Symptom229 problems· 18 reviewed

Permission Denied

229 incident problems that show up as “Permission Denied”.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

CICD-031GITHUB_TOKEN read-only default blocks release provenance uploadThe workflow can build and test successfully, but the release job fails when it tries to publish attestations or update release metadata with a narrower token scope.ReviewedCI/CDIntermediate21 minProCICD-109Self-hosted runner label matches the build queue but the runner misses the Docker socket mount and image builds fail only thereThe job lands on the intended runner group, yet one fleet member lacks the host capability the workflow assumes every labeled runner provides.ReviewedCI/CDIntermediate16 minFreedocker push: denied: requested access to the resource is denieddocker push: denied: requested access to the resource is denied is a hands-on troubleshooting drill. Check which registry an image tag actually points to before debugging credentials. GitHub Container Image Delivery needs to be checked by narrowing scope, recent change, and th...ReviewedCI/CDBeginner14 minFreeK8S-030Ingress class mismatch sends traffic to the wrong controllerIngress class mismatch sends traffic to the wrong controller is a hands-on troubleshooting drill. Routing rules are valid, but the ingress object is reconciled by a different controller than the team expected. Kubernetes Ingress and Traffic needs to be checked by narrowing sco...ReviewedKubernetesIntermediate19 minFreeLINUX-006The application cannot read filesA scenario that narrows down the root cause, centered on checking permissions, owner, and the execution account together, in the situation of the application being unable to read files because permissions changed after a deploy script.ReviewedLinuxIntermediate19 minFreeLINUX-031SELinux context breaks web content after rsync-based restoreFile ownership and permissions look correct after a restore, but the service still cannot read content because the restored paths lost the expected SELinux labels.ReviewedLinuxIntermediate21 minFree

All problems (229)

nginx 403 with (13: Permission denied): only the newly uploaded filenginx 403 with (13: Permission denied): only the newly uploaded file is a hands-on troubleshooting drill. Read file permissions to see why nginx cannot open a file. NGINX file-permissions needs to be checked by narrowing scope, recent change, and the current live signal before...ReviewedLinuxBeginner3 minFree403 Forbidden: login works but one admin action is refused (vs 401)403 Forbidden: login works but one admin action is refused (vs 401) is a hands-on troubleshooting drill. Tell authentication failures (401) from authorization failures (403). Identity And Access needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeWARNING: UNPROTECTED PRIVATE KEY FILE: SSH refused on a new laptopWARNING: UNPROTECTED PRIVATE KEY FILE: SSH refused on a new laptop is a hands-on troubleshooting drill. Understand why ssh ignores a private key whose permissions are too open. Identity And Access needs to be checked by narrowing scope, recent change, and the current live sign...ReviewedSecurityBeginner3 minFreeSSH Permission denied (publickey): cannot log in to a new EC2 instanceSSH Permission denied (publickey): cannot log in to a new EC2 instance is a hands-on troubleshooting drill. Know each AMI's default login user. AWS remote-access needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 remote-ac...ReviewedLinuxBeginner3 minFreeNETWORK-064ACL shadow rule blocks load balancer health checks from the SNAT poolUser traffic seems permitted on paper, but backends stay marked unhealthy because the firewall never allowed the translated health-check source range.ReviewedNetworkIntermediate18 minFreeSECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFreeSECURITY-056Secrets Manager rotation updates the writer credential but read replicas still use the old secretRotation completes successfully on the primary path, yet one read-side workload keeps failing because its secret retrieval or cache path was never included in the rotation design.ReviewedSecurityIntermediate21 minFreeK8S-030Ingress class mismatch sends traffic to the wrong controllerIngress class mismatch sends traffic to the wrong controller is a hands-on troubleshooting drill. Routing rules are valid, but the ingress object is reconciled by a different controller than the team expected. Kubernetes Ingress and Traffic needs to be checked by narrowing sco...ReviewedKubernetesIntermediate19 minFreeLINUX-006The application cannot read filesA scenario that narrows down the root cause, centered on checking permissions, owner, and the execution account together, in the situation of the application being unable to read files because permissions changed after a deploy script.ReviewedLinuxIntermediate19 minFreeLINUX-031SELinux context breaks web content after rsync-based restoreFile ownership and permissions look correct after a restore, but the service still cannot read content because the restored paths lost the expected SELinux labels.ReviewedLinuxIntermediate21 minFreeSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeCICD-109Self-hosted runner label matches the build queue but the runner misses the Docker socket mount and image builds fail only thereThe job lands on the intended runner group, yet one fleet member lacks the host capability the workflow assumes every labeled runner provides.ReviewedCI/CDIntermediate16 minFreeLINUX-056SSH key is valid but included config disables PubkeyAuthentication later in the chainAuthorized keys and file permissions look healthy, yet login falls back to password because a later include file overrides the expected sshd setting.ReviewedLinuxIntermediate17 minFreeLINUX-063sudoers include file is ignoredThe rule is written correctly, yet sudo behavior never changes because the included file fails the safety checks and is silently skipped.ReviewedLinuxBeginner13 minFreedocker push: denied: requested access to the resource is denieddocker push: denied: requested access to the resource is denied is a hands-on troubleshooting drill. Check which registry an image tag actually points to before debugging credentials. GitHub Container Image Delivery needs to be checked by narrowing scope, recent change, and th...ReviewedCI/CDBeginner14 minFreeS3 AccessDenied: the IAM policy allows it but the bucket policy denies itS3 AccessDenied: the IAM policy allows it but the bucket policy denies it is a hands-on troubleshooting drill. Read the explicit-deny wording in AccessDenied and fix access through the approved path. AWS cloud-security-and-governance needs to be checked by narrowing scope, rec...ReviewedSecurityIntermediate17 minFreeLINUX-017Only the operations automation account fails to run a command due to a sudoers rule differenceCovers a situation where human accounts work but only the automation account is blocked on a specific command due to different permissions.LinuxIntermediate19 minFreeSECURITY-039S3 server access log archive fails after object ownership policy changedCentral logging was working until bucket ownership controls changed, and now write attempts fail even though the destination bucket still exists and the prefix is correct.SecurityIntermediate19 minFreeCICD-098Maven cache reuse hides a repository auth failure until the monthly cache eviction windowBuilds appear stable for weeks, then all fail at once because the dependency cache had been masking a broken repository credential path.CI/CDIntermediate15 minFreeSECURITY-152A browser isolation policy renders the admin portal remotely, but a direct-download allowlist still lets CSV exports bypass the isolated sessionThe riskiest interaction is protected, yet a side path still leaks the sensitive payload.SecurityIntermediate16 minFree