Identity And Access
604 incident problems about Identity And Access. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (604)
SECURITY-1449A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minProSECURITY-1419A service binding receives a tighter policy and one application tier keeps...A service binding receives a tighter policy and one application tier keeps... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can persist when applications couple reloads to secret change...SecurityAdvanced14 minProSECURITY-1409A service binding receives the correct policy on first rollout and later...A service binding receives the correct policy on first rollout and later... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Permission drift can survive policy rollout when pooled connections cache earlie...SecurityAdvanced14 minProSECURITY-1322A Vault policy looks permissive and KV reads still failA service token is updated and later can enumerate secrets but cannot actually read the intended values from Vault.SecurityAdvanced14 minProSECURITY-1401An access proxy protects the user API and one newly split service path is...An access proxy protects the user API and one newly split service path is... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Security regressions often come from route shadowing, not from a mis...SecurityAdvanced14 minProSECURITY-1384An NGINX allowlist protects private APIs and one upstream app becomes...An NGINX allowlist protects private APIs and one upstream app becomes... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Security gaps can live in the ordering between normalization and authorization, no...SecurityAdvanced14 minProSECURITY-1374An NGINX auth_request gateway protects normal methods and one CORS preflight...An NGINX auth_request gateway protects normal methods and one CORS... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Method-specific branches in proxies can bypass security logic even when the main path...SecurityAdvanced14 minProSECURITY-1335An Ubuntu unattended upgrade secures packages and leaves one bastion inaccessibleA hardened bastion receives unattended upgrades and later downstream systems that pin host identity stop trusting it.SecurityIntermediate14 minProSECURITY-1375Cloudflare Access protects the main hostname and an alternate admin listener...Cloudflare Access protects the main hostname and an alternate admin... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge access controls are only as complete as the hos...SecurityAdvanced14 minProSECURITY-1379Unattended upgrades complete and the host loses trust in its own workload...Unattended upgrades complete and the host loses trust in its own workload... focuses on Identity And Access and asks the reader to isolate the key signal in ubuntu. Automatic certificate renewal can break local trust pin...SecurityAdvanced14 minProSECURITY-1302Vault KV access works in the UI and fails in automationOperators validate access in the UI and later the service account still gets permission denied on KV reads.SecurityIntermediate14 minProLINUX-1316A chronyd recovery brings NTP back and Kerberos still failsA host boots with skew, later synchronizes, and only long-running identity-bound daemons continue failing.LinuxAdvanced15 minProK8S-1392A Gatekeeper policy looks unchanged and one namespace starts failing admissionA Gatekeeper policy looks unchanged and one namespace starts failing admission focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Admission drift can hide in CRD conversion...KubernetesAdvanced15 minProK8S-1345A kubelet certificate rotation succeeds and nodes still flip NotReadyA certificate maintenance window completes and afterward node readiness or metrics become inconsistent despite successful kubelet rotation.KubernetesAdvanced15 minProK8S-1333A Loki ingestion path stays healthy and dashboards still miss one tenantA Loki ingestion path stays healthy and dashboards still miss one tenant focuses on Identity And Access and asks the reader to isolate the key signal in grafana. Multi-tenant observability bugs often come from query path identity, not from ing...KubernetesAdvanced15 minProK8S-1325A projected service account token looks valid and a custom API aggregation...A projected service account token looks valid and a custom API aggregation... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. In Kubernetes auth, a valid token can still be unusable if its aud...KubernetesAdvanced15 minProK8S-1384A Rancher-managed cluster upgrade completes and one node pool never rejoinsA Rancher-managed cluster upgrade completes and one node pool never rejoins focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Managed cluster reconnect failures often live in agent bootstra...KubernetesAdvanced15 minProSECURITY-1292A SameSite fix solves desktop login and still breaks mobile webview SSOAn auth hardening change appears successful until mobile app login starts looping while desktop login remains normal.SecurityIntermediate15 minProSECURITY-1272A SameSite hardening change breaks SSO only on one browser flowA cookie hardening rollout leaves some browsers or embedded login flows broken while ordinary browser login still succeeds.SecurityIntermediate15 minProCICD-1326A self hosted runner reuses a stale npm registry tokenA publish workflow works intermittently on hosted runners and fails reliably on one self-hosted runner with invalid auth errors.CI/CDAdvanced15 minPro