Resource Exhaustion
159 incident problems that show up as “Resource Exhaustion”.
먼저 읽을 가이드
추천 문제
All problems (159)
CICD-090Canary bake time is shorter than the queue visibility window and failure signals arrive after promotionThe rollout passes its bake stage, but hidden worker failures appear only after the queue timeout window elapses, long after traffic has fully shifted.CI/CDAdvanced24 minProLINUX-062Missing bind mount at boot makes rsync --delete clean the host path instead of the volumeThe sync command is valid, but the intended mount point never appeared and the cleanup step now targets the underlying directory on the root filesystem.LinuxAdvanced24 minProK8S-071PodDisruptionBudget and topology spread leave no legal recovery layout after an AZ outageThe workload had enough replicas before the outage, but after one zone disappears the remaining rules make every recovery option violate either spread or disruption guarantees.KubernetesAdvanced24 minProLINUX-053rsyslog disk queue fills /var after the remote collector becomes unreachableCentral logging is configured correctly for healthy periods, but when the collector disappears the buffered queue grows until the local partition reaches pressure.LinuxAdvanced24 minProLINUX-009An rsync deploy filling the root partitionA scenario that narrows down the root cause, centered on improving the deploy tool's temp-file strategy and the partition policy, in the situation of an rsync deploy filling the root partition because of temp files.LinuxAdvanced26 minProLINUX-057RAID rebuild targets the wrong device after a degraded mdadm recoveryThe array is degraded but recoverable, and the biggest risk now is re-adding or marking the wrong member while interpreting device names under pressure.LinuxAdvanced27 minProSECURITY-351A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate16 minProLINUX-098Rsync transfer is complete but hard links were expanded and the backup target fills twice as fastThe restore path works, yet storage usage explodes because the transfer options did not preserve link semantics the source tree relied on.LinuxAdvanced16 minProSECURITY-116Windows event forwarding over mutual auth works, but the subscription content format drops PowerShell script block logsThe channel is healthy, yet investigation quality degrades because the collector-side format setting strips fields one detection depends on.SecurityAdvanced16 minProNETWORK-160A campus fabric migration preserves the SVI gateway addresses, but one downstream ACL still keys off the old chassis MAC and security monitoring floods with false anomaliesRouting is fine, yet dependent controls still expect the previous gateway identity.NetworkAdvanced17 minProSECURITY-140An incident isolation rule cuts a host off from attackers and also from the EDR telemetry path, leaving responders blindContainment succeeds, yet investigation quality collapses because the rule removed the team's own visibility channel.SecurityAdvanced17 minProLINUX-093Systemd path unit keeps relaunching a failed helperThe service appears to restart itself, but the real trigger is a path unit that keeps firing on the same file activity loop.LinuxAdvanced17 minProLINUX-129The auditd backlog limit is too small and a privilege escalation burst drops the very exec events the investigation needsThe host stays online, but the audit trail is incomplete because event pressure outran the queue design.LinuxAdvanced17 minProNETWORK-336A gateway IP remains stable while one downstream security policy still keys off the previous virtual MAC after a fabric migration during a failover rehearsalAddress continuity masks an identity change that another control still cares about. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced18 minProLINUX-113A shell cleanup trap unmounts the bind mount before the child process exits and late writes vanish from the host pathThe script looks tidy, but teardown runs too early and data written by a still-running child process disappears into a dead mount namespace.LinuxAdvanced18 minProSECURITY-469A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate18 minProSECURITY-276An incident quarantine revokes general egress while forensic collection still depends on one artifact upload endpoint during a failover rehearsalContainment is immediate and visibility disappears with it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-112Cache warming publishes a stale base image to the internal mirror and every subsequent build inherits the vulnerable layerThe dependency warmup stage succeeds, yet later builds are compromised by a mirrored base image that bypassed the freshness policy.CI/CDAdvanced18 minProCICD-100Canary traffic shifts correctly but a legacy cron node keeps running the old job image out of bandThe service path looks promoted, but background jobs still operate on the old release because the scheduler pool was not included in the rollout boundary.CI/CDAdvanced18 minProK8S-112HorizontalPodAutoscaler sees the custom metric intermittentlyAutoscaling seems random because the adapter is reachable, yet TLS validation fails sporadically between control plane components.KubernetesAdvanced18 minPro