Symptom229 problems· 18 reviewed

Permission Denied

229 incident problems that show up as “Permission Denied”.

All problems (229)

SECURITY-312A browser isolation or proxy layer protects the main UI while websocket or export paths bypass the protected route entirely during a failover rehearsalThe most visible path is controlled and a lower-visibility path still leaks data or interactivity. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-119A CASB session rule blocks downloads in the browser, but the desktop client uses a direct API token path that bypasses the web controlThe browser looks governed, yet data still leaves the tenant because another client channel was never put behind the same session controls.SecurityAdvanced18 minProK8S-146A Gateway API route binds to the correct listener, but the backendRef points at a Service in another namespace without the required ReferenceGrantEverything looks connected until cross-namespace security rules are evaluated.KubernetesAdvanced18 minProCICD-270A provenance gate compares Git tags while the published release is built from a detached worktree tarball during a failover rehearsalSource control identity and published artifact identity diverge even though both look plausible in isolation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-477A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate18 minProSECURITY-264A Vault policy grants transit encryption while the wrapped response workflow strips the unwrap capability from operators during a failover rehearsalThe crypto permission exists and the operational path to use it is incomplete. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-312An IaC validation stage ignores tag-only drift while a compliance controller uses those tags to permit or deny later runtime changes during a failover rehearsalThe infrastructure shape matches expectations, yet its governance behavior does not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-240An integrity gate trusts an object-store ETag after transparent recompression changed the real payload identity during a failover rehearsalThe object is present and the hash-like signal no longer represents the original binary content. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProSECURITY-106An OPA policy package rename leaves the fallback allow rule active in one cluster after a partial config rolloutMost clusters enforce the new package, but one environment silently drops into the default allow behavior because its bundle path never updated.SecurityAdvanced18 minProCICD-122Cosign verification succeeds on the public digest, but deployment pulls from a private mirror that serves a different manifestSupply chain checks pass during build, yet the runtime artifact is not the one that was signed because the mirror rewrites the digest target.CI/CDAdvanced18 minProK8S-104CSI node plugin is healthy but SELinux labeling blocks the kubelet from using the published socketThe DaemonSet looks ready, yet mounts fail because the host path and socket labels do not allow the kubelet domain to connect.KubernetesAdvanced18 minProK8S-100Ingress leader election looks healthy but one class still routes nowhereThe controller pods are up, yet routes for one ingress class remain empty because the controller cannot write the status fields other components depend on.KubernetesAdvanced18 minProNETWORK-076Policy-based routing sends health-check probes into a blackhole next hopNormal application flows look fine, but the service stays unhealthy because policy routing treats the health-check source differently and steers it to a dead path.NetworkAdvanced18 minProNETWORK-110The ACL is accepted in the config, but TCAM is full and the new deny rule is never programmed into hardwareOperators trust the running configuration, yet packets keep flowing because the forwarding ASIC could not install the rule set.NetworkAdvanced18 minProK8S-125The kubelet credential provider cache expires before the node refreshes its cloud identity, and private registry pulls fail only after several hoursNew pods work immediately after boot, but later image pulls break because two credential lifecycles drift apart.KubernetesAdvanced18 minProCICD-127The release pipeline signs the SBOM for the original image digest, but a last-minute rebuild produces a new digest that goes out unsignedEvery compliance report points at a valid attestation, just not for the image that actually ships.CI/CDAdvanced18 minProLINUX-080XFS project quota silently blocks writes inside the container content pathThe filesystem still has free space, but one workload starts failing writes because a project quota limit was reached on the specific content subtree it uses.LinuxAdvanced18 minProCICD-228A deploy pipeline signs the container image but not the values bundle that actually changes runtime behavior during a failover rehearsalSupply-chain checks pass for the binary artifact while the configuration artifact remains unsigned and mutable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-476A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProCICD-478A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minPro