Deployment Governance
222 incident problems about Deployment Governance. Start with the reviewed ones.
Read first
When the CI cache restores the wrong dependency graphAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when package.json, the lockfile, and artifacts no longer agree even after a cache hit.CI/CD3 min readWhen GitHub Actions succeeds but only the rollout failsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the build logs look fine but the failure surfaces only on the target deploy cluster or runtime.CI/CD3 min readThe checking order when GitHub Actions succeeds but only the deploy failsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the workflow is green but the failure happens only in the rollout, promotion, or health check stage.CI/CD3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
CICD-1616A Terraform apply fails in one workspaceOne Terraform workspace still fails after environment slug cleanup.ReviewedCI/CDBeginner7 minFreeLINUX-1377A cron-triggered deploy script works manually and fails overnightA maintenance script is promoted to cron and later the scheduled run fails with a binary not found error no one can reproduce manually.ReviewedLinuxBeginner10 minFree
All problems (222)
LINUX-1377A cron-triggered deploy script works manually and fails overnightA maintenance script is promoted to cron and later the scheduled run fails with a binary not found error no one can reproduce manually.ReviewedLinuxBeginner10 minFreeCICD-1616A Terraform apply fails in one workspaceOne Terraform workspace still fails after environment slug cleanup.ReviewedCI/CDBeginner7 minFreeCICD-1623A deploy approval is correct and one reviewer rule still points at the old team slugThe reviewer is active, but one environment rule still uses the previous team slug.CI/CDBeginner6 minFreeCICD-1637A deploy gate is open and one environment still blocksOne environment still blocks after a branch alias cleanup.CI/CDBeginner7 minFreeCICD-1626A secret rotation is complete and one step still failsOne CI step still fails after a secret rename.CI/CDBeginner7 minFreeCICD-1647A Terraform variable set is attached and one workspace still failsOne workspace still fails after an environment code cleanup.CI/CDBeginner7 minFreeCICD-1657A Terraform variable set is attached and one workspace still failsOne workspace still fails after an environment suffix cleanup.CI/CDBeginner7 minFreeCICD-1667A Terraform workspace has values and one apply still failsOne Terraform apply still fails after an environment suffix cleanup.CI/CDBeginner7 minFreeSECURITY-1341A Grafana SSO login succeeds and folder permissions look emptyA company refreshes its IdP schema and later Grafana users log in successfully but lose access to folders they previously owned.SecurityAdvanced15 minProSECURITY-1339A WAF challenge policy protects the main app and still exposes one admin routeA WAF challenge policy protects the main app and still exposes one admin route focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Security includes can look global while still missing routes defined in separate...SecurityAdvanced15 minProSECURITY-1350An AWS OIDC trust policy matches the cluster issuer and one controller still...An AWS OIDC trust policy matches the cluster issuer and one controller... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared IaC can still emit stale identity data if one workspace cached old metadata.SecurityAdvanced15 minProSECURITY-1360An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity maintenance task succeeds broadly and later one controller in one environment alone continues failing IRSA or web-identity auth.SecurityAdvanced15 minProSECURITY-1370An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity refresh completes and later only one environment continues to fail IRSA or web-identity auth for a controller.SecurityAdvanced15 minProSECURITY-1340An AWSKRUG-style EKS access pattern uses OIDC and still breaks one controllerAn AWSKRUG-style EKS access pattern uses OIDC and still breaks one controller focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared Terraform code can still render different identity assumptions if...SecurityAdvanced15 minProSECURITY-1332An OpenSearch role mapping looks correct and SSO users still lose accessAn OpenSearch role mapping looks correct and SSO users still lose access focuses on Deployment Governance and asks the reader to isolate the key signal in Linux. An auth token can contain the right roles under the wrong shape for a plugin th...SecurityAdvanced15 minProSECURITY-1313A Vault AppRole rollout works in staging and fails in productionA Vault AppRole rollout works in staging and fails in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. CIDR-bound auth often fails on hidden NAT differences rather than on Vault role misconfigu...SecurityAdvanced16 minProCICD-1575An ApplicationSet renders the new branch map and one app still deploys the old refOne Argo CD application keeps syncing the old branch after branch map cleanup.CI/CDAdvanced10 minProCICD-1595An Argo CD OCI repo works and one app still syncs the old chartOne Argo CD app keeps syncing the old chart after OCI registry cleanup.CI/CDAdvanced10 minProCICD-1605An Argo CD repo update is correct and one application still syncs the old chartOne Argo CD app still syncs the old chart after registry cleanup.CI/CDAdvanced10 minProCICD-1585An Argo CD sync is healthy and one app still deploys the old chartOne Argo CD app syncs the old chart after OCI repository cleanup.CI/CDAdvanced10 minPro