GitHub Actions Workflows
52 incident problems about GitHub Actions Workflows. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (52)
CICD-1191Private submodule checkout breaksA team copies a public submodule checkout recipe. The main repo checks out cleanly, but private submodules fail depending on whether the SSH agent was configured before or after checkout.CI/CDIntermediate22 minProCICD-008Deployments passing without verificationA scenario that narrows down the root cause, centered on designing governance that enforces the verification step before deployment approval, in the situation of deployments passing without verification because a smoke-test conditional is wrong.CI/CDAdvanced23 minProCICD-058Production environment review waits foreverThe environment requires human approval on paper, but tagged releases stall indefinitely because the reviewer and branch rules were designed only for branch-based promotion.CI/CDAdvanced24 minProCICD-052Reusable workflow caller changes the OIDC subject and breaks deploy role trustThe same deployment worked as a repository-local workflow, but it fails after moving into a reusable workflow because the token subject no longer matches the original trust condition.CI/CDAdvanced27 minProCICD-032OIDC subject condition mismatch denies AWS deploy role assumptionGitHub Actions reaches AWS STS, but the trust policy rejects the web identity token because the subject or audience condition no longer matches the branch and environment path.CI/CDAdvanced28 minProCICD-026Promotion pipeline deploys stale image from previous commitThe promotion stage uses an artifact reference that looks correct but resolves to an older image digest after registry cleanup.CI/CDAdvanced29 minProCICD-1208Editor lint says the local reusable workflow path is invalid while GitHub still runs it correctlyThe workflow executes in GitHub, but local tooling reports the reference as missing and pushes engineers toward the wrong cleanup work.CI/CDAdvanced16 minProCICD-011Branch protection rules exist, but the deploy workflow pushes directly to mainCovers a deployment-policy problem where code-review protection exists but the automation account becomes a bypass path.CI/CDBeginner17 minProCICD-1223Matrix cleanup job deletes a needed cacheA multi-shard workflow uses a cleanup step to remove temp caches and occasionally deletes assets still needed by slower shards.CI/CDAdvanced18 minProCICD-1225Token-based checkout works but post-job cleanup failsA pipeline migrates from SSH keys to token auth and later starts failing after the main work is already done.CI/CDAdvanced18 minProCICD-1211Matrix jobs all succeed but the release step still sees only the last computed outputA matrix workflow computes per-target metadata, yet the downstream stage reads only one value because outputs are not aggregated the way the team assumed.CI/CDAdvanced21 minProCICD-028Retry policy re-runs destructive migration job twiceRetry policy re-runs destructive migration job twice is a hands-on troubleshooting drill. A generic retry wrapper helps flaky steps but becomes dangerous when applied to a migration or cleanup command. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, rec...CI/CDIntermediate21 minProCICD-1206Reusable workflow inherits secrets but one environment secret is still blank at runtimeThe reusable deployment starts normally, yet one secret resolves blank because the call boundary does not expose the environment-scoped secret the way the team assumed.CI/CDAdvanced22 minProCICD-1202Deploy key works for one checkout path but package restore still fails on a second private repositoryOne private repository is accessible, yet restore still breaks because a second dependency path needs a different credential scope than the first successful checkout.CI/CDAdvanced23 minProCICD-1210Reusable workflow runs by tag but an internal checkout still resolves against caller contextThe reusable workflow is versioned by tag, yet one internal action path still follows caller context and breaks unexpectedly.CI/CDAdvanced23 minProCICD-023Artifact signing step succeeds locally but fails in CI runnersThe same signing command works on a developer machine but breaks in ephemeral runners because the key material and trust chain differ.CI/CDAdvanced27 minProCICD-059Artifact attestation exists but the deploy gate verifies the wrong repository subjectSupply-chain verification is enabled, yet trusted artifacts are rejected because the admission or deploy gate expects a different repository identity than the builder actually signs.CI/CDAdvanced28 minProCICD-1181GitHub Actions OIDC trust works on main but fails on pull_requestThe same AWS deploy workflow succeeds on main and fails on pull_request because the OIDC token subject no longer matches the IAM trust policy.CI/CDAdvanced28 minProCICD-024Manual approval gate skips production environment reviewManual approval gate skips production environment review is a hands-on troubleshooting drill. A workflow was expected to pause before production, but a condition mismatch causes the approval gate to be skipped. GitHub GitHub Actions Workflows needs to be checked by narrowing s...CI/CDBeginner14 minProCICD-1213Private submodules still failToken-based checkout works, yet private submodules still attempt SSH and fail.CI/CDIntermediate19 minPro