DNS Resolution Failure
59 incident problems that show up as “DNS Resolution Failure”.
먼저 읽을 가이드
추천 문제
All problems (59)
NETWORK-007A missing ip_forward setting blocks NAT egress after a rebootCovers a kernel network setting problem that a temporary fix resolves but that breaks again after a reboot.NetworkIntermediate22 minFreeNETWORK-100Anycast DNS stays reachable but one site serves stale zone data after an AXFR policy changeThe service appears up globally, yet answers diverge because one anycast site stopped receiving zone transfers under the new policy.NetworkAdvanced18 minProSECURITY-027Egress proxy bypass remains possible through one legacy hostnameMost outbound traffic now uses the secured path, but an overlooked legacy name still resolves around the expected control point.SecurityAdvanced27 minProCICD-026Promotion pipeline deploys stale image from previous commitThe promotion stage uses an artifact reference that looks correct but resolves to an older image digest after registry cleanup.CI/CDAdvanced29 minProNETWORK-062MLAG peer link is healthy but the orphan VLAN is not allowed and ARP blackholes one rackThe chassis pair stays up, yet half the rack cannot resolve the gateway because the affected VLAN was never permitted across the peer path.NetworkAdvanced23 minProSECURITY-148A DNS firewall blocks known malicious domains, but the internal resolver still returns stale positive cache answers for one recently blacklisted hostThe policy is correct now, yet the cached resolution path preserves yesterday's trust decision.SecurityAdvanced16 minProSECURITY-137Split-horizon DNS forgot the external TXT record needed for domain ownership, and the SSO cutover never verifies on the public sideInternal testing passes, but the control plane outside the network cannot see the proof it needs.SecurityAdvanced16 minProSECURITY-204A newly blocked domain remains reachable through stale resolver cache state during a failover rehearsalThe control is correct now while caches preserve yesterday's trust decision. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProLINUX-112systemd-resolved split DNS sends the internal domain to the public resolverThe name exists internally, yet queries leak outward because the resolver policy is bound to a different interface than the app actually uses.LinuxAdvanced17 minProSECURITY-258A DNSSEC-signed public zone validates while the internal split-horizon copy still serves unsigned child records during a failover rehearsalExternal trust is healthy and internal trust assumptions no longer match it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-117DNSSEC validates at the registrar, but CDS and CDNSKEY automation stopped and the child zone slowly drifts out of syncValidation still passes today, yet the delegation path is aging toward failure because the parent update automation quietly stopped.SecurityAdvanced18 minProNETWORK-030Blue-green cutover misses webhook callback allowlistThe new stack goes live, but one callback provider still points at the old address because its allowlist and DNS cutover are out of sync.NetworkIntermediate19 minProK8S-025Cross-namespace DNS lookup works in debug pod but not app podA quick debug shell resolves the name, while the workload container fails because search domains and runtime image differ.KubernetesIntermediate20 minProNETWORK-022Internal DNS resolves the old targetMost clients pick up the new destination, but a subset stays on the stale IP because resolver behavior is inconsistent.NetworkIntermediate21 minProK8S-134Node-local DNS cache serves NXDOMAIN for a Service that was created moments later, and one node keeps the bad answer through the rolloutThe Service exists now, but one resolver path still trusts the earlier negative cache result.KubernetesIntermediate15 minProNETWORK-150A DNS resolver cluster answers internally, but the monitoring probe queries over TCP only and a firewall change now blocks fallback responses for large recordsMost lookups seem fine until oversized replies require a protocol path the probe no longer reaches.NetworkIntermediate16 minProSECURITY-369A DNS sinkhole activates for new queries while one recursive resolver keeps serving stale ECS- or geo-influenced answers from a previous policy epoch during a staged decommissionThe block policy is correct now and resolver memory still reflects the old decision. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityIntermediate16 minProK8S-144A headless Service returns pod A records correctly, but one Java client caches the first answer forever and never balances after scale-outCluster DNS is accurate, yet one library's lookup behavior defeats the intended design.KubernetesIntermediate16 minProK8S-381A NetworkPolicy permits the application path while node-local DNS forwarding now uses a different source identity than the rule expected during a staged decommissionApp traffic is allowed, yet name resolution fails because the helper path no longer matches policy assumptions. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.KubernetesIntermediate16 minProNETWORK-363A resolver answers from cache while one DNS64 or split-horizon view changed only on the authoritative path and new clients fail immediately during a staged decommissionWarm clients look healthy, cold clients prove the design drifted. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkIntermediate16 minPro