Resource Exhaustion
159 incident problems that show up as “Resource Exhaustion”.
먼저 읽을 가이드
추천 문제
All problems (159)
SECURITY-125A SIEM suppression for the vulnerability scanner hides real lateral movementNoise reduction worked for one source, but the coarse suppression pattern now covers genuine malicious activity.SecurityAdvanced17 minProSECURITY-228A custom WAF response hides the real block reason while upstream retries amplify the same exploit attempt internally during a failover rehearsalThe control works and one observability decision turns it into operational noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-160A ransomware isolation workflow snapshots the volumes correctly, but the snapshot retention tag is missing and cleanup automation deletes the evidence before triage startsContainment worked, yet incident preservation failed because the evidence path lacked lifecycle protection.SecurityAdvanced18 minProSECURITY-399Containment isolates egress from compromised hosts while the forensic image or memory capture workflow still depends on an outbound escrow service during a staged decommissionThe incident is contained and the evidence pipeline quietly breaks. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced18 minProLINUX-100Filesystem is remounted read-only after transient storage errors but the app hides it as generic 500sThe application logs are noisy, yet the real cause is the kernel remounting the filesystem read-only after I/O faults the app never surfaces clearly.LinuxAdvanced18 minProK8S-090Node reboot storm leaves CSI node plugin healthy but volume mounts failThe plugin pods appear up after recovery, but mounts still fail because kubelet is looking for a registration endpoint that the updated plugin no longer exposes in the same path.KubernetesAdvanced20 minProSECURITY-089SIEM suppression rule hides the second stage of an attackThe first alerts are known noise, but the actual compromise gets hidden because the suppression logic keys on a reused naming pattern across rebuilt hosts.SecurityAdvanced20 minProLINUX-068tmpfs-backed runtime path fillsThe service outage looks like a simple restart loop, but the deeper issue is runtime storage pressure from large repeated coredumps on a limited tmpfs path.LinuxAdvanced20 minProLINUX-079auditd backlog overflow drops the exact events needed to explain the breach windowAuditing is enabled, yet the highest-value records are missing because the kernel backlog overflowed during bursty activity and the team never noticed the loss signal.LinuxAdvanced21 minProK8S-086Cluster Autoscaler ignores pending podsPods stay pending and autoscaling never reacts because the requested local storage profile cannot fit any node shape in the expansion group.KubernetesAdvanced21 minProK8S-097CSI snapshot restore completes but the filesystem UUID collision confuses the bootstrap scriptStorage comes back online, yet the app still fails because the restored filesystem identity collides with a value the startup logic treats as unique.KubernetesAdvanced21 minProCICD-065ECR lifecycle cleanup deletes one architecture image and arm nodes start failing pullsThe repository still contains the expected tag, but multi-architecture pulls break on one platform because the manifest list points to a child image that was already expired.CI/CDAdvanced21 minProCICD-085CloudFormation import succeeds but later drift repair wants to replace the manually retained resourceThe stack stabilizes after import, yet a future update becomes dangerous because the imported resource shape still differs from what the template assumes is replaceable.CI/CDAdvanced22 minProSECURITY-070EDR quarantine removes the log shipper binary and host visibility disappears without an alertThe endpoint agent did its job from one perspective, but security operations lose telemetry because the quarantined component was also the only path to central visibility.SecurityAdvanced22 minProCICD-093Terraform drift fix replaces a subnet that still holds the canary target group routeThe plan appears corrective, but applying it would cut live traffic because one supposedly stale subnet still anchors an active canary path.CI/CDAdvanced22 minProK8S-076VolumeSnapshot restore binds to the wrong PVC lineage after a cloned recovery testThe snapshot data is valid, but a later restore attaches to the wrong expectation chain because snapshot content and clone naming were reused too casually during testing.KubernetesAdvanced22 minProLINUX-085XFS metadata corruption warning is stale but the on-call plans a destructive repair on the mounted volumeAn old alert resurfaces during an incident, and the real risk now is operator action because the filesystem is still mounted and serving production writes.LinuxAdvanced22 minProCICD-080Feature flag migration step runs before the dependent schema change reaches every shardThe rollout script succeeds centrally, but one shard still serves the old schema and the new flag path begins calling a column that does not exist everywhere yet.CI/CDAdvanced23 minProK8S-062Stale VolumeAttachment object blocks PVC reattach after a node lossThe replacement node is ready, but the workload never mounts its volume because the storage control path still believes the old attachment is active.KubernetesAdvanced23 minProCICD-075Blue-green node group cutover drains the only log shipper before the replacement path is readyThe new nodes are healthy for the app, but operational visibility disappears because the drain order removed a cluster-wide DaemonSet before the replacement fleet was fully attached.CI/CDAdvanced24 minPro