DNS Resolution Failure
59 incident problems that show up as “DNS Resolution Failure”.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
K8S-034NetworkPolicy allows the app service but blocks CoreDNS resolutionThe namespace appears to have the right egress rules for the application path, yet pods still fail because DNS traffic to kube-dns was never permitted.ReviewedKubernetesIntermediate18 minFreeNETWORK-004DNS resolves on the host but not inside the containerA typical failure that appears when the container runtime's DNS settings and search domains diverge.ReviewedNetworkBeginner16 minFreeNETWORK-027Resolver search suffix turns short name into wrong destinationResolver search suffix turns short name into wrong destination is a hands-on troubleshooting drill. A short hostname works in one environment and points somewhere else in another because search suffix order changed. DNS and Routing needs to be checked by narrowing scope, recen...ReviewedNetworkBeginner13 minFreeCould not resolve host: external API calls fail on one server onlyCould not resolve host: external API calls fail on one server only is a hands-on troubleshooting drill. Tell a DNS failure from a connectivity or remote outage. GitHub dns-resolution needs to be checked by narrowing scope, recent change, and the current live signal before roll...ReviewedNetworkBeginner3 minFreeNETWORK-001Quickly checking the network path when containers cannot communicateA network-basics incident scenario that organizes the order of checking the bridge network, iptables, port mapping, and DNS.NetworkIntermediate21 minFreeNETWORK-017Internal DNS search-domain order attaches to a different service with the same nameInternal DNS search-domain order attaches to a different service with the... is a hands-on troubleshooting drill. Covers a search-domain setting problem where a short-name call resolves to a different service than intended. DNS and Routing needs to be checked by narrowing scop...NetworkBeginner15 minFree
All problems (59)
Could not resolve host: external API calls fail on one server onlyCould not resolve host: external API calls fail on one server only is a hands-on troubleshooting drill. Tell a DNS failure from a connectivity or remote outage. GitHub dns-resolution needs to be checked by narrowing scope, recent change, and the current live signal before roll...ReviewedNetworkBeginner3 minFreeK8S-034NetworkPolicy allows the app service but blocks CoreDNS resolutionThe namespace appears to have the right egress rules for the application path, yet pods still fail because DNS traffic to kube-dns was never permitted.ReviewedKubernetesIntermediate18 minFreeNETWORK-027Resolver search suffix turns short name into wrong destinationResolver search suffix turns short name into wrong destination is a hands-on troubleshooting drill. A short hostname works in one environment and points somewhere else in another because search suffix order changed. DNS and Routing needs to be checked by narrowing scope, recen...ReviewedNetworkBeginner13 minFreeNETWORK-004DNS resolves on the host but not inside the containerA typical failure that appears when the container runtime's DNS settings and search domains diverge.ReviewedNetworkBeginner16 minFreeNETWORK-001Quickly checking the network path when containers cannot communicateA network-basics incident scenario that organizes the order of checking the bridge network, iptables, port mapping, and DNS.NetworkIntermediate21 minFreeNETWORK-017Internal DNS search-domain order attaches to a different service with the same nameInternal DNS search-domain order attaches to a different service with the... is a hands-on troubleshooting drill. Covers a search-domain setting problem where a short-name call resolves to a different service than intended. DNS and Routing needs to be checked by narrowing scop...NetworkBeginner15 minFreeK8S-072ExternalDNS updates the wrong hosted zoneDNS automation is healthy, but one record lands in the wrong zone because two matching filters and ownership assumptions overlap in a way the operator did not expect.KubernetesIntermediate18 minFreeNETWORK-037Internal clients cannot reach the public VIPExternal users can access the service normally, but inside clients fail when they resolve the same public name because the edge path does not support loopback NAT.NetworkIntermediate20 minFreeNETWORK-075IPv6 RA guard blocks the real router after a campus template is copied to the uplinkIPv4 still works, but IPv6 clients lose their gateway because the edge protection template was applied to the wrong interface type.NetworkIntermediate15 minFreeK8S-114NetworkPolicy allows the namespace selector but cluster DNS still failsThe app can reach peer services, yet name resolution breaks because the policy only modeled TCP while the resolver path still needs UDP.KubernetesIntermediate15 minFreeNETWORK-069Internal clients cannot reach the public VIPExternal users connect normally, yet internal users fail on the same FQDN because the firewall does not hairpin the connection back to the inside service path.NetworkIntermediate16 minFreeK8S-103ExternalDNS creates the new record but readiness still failsDNS updates succeed outside the pod, yet the app never heals because its resolver library keeps using stale answers through the rollout.KubernetesIntermediate17 minFreeSECURITY-157A web proxy enforces SafeSearch through DNS rewriting, but one application hardcodes HTTPS endpoints and bypasses the control entirelyName-based filtering works where DNS is consulted, but one client path never asks DNS again.SecurityIntermediate15 minFreeK8S-077CoreDNS negative caching masks a fixed service record long after the backend issue is goneThe service entry is corrected, but clients still fail because the resolver path is serving a negative cache response longer than operators expect.KubernetesIntermediate16 minFreeNETWORK-055DHCP relay helper is configured but the reply is blocked on the return ACLThe client broadcast is forwarded correctly, yet lease assignment still fails because the routed reply path is filtered differently on the way back.NetworkBeginner17 minFreeNETWORK-034DHCP snooping blocks voice VLAN leases on a new access stackClients on the data VLAN receive addresses correctly, but phones on the voice VLAN fail because the uplink trust boundary or helper path was not mirrored.NetworkBeginner17 minFreeK8S-078NodeLocal DNSCache keeps using the old upstream after a ConfigMap updateCluster DNS works partially, but one set of nodes still forwards to the retired resolver because the node-local cache path never reloaded the new upstream config.KubernetesIntermediate17 minFreeK8S-067StatefulSet ordinal DNS looks healthy but traffic is emptyPod names resolve as expected, yet clients get no working backend because the Service that should back ordinal DNS no longer selects the current pods.KubernetesIntermediate17 minFreeK8S-057CoreDNS stub domain forwards the internal zone to the wrong upstreamMost cluster DNS works, but one internal zone fails because the custom forwarding block points at an outdated resolver target.KubernetesIntermediate18 minFreeK8S-064NetworkPolicy allows UDP 53 but blocks DNS TCP fallback for large responsesMost lookups appear healthy, yet one domain consistently fails because the policy only permits the UDP path and the resolver falls back to TCP for bigger answers.KubernetesIntermediate18 minFree