DNS Resolution
39 incident problems about DNS Resolution. Start with the reviewed ones.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
All problems (39)
Could not resolve host: external API calls fail on one server onlyCould not resolve host: external API calls fail on one server only is a hands-on troubleshooting drill. Tell a DNS failure from a connectivity or remote outage. GitHub dns-resolution needs to be checked by narrowing scope, recent change, and the current live signal before roll...ReviewedNetworkBeginner3 minFreeLINUX-1340A boot upgrade leaves one host without DNSA boot upgrade leaves one host without DNS focuses on cluster-maintenance and asks the reader to isolate the key signal in Linux. DNS failures after upgrades can come from two healthy components disagreeing on which interface is primary.LinuxAdvanced15 minProLINUX-1356A rootless Docker host resolves DNS manually and containers failA rootless container service survives reboot and afterward only name resolution fails while network reachability remains fine.LinuxAdvanced15 minProLINUX-1346A rootless service starts (rootless-service-dns-broke-after-reboot-due-to-user-resolver-path)A rootless service starts (rootless-service-dns-broke-after-reboot-due-to... focuses on dns-resolution and asks the reader to isolate the key signal in Linux. Rootless boot persistence can change which resolver view a process...LinuxAdvanced15 minProNETWORK-1325A split horizon DNS setup works on LAN and fails at the edgeA hybrid network uses different answers for internal and public clients and later some edge users resolve to the wrong target after an upstream cache change.NetworkAdvanced15 minProNETWORK-1308Large DNS lookups fail only on TCP fallbackOnly large DNS responses or DNSSEC-heavy queries fail through a path that otherwise seems to resolve names correctly.NetworkAdvanced15 minProK8S-1341A Cilium cluster upgrade passes smoke tests and one namespace loses DNS egressA Cilium cluster upgrade passes smoke tests and one namespace loses DNS egress focuses on dns-resolution and asks the reader to isolate the key signal in Kubernetes. Name-based egress policy can fail when stale DNS state survives longer t...KubernetesAdvanced16 minProK8S-1312A service mesh sidecar is injected correctly and egress still failsA service mesh sidecar is injected correctly and egress still fails focuses on dns-resolution and asks the reader to isolate the key signal in Kubernetes. Sidecar policy debugging should include DNS path changes, not only network ACLs.KubernetesAdvanced16 minProK8S-1304A validating webhook only times out on node-local DNS nodesAdmission failures appear random after a service rename because only certain nodes run through a different DNS path.KubernetesAdvanced16 minProNETWORK-1297A PMTUD issue affects only DNSSEC responsesUsers resolve common domains correctly and validation-heavy DNS workflows fail in one network path.NetworkAdvanced17 minProK8S-1279An external-dns update looks successful but users still hit the wrong load balancerA cluster migration changes DNS and the automation pipeline reports success while real traffic continues to resolve the former endpoint.KubernetesAdvanced17 minProK8S-1281A pod restarts after every successful deploymentA rollout works on some nodes and fails on others immediately after a private endpoint or dependency address changed.KubernetesAdvanced18 minProK8S-1264Pods resolve names intermittentlyK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced18 minProK8S-1269Pods resolve names intermittentlyCluster DNS appears green in dashboards, but application pods on certain nodes still time out when resolving service or external names.KubernetesAdvanced18 minProNETWORK-1358A DNS service resolves small answers and signed domains failA DNS service resolves small answers and signed domains fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub success does not prove the recursive server can complete its own fallback path.NetworkIntermediate12 minProNETWORK-1366A DNS service resolves small records and DNSSEC-heavy zones failA DNS service resolves small records and DNSSEC-heavy zones fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub success does not prove the recursive server can finish its own fallback behavior.NetworkIntermediate12 minProNETWORK-1277Manual DNS testing passesA DNS incident appears solved after a manual command, but applications continue failing in production.NetworkIntermediate13 minProNETWORK-1338A DNS path fails only for signed domainsOperators validate DNS from a client and still see production resolvers fail selectively for signed zones.NetworkIntermediate14 minProNETWORK-1318A DNS resolver works for most records and large TXT lookups failA DNS resolver works for most records and large TXT lookups fail focuses on dns-resolution and asks the reader to isolate the key signal in Cisco. Partial DNS breakage often starts with packet-size assumptions, not name data quality.NetworkIntermediate14 minProNETWORK-1348A DNS resolver works for most zones and signed domains failA DNS resolver works for most zones and signed domains fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub resolver success does not prove the recursive server can complete its own fallback behavior.NetworkIntermediate14 minPro