Permission Denied
229 incident problems that show up as “Permission Denied”.
먼저 읽을 가이드
추천 문제
All problems (229)
SECURITY-132A GitHub App remains installed after a repository transfer, but the new organization grant was never approved and installation tokens lose repository scopeAutomation still exists, yet the trust boundary around the repo changed in a way the app permissions did not follow.SecurityAdvanced17 minProSECURITY-144A new KMS grant allows the backup role to decrypt snapshots, but the grant was created in one region and cross-region restore still failsThe permission exists, just not in the control-plane scope the recovery workflow actually uses.SecurityAdvanced17 minProCICD-157A package signing key rotates in the build stage, but the downstream install test still trusts only the old fingerprint and rejects the freshly built repositoryThe package was published correctly, yet the validation environment pins a previous trust root.CI/CDAdvanced17 minProCICD-252A queued ChatOps rerun inherits stale authorization after the original release freeze window already closed during a failover rehearsalThe command looks approved from the chat log while execution happens under a no-longer-valid auth context. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced17 minProCICD-393A release artifact is immutable while the runtime startup still downloads a policy pack from a bucket with newly narrowed cross-account access during a staged decommissionThe artifact did not change, but its boot dependency contract did. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDAdvanced17 minProLINUX-108A sudoers include file loads later and quietly re-enables a broad NOPASSWD rule the team thought it removedPrivilege hardening seems complete, yet one lexical include order detail restores broad administrative access after the next package update.LinuxAdvanced17 minProK8S-140After an upgrade, the kubelet image credential provider binary path changes, and pulls from the private registry fail on the new nodes onlyLegacy nodes keep working, but fresh workers cannot execute the helper that mints registry credentials.KubernetesAdvanced17 minProCICD-153An emergency patch bypasses the normal image scan stage, but admission still expects the scan metadata label and production refuses the deploymentThe fast path skips validation intentionally, yet the runtime guardrail still requires proof that only the normal path produces.CI/CDAdvanced17 minProCICD-158An IaC drift detector ignores a tag-only difference, but the omitted tag controls an SCP exception and the next deploy fails in production onlyThe infrastructure looks equivalent in shape, yet one governance-relevant tag changed the allowed behavior.CI/CDAdvanced17 minProLINUX-097AppArmor profile loads but one helper binary escapes mediationPrimary commands are constrained, yet a helper path stays unrestricted because the profile pattern never matched the deployed binary location.LinuxAdvanced17 minProCICD-137Build provenance records the merge queue pseudo-ref, but the published tag points elsewhere and auditors cannot reconcile the releaseAll artifacts exist, yet traceability breaks because the build source ref and user-facing release ref diverged.CI/CDAdvanced17 minProCICD-125Git submodule authentication works during checkout, but the downstream Docker build context cannot re-fetch the private module and image creation failsThe workflow clone step succeeds, yet a later stage rebuilds context in an environment without the same credentials.CI/CDAdvanced17 minProCICD-084GitHub Environment protection waits foreverReviewers approve the release, but the gate never opens because the workflow reports status to a differently cased or aliased environment than the protected one.CI/CDAdvanced17 minProLINUX-127Journal forward-secure sealing is enabled, but the verification key was rotated out of sync and log integrity checks now failLogs are still written, yet the trust model behind their integrity no longer validates after a partial key update.LinuxAdvanced17 minProK8S-096PodSecurity admission blocks the debug container flow even though the base workload still runsThe app continues serving traffic, but emergency debugging fails because the current security profile denies the ephemeral container path.KubernetesAdvanced17 minProK8S-117Projected service account token expires and the sidecar never reloads it so calls to the cloud API fail hours laterEverything works after startup, but long-lived pods lose access because one component reads the token once and never reopens the projected file.KubernetesAdvanced17 minProSECURITY-128S3 encryption enforcement is enabled, but a legacy multipart client omits the required KMS context and uploads start failing midstreamThe bucket policy is correct, yet one older client implementation cannot satisfy the newer encryption contract.SecurityAdvanced17 minProCICD-118Secret-scanning allowlist suppresses detection of a real deploy key leak after the repository path pattern changedA known false positive rule is kept too broad, and once the repository layout changes it begins to hide a genuine credential leak in the new path.CI/CDAdvanced17 minProCICD-148The artifact retention job keeps the container image but deletes the detached attestation blob, and production admission starts blocking the next rolloutBuild and publish succeeded, yet the downstream verifier requires a side artifact that retention policy treated as optional.CI/CDAdvanced17 minProSECURITY-115The OAuth device flow trusted-client list still includes a test app and users can bypass the normal consent reviewThe production app is locked down, yet the device flow stays open because an old trusted client registration survived the environment cleanup.SecurityAdvanced17 minPro