Topic17 problems· 3 reviewed

Container Image Delivery

17 incident problems about Container Image Delivery. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

CICD-002Recovering a container deployment where the latest tag blocks rollbackCovers how to redesign a safe rollback structure in a pipeline that has no image versioning strategy.ReviewedCI/CDAdvanced25 minProCICD-009Deployment failingA scenario that narrows down the root cause, centered on checking the permission-policy difference by event type, in the situation of a deployment failing because the secret is empty only on tag releases.ReviewedCI/CDIntermediate21 minFreedocker push: denied: requested access to the resource is denieddocker push: denied: requested access to the resource is denied is a hands-on troubleshooting drill. Check which registry an image tag actually points to before debugging credentials. GitHub Container Image Delivery needs to be checked by narrowing scope, recent change, and th...ReviewedCI/CDBeginner14 minFreeCICD-015During parallel deploys, the staging cache bleeds into production tooDuring parallel deploys, the staging cache bleeds into production too is a hands-on troubleshooting drill. Covers an incident where a shared cache key with no environment separation lets staging results affect production. GitHub GitHub Actions Workflows needs to be checked by...CI/CDIntermediate20 minProCICD-018A path-filter malfunction that drops tests only on pull request eventsA path-filter malfunction that drops tests only on pull request events is a hands-on troubleshooting drill. Covers a problem where a wrong changed-file path filter drops the most important PR tests. Container Image Delivery needs to be checked by narrowing scope, recent change...CI/CDBeginner16 minFreeCICD-020Only nightly builds failing due to a package registry rate limitA situation where it is fine during the day, but parallel builds pile up at certain hours and hit an external package registry limit.CI/CDIntermediate22 minPro

All problems (17)

CICD-009Deployment failingA scenario that narrows down the root cause, centered on checking the permission-policy difference by event type, in the situation of a deployment failing because the secret is empty only on tag releases.ReviewedCI/CDIntermediate21 minFreedocker push: denied: requested access to the resource is denieddocker push: denied: requested access to the resource is denied is a hands-on troubleshooting drill. Check which registry an image tag actually points to before debugging credentials. GitHub Container Image Delivery needs to be checked by narrowing scope, recent change, and th...ReviewedCI/CDBeginner14 minFreeCICD-018A path-filter malfunction that drops tests only on pull request eventsA path-filter malfunction that drops tests only on pull request events is a hands-on troubleshooting drill. Covers a problem where a wrong changed-file path filter drops the most important PR tests. Container Image Delivery needs to be checked by narrowing scope, recent change...CI/CDBeginner16 minFreeCICD-030Release note generation fails on shallow clone runnersRelease note generation fails on shallow clone runners is a hands-on troubleshooting drill. A changelog step depends on full git history, but shallow checkout settings hide the required tags and commits. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, r...CI/CDIntermediate18 minFreeCICD-034Private GHCR package install fails although workflow repository is trustedA build can authenticate to GitHub, but dependency restore still fails because the package lives in another private repository with separate access control.CI/CDIntermediate19 minFreeCICD-002Recovering a container deployment where the latest tag blocks rollbackCovers how to redesign a safe rollback structure in a pipeline that has no image versioning strategy.ReviewedCI/CDAdvanced25 minProCICD-015During parallel deploys, the staging cache bleeds into production tooDuring parallel deploys, the staging cache bleeds into production too is a hands-on troubleshooting drill. Covers an incident where a shared cache key with no environment separation lets staging results affect production. GitHub GitHub Actions Workflows needs to be checked by...CI/CDIntermediate20 minProCICD-020Only nightly builds failing due to a package registry rate limitA situation where it is fine during the day, but parallel builds pile up at certain hours and hit an external package registry limit.CI/CDIntermediate22 minProCICD-026Promotion pipeline deploys stale image from previous commitThe promotion stage uses an artifact reference that looks correct but resolves to an older image digest after registry cleanup.CI/CDAdvanced29 minProCICD-039ECR lifecycle cleanup deletes digest still referenced by promotion manifestThe production promotion manifest points to an immutable digest, but registry cleanup removes the only copy before the delayed deployment window starts.CI/CDIntermediate22 minProCICD-054Buildx multi-arch pipeline failsThe image builds successfully for one architecture, but the overall publish stage fails when temporary layers and cache exports exceed the runner disk budget.CI/CDAdvanced26 minProCICD-059Artifact attestation exists but the deploy gate verifies the wrong repository subjectSupply-chain verification is enabled, yet trusted artifacts are rejected because the admission or deploy gate expects a different repository identity than the builder actually signs.CI/CDAdvanced28 minProCICD-003Adding an approval stage to an unverified production deployment pipelineA template-style problem for designing an approval flow and staging verification with per-environment deployment boundaries.CI/CDBeginner15 minProCICD-053OCI Helm chart publish succeeds but cluster still pulls the previous chartThe registry receives the new chart artifact, yet the deployment job keeps resolving the previous digest because the chart reference and version bump were not updated together.CI/CDIntermediate20 minProCICD-055CodeBuild local cache reuses stale base layer after package repository changedBuild time looks great, but the produced image quietly carries an older package baseline because local Docker layer cache survives a repository-side base image update.CI/CDIntermediate21 minProCICD-017Unsigned images get mixed in and are blocked by the deployment approval policyA situation where the security policy is correct but a missing image-signing scheme blocks releases for only certain services.CI/CDIntermediate21 minProCICD-022Canary deploy passes health checks but fails background jobsCanary deploy passes health checks but fails background jobs is a hands-on troubleshooting drill. The web process looks healthy while the worker image lags behind and starts processing incompatible payloads. GitHub Actions Workflows needs to be checked by narrowing scope, rece...CI/CDIntermediate24 minPro