Symptom229 problems· 18 reviewed

Permission Denied

229 incident problems that show up as “Permission Denied”.

All problems (229)

SECURITY-077Custom WAF allow rule matches but a later managed rule still blocks the requestThe operator sees the expected custom rule fire, yet traffic remains blocked because the final decision is made by a later managed rule with stronger action priority.SecurityIntermediate16 minFreeSECURITY-068MFA-enforced sudo flow breaks non-interactive automation on one hostThe stronger policy is correct for humans, but the service account path now fails because the exempt automation group was never applied consistently.SecurityIntermediate16 minFreeLINUX-075pam_faillock keeps accounts blocked after LDAP recoveryDirectory authentication is healthy again, but users still cannot log in because the host-local lock records survived the upstream outage.LinuxIntermediate16 minFreeSECURITY-076EKS IRSA token file becomes unreadable after a sidecar changes the shared volume ownershipThe role mapping is correct, but the application cannot assume it because the projected token path no longer matches the runtime user permissions after a sidecar update.SecurityIntermediate17 minFreeSECURITY-064WAF bot challenge protects the browser path but blocks webhook callbacks from non-browser clientsThe site is safer for humans, but an integration silently breaks because the challenged path now assumes browser behavior that the webhook sender never provides.SecurityIntermediate17 minFreeSECURITY-059Conditional access blocks the break-glass admin path during a device compliance incidentThe stronger policy makes sense normally, but the emergency access route now fails because it was never carved out from the same device compliance requirements.SecurityIntermediate18 minFreeNETWORK-057Dynamic ARP inspection drops a host after a static IP move without updated bindingsLayer2 connectivity looks normal, but one endpoint stops talking because the protection policy still trusts the old DHCP or ARP binding state.NetworkIntermediate19 minFreeLINUX-084sudo NOPASSWD rule is present but a later group rule still forces password promptsThe expected privilege rule exists, but one broader matching policy lower in the evaluation path overrides the operator's assumption about effective behavior.LinuxIntermediate13 minFreeLINUX-086sshd Match block for a bastion subnet disables agent forwarding on one host class onlySSH works broadly, but a specific bastion path behaves differently because a later Match clause quietly changes capabilities for one source range.LinuxIntermediate15 minFreeLINUX-076tmpfiles.d recreates the runtime directory with the wrong owner after rebootPermissions look correct before restart, but the service fails after boot because tmpfiles recreated the path with ownership that no longer matches the daemon user.LinuxIntermediate15 minFreeCICD-092GitHub Actions reusable workflow loses required secretsThe shared pipeline is healthy overall, but one repository fails because the caller stopped forwarding the secret set the workflow expects.CI/CDIntermediate16 minFreeLINUX-066SELinux blocks the new content rootPermissions and ownership look correct, but the service still gets denied because the moved directory kept the wrong security context.LinuxIntermediate16 minFreeLINUX-094SELinux context is correct on the binary but the parent directory type still blocks traversalThe executable label looks valid, yet access fails because one parent directory retains a context that denies the path traversal required to reach the file.LinuxIntermediate16 minFreeCICD-108Artifact retention removes the SBOM before the security gate runs and attestation verification reports a missing dependency inventoryBuilds finish successfully, but the delayed security job cannot verify compliance because the artifact policy pruned the required software bill of materials too early.CI/CDIntermediate17 minFreeSECURITY-270Browser isolation covers the main admin page while websocket upgrades to the same host bypass the isolated route during a failover rehearsalThe most visible path is protected and a less visible interactive path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeLINUX-070SSSD cache preserves deleted group membership and sudo access lingers after offboardingThe identity source is already updated, but one host still grants privileged access because its local cache did not expire when the account changed.LinuxIntermediate17 minFreeK8S-085Gateway API route is accepted but the ReferenceGrant does not cover the namespace of the backend serviceThe route object itself looks valid, yet traffic never forwards because the cross-namespace backend reference is not explicitly granted.KubernetesIntermediate18 minFreeCICD-062Reusable GitHub workflow call fails after the default branch renameWorkflows on the main pipeline still run, but the shared reusable workflow is no longer resolved because the referenced branch and published ref policy drifted apart.CI/CDIntermediate18 minFreeLINUX-051systemd-tmpfiles cleanup removes the application socket directory after rebootThe service worked before restart, but after boot its runtime socket path is missing because the tmpfiles policy cleaned the directory more aggressively than expected.LinuxIntermediate18 minFreeCICD-034Private GHCR package install fails although workflow repository is trustedA build can authenticate to GitHub, but dependency restore still fails because the package lives in another private repository with separate access control.CI/CDIntermediate19 minFree