Symptom229 problems· 18 reviewed

Permission Denied

229 incident problems that show up as “Permission Denied”.

All problems (229)

CICD-168A reusable workflow assumes a broader OIDC scope than the caller actually grants during a failover rehearsalThe shared logic is valid, but the effective token permissions are still narrower than the deployment step needs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProSECURITY-081Conditional Access excludes the break-glass user but not the device-registration prerequisiteThe emergency account is excluded from the main policy, yet login still fails because an upstream prerequisite step is governed by a different device rule set.SecurityAdvanced19 minProSECURITY-072IAM permission boundary blocks emergency admin role assumption despite the attached allow policyThe incident role seems fully privileged, but assumption still fails because the boundary silently caps effective access below the attached policy intent.SecurityAdvanced20 minProSECURITY-083KMS grant allows encrypt but one rotated alias points the application to a key without decrypt permissionThe secret path still looks valid, yet runtime failures begin because the alias now resolves to a different key than the policy and grants were built for.SecurityAdvanced20 minProCICD-089Multi-account deployment role trusts the pipeline account but not the delegated tooling role session name patternCross-account deploys worked before, but now fail because the trust policy still allows the source account while denying the actual delegated session identity format.CI/CDAdvanced20 minProCICD-069OIDC deploy role works on push events but fails on workflow_call reuseThe repository already deploys successfully on direct pushes, but the reusable workflow path now fails because the token subject pattern no longer matches the calling context.CI/CDAdvanced20 minProLINUX-077Rsync restore with numeric-ids shifts file ownershipThe backup looks intact, but the restored application loses access because numeric UID preservation no longer matches the target system account layout.LinuxAdvanced20 minProSECURITY-100Vault seal migration completes on the leader but one standby still advertises stale recovery key requirementsThe cluster seems healthy, yet operational confusion persists because one standby node still reflects the previous seal-state assumptions after migration.SecurityAdvanced20 minProSECURITY-080Endpoint isolation policy blocks the EDR cloud callback and the host never recovers from containmentContainment starts correctly, but the host stays permanently isolated because the policy also cut off the control channel required to release it safely.SecurityAdvanced21 minProK8S-066Projected service account token audience mismatch breaks external Vault authThe pod has a valid token, but external auth still fails because the verifier expects a different audience than the projected token request generated.KubernetesAdvanced21 minProSECURITY-084WAF JSON parser normalizes the body differently from the application and bypasses the intended block ruleSecurity rules appear present, but a crafted request still reaches the app because the protection layer interprets the JSON structure differently from the backend.SecurityAdvanced21 minProSECURITY-075An SCP allows the recovery service but blocks the dependent KMS decrypt call during restoreThe incident playbook launches correctly, but restore still fails because the organization policy forgot the downstream KMS permission the service actually needs.SecurityAdvanced22 minProSECURITY-087CloudTrail organization trail exists but one delegated admin account writes to an unmonitored bucket in another regionAudit coverage seems complete, yet one privileged path is effectively invisible because the delegated admin is using a destination outside the monitored collection pattern.SecurityAdvanced22 minProK8S-068FailurePolicy Ignore lets pods start without the required security sidecarThe cluster stays available during webhook trouble, but production traffic later fails because workloads launched without the sidecar contract the platform assumes.KubernetesAdvanced22 minProSECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProCICD-073Terraform plan looks safe but apply recreates IAM roles after a for_each key renameNo obvious destructive change is noticed in review, yet apply replaces active roles because the stable key used by for_each changed during a refactor.CI/CDAdvanced22 minProSECURITY-065Vault periodic token stops renewingThe workload starts normally, but long-lived sessions fail hours later because the renewal path assumed a parent-child token chain that no longer exists.SecurityAdvanced22 minProSECURITY-053CSP nonce is generated correctly but disappears after CDN template cachingThe application renders a fresh nonce, yet the browser still blocks the script because the cached edge fragment reuses a stale header-body combination.SecurityAdvanced23 minProSECURITY-063KMS policy lets backup jobs encrypt but restore jobs cannot decrypt in the recovery accountBackups complete successfully, yet every restore attempt fails because the disaster-recovery account was never granted the full decrypt path for the same key.SecurityAdvanced23 minProCICD-063Terraform remote state lock survives a killed apply in a cross-account backendA failed apply no longer holds any active process, but every later run still stops on the lock because the backend cleanup path never completed across accounts.CI/CDAdvanced23 minPro