Artifact Promotion
325 incident problems about Artifact Promotion. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (325)
SECURITY-1242A rotated secret keeps triggering alertsAn incident response team rotates a secret and later keeps seeing alerts tied to an old downloadable diagnostic archive.SecurityIntermediate17 minProSECURITY-1247A rotated secret keeps triggering alertsAfter a secret rotation, teams still see alerts tied to an old downloadable artifact generated during the incident window.SecurityIntermediate17 minProCICD-1271A setup-node cache step succeeds on hosted runners but hangs on one self-hosted repoA monorepo using workspaces starts failing only on one self-hosted lane after cache support is enabled.CI/CDAdvanced17 minProCICD-1318An artifact signing step succeeds and provenance verification failsA release pipeline renames or relocates packaged output between signing and promotion and later attestation checks start failing.CI/CDAdvanced17 minProSECURITY-1217Secret scanning catches the token againA revoked token disappears from the repo tree but scanning keeps flagging downloads or release bundles.SecurityIntermediate17 minProCICD-1261A cache restore step works on hosted runners but fails on a self-hosted runnerCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced18 minProCICD-1266A cache restore step works on hosted runners but fails on a self-hosted runnerA self-hosted pipeline starts failing only on cache restore or save after a containerized or sudo-based build step was introduced.CI/CDAdvanced18 minProCICD-1265A Docker build pushes successfully but later pulls failCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced18 minProCICD-1270A Docker build pushes successfully but later pulls failA registry migration leaves CI green while production deploys fail or pull an unexpected image because the runtime host is still logged into the former registry.CI/CDAdvanced18 minProCICD-1283A self-hosted runner passes health checks but builds fail near the endA self-hosted container build lane grows flakier over several days while the runner still shows healthy in the Actions UI.CI/CDAdvanced18 minProCICD-1231A workflow deploys successfully but rollback cannot find the buildA team tries to promote and later roll back one release, but the rollback pipeline cannot identify which immutable artifact the release should point to.CI/CDAdvanced18 minProCICD-1228Self-hosted runner reaches the artifact store but uploads still failA self-hosted runner can download code and dependencies but starts failing only on artifact upload calls.CI/CDAdvanced18 minProCICD-1251A hotfix workflow builds the right image but the production deploy still reuses the previous digestA hotfix release is approved and deployed quickly, but post-deploy checks reveal the cluster still runs the previous image build.CI/CDAdvanced19 minProCICD-1236A release promotion succeeds but provenance attestation is missingA team adopts provenance generation and later finds production artifacts cannot be tied back to a verifiable attestation in the release pipeline.CI/CDAdvanced19 minProCICD-1218A reusable deployment workflow succeeds but later cleanup deletes the artifactA reusable workflow promotes a build, but compliance review later finds the evidence package already deleted.CI/CDAdvanced20 minProCICD-1211Matrix jobs all succeed but the release step still sees only the last computed outputA matrix workflow computes per-target metadata, yet the downstream stage reads only one value because outputs are not aggregated the way the team assumed.CI/CDAdvanced21 minProCICD-1210Reusable workflow runs by tag but an internal checkout still resolves against caller contextThe reusable workflow is versioned by tag, yet one internal action path still follows caller context and breaks unexpectedly.CI/CDAdvanced23 minProCICD-1204Container registry login succeeds but build still pulls anonymouslyA registry login step copied from public examples looks green. The later builder still pulls anonymously because it uses a different execution context than the shell that performed the login.CI/CDAdvanced24 minProCICD-1199Container image scan passes on build but release still ships an older vulnerable tagThe current build artifact is scanned successfully, yet the release pipeline promotes a different tag or digest that was never covered by the scan result.CI/CDAdvanced25 minProCICD-1187Concurrency cancellation leaves a half-finished promotion state in the release pathCancel-in-progress helps reduce overlap, but one release run exits after mutating shared promotion state and before the next run can safely continue.CI/CDAdvanced29 minPro