY-141A SAML assertion signs correctly, but the audience URI casing changed during the domain move and one service provider rejects only mixed-case callbacksIdentity proof is valid, yet string normalization assumptions differ between the two ends.SecurityAdvanced16 minProLINUX-140SSH certificate authentication is configured, but the principals file permissions are too open and the daemon ignores it for security reasonsThe CA trust path is valid, yet certificate login falls back to password prompts because the principal mapping file fails ownership checks.LinuxAdvanced16 minProSECURITY-142A break-glass account is excluded from conditional access, but the session lifetime policy still revokes it before the maintenance task finishesThe account bypasses the main gate, yet another identity control still constrains the operation.SecurityAdvanced17 minProNETWORK-399A first-hop redundancy group fails over the gateway IP while one NAC or security system still authorizes the old active member based on switch identity during a staged decommissionGateway continuity hides an adjacent policy engine that keys off the old box. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkAdvanced17 minProSECURITY-132A GitHub App remains installed after a repository transfer, but the new organization grant was never approved and installation tokens lose repository scopeAutomation still exists, yet the trust boundary around the repo changed in a way the app permissions did not follow.SecurityAdvanced17 minProSECURITY-123A named location in conditional access misses the new SD-WAN egress IP range, and compliant users are suddenly blocked after failoverIdentity posture is good, but network identity changed underneath the access policy.SecurityAdvanced17 minProLINUX-141A package update rewrites the PAM stack include order, and MFA still prompts but account validation now happens after the wrong moduleAuthentication appears normal until edge-case users begin failing account checks after successful factors.LinuxAdvanced17 minProSECURITY-162A signed identity response is valid while one relying party rejects its audience string under different normalization rules during a failover rehearsalTrust succeeds cryptographically and string semantics still break the session. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProLINUX-108A sudoers include file loads later and quietly re-enables a broad NOPASSWD rule the team thought it removedPrivilege hardening seems complete, yet one lexical include order detail restores broad administrative access after the next package update.LinuxAdvanced17 minPro