Symptom229 problems· 18 reviewed

Permission Denied

229 incident problems that show up as “Permission Denied”.

All problems (229)

SECURITY-090Vault unseal succeeds but one performance standby still serves stale auth configuration after leader failoverThe cluster looks healthy again, yet some login paths still fail because a standby node continues using old auth backend settings after control-plane leadership changed.SecurityAdvanced23 minProSECURITY-069Organization-wide CloudTrail is enabled but one region never uses the expected KMS keyAudit logging exists everywhere, yet one region violates the encryption standard because replication and key policy assumptions drifted apart over time.SecurityAdvanced24 minProSECURITY-055EDR quarantine removes the log shipper binary and blinds central visibilityContainment works on the compromised host, but the action also stops telemetry collection and makes the rest of the investigation much harder.SecurityAdvanced25 minProNETWORK-040Firewall rule shadowing makes the app port reachable from one segment onlyAn allow rule was added for the correct service, but an earlier broader rule still matches first on another path and blocks the flow unexpectedly.NetworkAdvanced25 minProSECURITY-040New allow rule never takes effectOperators add the expected allow rule for an update feed or admin flow, but traffic still fails because an earlier broader deny or different zone match wins first.SecurityAdvanced25 minProSECURITY-060GuardDuty member onboarding failsThe delegated admin path looks correct, but one child account never enables the detector because organizational guardrails deny the role creation needed by the service.SecurityAdvanced26 minProSECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProCICD-052Reusable workflow caller changes the OIDC subject and breaks deploy role trustThe same deployment worked as a repository-local workflow, but it fails after moving into a reusable workflow because the token subject no longer matches the original trust condition.CI/CDAdvanced27 minProCICD-032OIDC subject condition mismatch denies AWS deploy role assumptionGitHub Actions reaches AWS STS, but the trust policy rejects the web identity token because the subject or audience condition no longer matches the branch and environment path.CI/CDAdvanced28 minProCICD-040Terraform apply succeeds in staging but production backend locks a different state tableThe same pipeline logic passes against one workspace, but production never converges because the remote backend, state lock table, or workspace mapping differs subtly.CI/CDAdvanced30 minProSECURITY-134A CASB inline proxy rewrites the downloaded filename, and the DLP hash allowlist no longer matches the approved documentContent is safe, yet the downstream control no longer recognizes it because one enforcement layer changed the file artifact identity.SecurityAdvanced16 minProSECURITY-122A managed WAF rule override expires at midnight UTC, and the payroll batch starts failing in local business hours the next dayThe temporary exception worked during testing, but time-zone assumptions made its expiry far earlier than operators realized.SecurityAdvanced16 minProCICD-357A reusable workflow signs container images correctly while downstream promotion retags an unsigned digest from a side repository during a staged decommissionSupply-chain controls protect the main path, but a side promotion lane bypasses the signed artifact. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDIntermediate16 minProLINUX-140SSH certificate authentication is configured, but the principals file permissions are too open and the daemon ignores it for security reasonsThe CA trust path is valid, yet certificate login falls back to password prompts because the principal mapping file fails ownership checks.LinuxAdvanced16 minProLINUX-137A bridge netfilter sysctl is set correctly, but unloading and reloading the module resets the value and containers start bypassing the host policyThe host remains configured at rest, yet the live module state changed under the running workload.LinuxAdvanced17 minProSECURITY-114A bucket policy blocks public reads, but the legacy website endpoint still exposes content through an old object ACLThe new policy appears strict, yet one access path bypasses it because object-level permissions were left behind from the static site era.SecurityAdvanced17 minProSECURITY-158A cross-account access analyzer stays green, but a new resource policy grants a service principal wildcard that the analyzer scope does not flag in this org layoutVisibility tooling is present, yet its scope is narrower than the real exposure surface.SecurityAdvanced17 minProCICD-151A deployment freeze opens for one hour, but the delayed approval queue starts the rollout after the window closes and the policy engine revokes credentials mid-releaseEverything was approved at the right time, yet execution drifted outside the governance boundary.CI/CDAdvanced17 minProSECURITY-155A DLP sensor classifies the document correctly, but a newly compressed archive format bypasses the extraction depth limit and the policy never sees the payloadContent controls are configured, yet packaging format changed the scanner's visibility boundary.SecurityAdvanced17 minPro