Identity And Access
604 incident problems about Identity And Access. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (604)
SECURITY-1331An Elastic API key rotation succeeds and one Beats pipeline still gets 401An Elastic API key rotation succeeds and one Beats pipeline still gets 401 focuses on Identity And Access and asks the reader to isolate the key signal in Linux. Key rotation success in storage does not prove the runtime consumer has...SecurityAdvanced15 minProSECURITY-1343An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected-old-api-key-volume)An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Cluster secret updates do not automatically mean every pod reop...SecurityAdvanced15 minProSECURITY-1329An IdP secret rotation succeeds and one workload still failsAn OIDC signing key is rotated and only one service path keeps rejecting freshly minted tokens for a while afterward.SecurityAdvanced15 minProNETWORK-1349An NGINX auth flow works for normal pages and Cloudflare Access headers...An NGINX auth flow works for normal pages and Cloudflare Access headers... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity loss behind a proxy often happens on local rewrites long after...NetworkAdvanced15 minProSECURITY-1372An OpenSearch dashboard SSO flow works on GET and failsAn OpenSearch dashboard SSO flow works on GET and fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Cross-site POST returns are especially sensitive to SameSite policy changes around proxy and...SecurityAdvanced15 minProSECURITY-1332An OpenSearch role mapping looks correct and SSO users still lose accessAn OpenSearch role mapping looks correct and SSO users still lose access focuses on Deployment Governance and asks the reader to isolate the key signal in Linux. An auth token can contain the right roles under the wrong shape for a plugin th...SecurityAdvanced15 minProSECURITY-1324An SSH certificate rollout is correct and clients still choose the wrong identityA certificate-based SSH migration is rolled out and some users still fail even though the correct certificate is present in their environment.SecurityAdvanced15 minProSECURITY-1277A CDN or reverse proxy rate limit looks strict but password spray still landsAn authentication surface keeps seeing spray attempts after per-IP limits are lowered aggressively.SecurityAdvanced16 minProSECURITY-1311A Cloudflare Access policy looks correct and one API still returns 403An internal API is moved behind a new Access application and only some users keep seeing 403 responses from a browser session that otherwise looks authenticated.SecurityAdvanced16 minProSECURITY-1318A Kubernetes admission webhook serves valid TLS and requests still failA cluster rotates webhook serving certs in place and later admission failures appear even though the pod and service remain healthy.SecurityAdvanced16 minProSECURITY-1262A SameSite cookie setting breaks SSO only on one browser pathSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-1295A signed cookie works on one subdomain and fails on anotherA cross-subdomain auth feature works on one hostname and fails only when routed through a CDN alias or alternate domain.SecurityAdvanced16 minProSECURITY-1301A Vault AppRole login succeeds and database credentials still expire earlyAn app authenticates with AppRole and later loses its dynamic credentials long before the advertised secret lifetime should end.SecurityAdvanced16 minProSECURITY-1313A Vault AppRole rollout works in staging and fails in productionA Vault AppRole rollout works in staging and fails in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. CIDR-bound auth often fails on hidden NAT differences rather than on Vault role misconfigu...SecurityAdvanced16 minProSECURITY-1321An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy-change)An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. OIDC loops often come from callback identity drift rather than from bad user cr...SecurityAdvanced16 minProSECURITY-1303Cloudflare Access protects the app generally and one cached path reaches the origin without identity headersAn origin trusts CF Access headers and later one static-like route starts reaching it without the expected identity context.SecurityAdvanced16 minProSECURITY-1309mTLS resumes fine after certificate rotation on one service and fails on anotherA rotation campaign updates bundles cluster-wide and only one workload or sidecar continues failing mutual TLS handshakes.SecurityAdvanced16 minProSECURITY-1299A service mesh identity update looks correct but one gateway rejects mTLSA workload migration between trust domains succeeds broadly and one ingress or egress gateway alone starts rejecting mTLS peers.SecurityAdvanced17 minProSECURITY-1285A service mesh mTLS policy looks identical across namespaces but one namespace still failsA mesh-wide trust update succeeds broadly and one namespace alone begins failing mTLS handshakes immediately afterward.SecurityAdvanced17 minProSECURITY-1231A browser login loop persists after successful OIDC callbackOne hostname or browser completes the login flow and another loops forever even though the provider logs show success.SecurityAdvanced18 minPro