Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

NETWORK-1520A browser SSH app loads and still failsBrowser SSH fails only through one connector after an origin certificate renewal.NetworkAdvanced12 minProNETWORK-1530A browser SSH app loads and still failsBrowser SSH fails only through one connector after origin certificate renewal.NetworkAdvanced12 minProNETWORK-1510A Cloudflare Access app loads and browser SSH still failsBrowser SSH breaks only through one connector after origin certificate renewal.NetworkAdvanced12 minProNETWORK-1500A Cloudflare Access application renders and SSH over browser still failsCloudflare Access browser SSH breaks only through one connector after an origin certificate renewal.NetworkAdvanced12 minProSECURITY-1454A Cloudflare Access service token works for normal API calls and fails on one...A Cloudflare Access service token works for normal API calls and fails on... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Upgrade paths often use different rule branches than ordinary HTTP re...SecurityAdvanced12 minProCICD-1491A GitHub Actions OIDC deploy works in one region and fails in anotherA multi-region deployment pipeline starts failing only in the disaster recovery account after environment names were cleaned up.CI/CDAdvanced12 minProCICD-1541A GitHub deployment job passes approvals and still failsDeployments fail only in one account after moving the production workflow into a new path.CI/CDAdvanced12 minProCICD-1521A GitHub environment approval passes and the deploy job still failsOnly production deploys fail after a workflow file move even though approvals complete normally.CI/CDAdvanced12 minProCICD-1531A GitHub OIDC deployment works in one account and fails in anotherDeployments fail only in one account after moving repositories under a new GitHub organization.CI/CDAdvanced12 minProSECURITY-1481A Keycloak login works and one app still loopsOIDC login loops only for one app after proxy host rewrites were centralized.SecurityAdvanced12 minProCICD-1459A Vault login action succeeds and Terraform still uses stale AWS credentialsA Vault login action succeeds and Terraform still uses stale AWS credentials focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Credential freshness bugs often come from wrapper ordering around expo...CI/CDAdvanced12 minProSECURITY-1373An Elastic logging sidecar reconnects (elastic-sidecar-mounted-new-secret-but-kept-old-key-in-env-file)An Elastic logging sidecar reconnects (elastic-sidecar-mounted-new-secret-but... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Projected secret updates do not guarantee the process r...SecurityIntermediate12 minProSECURITY-1491An IAM access analyzer finding is resolved and a cross-account role still grants accessA cross-account role remains reachable from a retired account even after the primary stack set shows the fix applied.SecurityAdvanced12 minProSECURITY-1501An IAM access finding is resolved and a cross-account role still grants accessA retired external account can still assume a role from one region after the main fix is applied.SecurityAdvanced12 minProSECURITY-1511An IAM access finding is resolved and a cross-account role still grants accessA retired external account can still assume a role from one region after the primary fix is applied.SecurityAdvanced12 minProSECURITY-1362An OpenSearch dashboards login loops after proxy hardeningA reverse proxy is hardened and later users start bouncing between the IdP and dashboards without ever reaching an authenticated session.SecurityIntermediate12 minProSECURITY-1456An SSH CA principal map becomes too broadSSH certificate access becomes broader than intended after host and role names were standardized.SecurityAdvanced12 minProSECURITY-1323A Grafana OAuth login works and role sync stays wrongAn IdP cleanup changes claim names and Grafana users later authenticate successfully but lose admin or editor access unexpectedly.SecurityIntermediate13 minProSECURITY-1414A hardened proxy blocks normal admin verbs and one legacy WebDAV endpoint...A hardened proxy blocks normal admin verbs and one legacy WebDAV endpoint... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can escape security controls when named locations do n...SecurityAdvanced13 minProSECURITY-1424A hardened proxy blocks normal admin verbs and one legacy WebDAV path still...A hardened proxy blocks normal admin verbs and one legacy WebDAV path still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass controls when named locations do not inher...SecurityAdvanced13 minPro