Identity And Access
604 incident problems about Identity And Access. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (604)
K8S-1389A service mesh egress gateway looks healthy and outbound TLS still failsA service mesh egress gateway looks healthy and outbound TLS still fails focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Mesh trust rotations can fail asymmetrically when some namespa...KubernetesAdvanced15 minProSECURITY-1300A signed download URL validates in staging but fails in productionSigned file links work in staging and fail only behind the production proxy or CDN path.SecurityIntermediate15 minProSECURITY-1288A signed URL looks valid but file downloads still failDownloads begin failing only after a reverse-proxy or CDN change, even though the signed URL generator code did not change.SecurityIntermediate15 minProLINUX-1318A Vault template updates the file and the service reload hook never runsA secret rotation system updates files reliably and the consuming service still never reloads the new material.LinuxAdvanced15 minProK8S-1363A webhook certificate is valid and admission still times outA webhook certificate is valid and admission still times out focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Webhook health from pods does not prove the apiserver can reach the same endpoint.KubernetesAdvanced15 minProK8S-1373A webhook certificate is valid and admission still times outA webhook certificate is valid and admission still times out focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Pod reachability is not proof of apiserver reachability for admission webhooks.KubernetesAdvanced15 minProSECURITY-1278An app trusts X-Forwarded-Proto from one proxy hop and starts misclassifying secure requestsA reverse proxy or CDN is inserted ahead of an existing app and secure redirect or cookie behavior becomes inconsistent.SecurityIntermediate15 minProK8S-1335An EKS workload reaches AWS APIs and still fails one secret fetchAn EKS workload reaches AWS APIs and still fails one secret fetch focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Cross-cluster portability often fails at subtle identity defaults rather than at obvio...KubernetesAdvanced15 minProLINUX-1338An Elastic agent starts fine and never enrollsA trust bundle is rotated through symlink swaps and later one long-lived agent still rejects the same endpoint with old TLS errors.LinuxAdvanced15 minProK8S-1339An OpenSearch cluster behind Kubernetes ingress looks healthy and still drops...An OpenSearch cluster behind Kubernetes ingress looks healthy and still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Session loops can come from two valid cookies that disagree...KubernetesAdvanced15 minProNETWORK-1305Full strict mode returns 526 only on an alternate hostnameA new vanity or fallback hostname is added and only that path starts returning 526 through Cloudflare.NetworkAdvanced15 minProLINUX-1375MFA is required in policy and one bastion path still bypasses itA bastion hardening change is rolled out and later one login path authenticates users without the expected MFA challenge.LinuxAdvanced15 minProLINUX-1306Time sync fixes itself minutes after boot but TLS clients keep failingA rebooted host later shows good time sync, but services started during the skew window continue failing outbound auth or API calls.LinuxAdvanced15 minProLINUX-1309Vault Agent keeps rotating certificates but the service never reloadsA host renews certificates automatically and the consumer still serves the old cert until manually restarted.LinuxAdvanced15 minProNETWORK-1311A Cloudflare Tunnel stays healthy and origin mTLS still failsA private service is published through Tunnel and later only the mTLS-protected route fails after an origin proxy change.NetworkAdvanced16 minProNETWORK-1320A Cloudflare WARP to Tunnel path reaches the origin and application auth...A Cloudflare WARP to Tunnel path reaches the origin and application auth... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Path success through Zero Trust does not prove origin ACLs recognize the new caller...NetworkAdvanced16 minProCICD-1312A GitHub deployment uses OIDC successfully and Terraform still failsA team migrates to OIDC and still sees Terraform acting as an old IAM principal in only one workflow path.CI/CDAdvanced16 minProSECURITY-1287A rate limiter reduces abuse in IPv4 logs but an attacker keeps spraying via IPv6 privacy addressesPer-IP rate limiting appears to work and an attack still continues from an address family the dashboards underweight.SecurityAdvanced16 minProCICD-1262A reusable workflow deploys correctly in the caller but silently loses its secret in the called workflowCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced16 minProSECURITY-1267A SameSite cookie setting breaks SSO only on one browser pathA browser-specific SSO failure appears after cookie hardening, while the same app still works through simpler redirect paths.SecurityIntermediate16 minPro