CI/CD Release Safety
105 incident problems about CI/CD Release Safety. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (105)
CICD-160A final approval step signs off the release manifest, but the deploy job re-renders templates afterward and ships a different object set than was reviewedApproval happened on one representation of the release, while execution used another.CI/CDAdvanced18 minProCICD-222A promotion rule trusts semantic version metadata while mirror sync rewrites the build metadata during a failover rehearsalThe release artifact keeps its version label, yet the mirror path mutates the metadata field one downstream gate still uses. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-162A release gate reads a stale error budget snapshot during a failover rehearsalThe canary automation evaluates lagged data and promotes or blocks on the wrong signal. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-139Canary analysis compares the old metric label after a service rename and promotes a release on meaningless dataThe statistical gate still returns a verdict, but it is evaluating the wrong stream after an observability label migration.CI/CDAdvanced18 minProCICD-324A canary approval checks HTTP success while the job queue depth quietly rises behind the scenes and the release passes on the wrong health dimension during a failover rehearsalUser-facing requests look fine, but asynchronous backlog is already proving the release is unhealthy. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-216A final approval signs one manifest while the deploy job renders a different object set during a failover rehearsalReview and execution diverge because mutation still happens after signoff. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-145A phased rollback restores traffic routing but leaves the message queue schema on the new version, and old workers poison retry trafficUser-facing paths look recovered, yet asynchronous paths still speak the newer contract and create delayed instability.CI/CDAdvanced19 minProCICD-258A rollback restores application code while feature migration flags remain enabled in the old environment during a failover rehearsalThe binary path moves backward and the runtime behavior still follows the newer feature contract. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-180A rollback restores the app path but leaves an asynchronous contract on the newer version during a failover rehearsalUser-facing traffic recovers while queue consumers, workers, or webhooks still run with incompatible assumptions. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-300A rollout job waits for one migration task while a second schema-affecting job starts from another workflow in parallel during a failover rehearsalThe database change path appears serialized, yet another automation lane mutates the same contract at the same time. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-115Blue-green cutover updates ingress weights but the background cron target still writes into the old database schemaUser traffic looks healthy after the switch, yet scheduled jobs still point at the old stack and corrupt data alignment across environments.CI/CDAdvanced20 minProCICD-105Rollback restores the app chart but not the migration job image and the database contract stays ahead of the codeA release rollback appears complete, yet application errors continue because the migration runner image remained on the newer schema contract.CI/CDAdvanced20 minProCICD-081Approval workflow promotes the wrong artifactThe review step is followed correctly, but the production deployment still uses the wrong image because the artifact reference is re-evaluated after a newer build already exists.CI/CDAdvanced21 minProCICD-140A release notes bot creates the Git tag before the artifact upload finalizes, and downstream consumers fetch a version with no binaries yetThe version appears published to automation, but its payload is still in flight when the deployment job tries to consume it.CI/CDIntermediate15 minProCICD-135A rollback job restores the config map but not the worker scale, and the system keeps over-consuming the old backendConfiguration returns to normal, yet runtime pressure stays high because capacity settings were treated as outside the rollback scope.CI/CDIntermediate15 minProCICD-399A broken-glass deploy skips manual approval while cleanup automation still assumes the abandoned candidate release owns the shared sandbox during a staged decommissionThe emergency path works, but cleanup logic later tears down the wrong environment state. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDIntermediate16 minProCICD-131A change-approval webhook retries on timeout and opens duplicate maintenance windows for the same deploymentOne release becomes two approved windows because the idempotency key was not preserved across retries.CI/CDIntermediate16 minProCICD-159A release pipeline reuses the same artifact name across two environments, and the staging package overwrites the production-ready build in shared storageThe objects are all present, but one naming collision turns an environment boundary into a storage race.CI/CDIntermediate16 minProCICD-336A deployment lock is cleared manually, but downstream cleanup logic still assumes the old lock owner is active and deletes the wrong environment during a failover rehearsalThe lock seems gone, yet ownership metadata from the previous run still drives destructive automation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDIntermediate17 minProCICD-174A multi-architecture promotion pipeline validates only one platform manifest during a failover rehearsalThe tag exists and one worker pool succeeds, yet another architecture never receives the complete promoted artifact. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDIntermediate17 minPro