CI/CD Release Safety
105 incident problems about CI/CD Release Safety. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (105)
CICD-393A release artifact is immutable while the runtime startup still downloads a policy pack from a bucket with newly narrowed cross-account access during a staged decommissionThe artifact did not change, but its boot dependency contract did. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDAdvanced17 minProCICD-153An emergency patch bypasses the normal image scan stage, but admission still expects the scan metadata label and production refuses the deploymentThe fast path skips validation intentionally, yet the runtime guardrail still requires proof that only the normal path produces.CI/CDAdvanced17 minProCICD-137Build provenance records the merge queue pseudo-ref, but the published tag points elsewhere and auditors cannot reconcile the releaseAll artifacts exist, yet traceability breaks because the build source ref and user-facing release ref diverged.CI/CDAdvanced17 minProCICD-101Preview environment cleanup job deletes the release candidate namespace before smoke tests startA pull request environment vanishes moments before validation because the cleanup workflow no longer waits for the downstream smoke test status.CI/CDAdvanced17 minProCICD-118Secret-scanning allowlist suppresses detection of a real deploy key leak after the repository path pattern changedA known false positive rule is kept too broad, and once the repository layout changes it begins to hide a genuine credential leak in the new path.CI/CDAdvanced17 minProCICD-148The artifact retention job keeps the container image but deletes the detached attestation blob, and production admission starts blocking the next rolloutBuild and publish succeeded, yet the downstream verifier requires a side artifact that retention policy treated as optional.CI/CDAdvanced17 minProCICD-351A blue-green cutover validates HTTP health while background lease holders still point at the retiring environment during a staged decommissionThe front door is healthy, but a hidden ownership path keeps mutating state from the wrong side. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDAdvanced18 minProCICD-330A container build uses one CA bundle during image creation while the runtime base layer refreshes and trusts a different internal PKI root during a failover rehearsalThe built image and the later-executed image lineage no longer share the same trust store assumptions. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-270A provenance gate compares Git tags while the published release is built from a detached worktree tarball during a failover rehearsalSource control identity and published artifact identity diverge even though both look plausible in isolation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-234A release candidate passes smoke tests in one region while traffic warmup happens against another region during a failover rehearsalValidation says the build is safe, but the workload that receives real traffic is not the one the tests exercised. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDIntermediate18 minProCICD-477A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate18 minProCICD-240An integrity gate trusts an object-store ETag after transparent recompression changed the real payload identity during a failover rehearsalThe object is present and the hash-like signal no longer represents the original binary content. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-112Cache warming publishes a stale base image to the internal mirror and every subsequent build inherits the vulnerable layerThe dependency warmup stage succeeds, yet later builds are compromised by a mirrored base image that bypassed the freshness policy.CI/CDAdvanced18 minProCICD-100Canary traffic shifts correctly but a legacy cron node keeps running the old job image out of bandThe service path looks promoted, but background jobs still operate on the old release because the scheduler pool was not included in the rollout boundary.CI/CDAdvanced18 minProCICD-122Cosign verification succeeds on the public digest, but deployment pulls from a private mirror that serves a different manifestSupply chain checks pass during build, yet the runtime artifact is not the one that was signed because the mirror rewrites the digest target.CI/CDAdvanced18 minProCICD-127The release pipeline signs the SBOM for the original image digest, but a last-minute rebuild produces a new digest that goes out unsignedEvery compliance report points at a valid attestation, just not for the image that actually ships.CI/CDAdvanced18 minProCICD-228A deploy pipeline signs the container image but not the values bundle that actually changes runtime behavior during a failover rehearsalSupply-chain checks pass for the binary artifact while the configuration artifact remains unsigned and mutable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-476A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProCICD-478A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProCICD-288A staged rollback restores old manifests while the backing secret reference already rotated to a new key family during a failover rehearsalThe old release comes back up, but its runtime secret contract no longer exists in the same form. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minPro