Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

K8S-1315Loki ingestion is healthy and dashboards are empty for one tenantLoki ingestion is healthy and dashboards are empty for one tenant focuses on Identity And Access and asks the reader to isolate the key signal in grafana. Empty dashboards can be a tenant identity mismatch even when ingestion is healthy.KubernetesAdvanced16 minProSECURITY-1260Password spray continues through rate limitingAn authentication edge still suffers password spraying even after strict per-IP limits were rolled out.SecurityIntermediate16 minProCICD-1303Terraform init succeeds but apply failsA team refactors shared credentials logic and later only apply fails while init and state refresh continue to work.CI/CDAdvanced16 minProCICD-1323Terraform reads remote state fine and module fetch failsA configuration works from engineers laptops and later fails only in the remote execution environment when a private module source is introduced.CI/CDAdvanced16 minProSECURITY-1291A JWKS rotation is complete but one consumer still failsA token issuer rotates keys and one consumer behind a proxy continues rejecting fresh tokens.SecurityAdvanced17 minProSECURITY-1289A JWT audience check passes in staging but fails in productionAuthentication works end-to-end in staging and fails only in production behind an API gateway performing token exchange or translation.SecurityAdvanced17 minProK8S-1320A kubelet authentication issue appears only on Windows nodesA mixed-node cluster upgrades and only Windows nodes begin showing authentication failures against the API server path.KubernetesAdvanced17 minProCICD-1287A private package restore works on push events but fails on pull_requestA private package restore works on push events but fails on pull_request focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Different GitHub event types can run the same pipeline under materially different secret...CI/CDAdvanced17 minProCICD-1263A private submodule checkout worked before repository hardening but now failsCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced17 minProCICD-1268A private submodule checkout worked before repository hardening but now failsA security hardening change reduces token permissions and suddenly only private submodule checkout begins failing in CI.CI/CDAdvanced17 minProCICD-1281A reusable workflow can mint an OIDC token in one repository but fails in anotherA deployment pipeline is refactored into a shared workflow and later only one repository can no longer assume the cloud role.CI/CDAdvanced17 minProK8S-1299An ingress controller pod is healthy but its target group never updatesA controller chart is upgraded and later ingress state stops reconciling even though the pods remain healthy.KubernetesAdvanced17 minProK8S-1297An IRSA role works in one namespace but fails in anotherA chart upgrade lands and one namespace loses AWS API access while another using the same role keeps working.KubernetesAdvanced17 minProSECURITY-1281An OAuth callback succeeds on the identity provider but the app rejects the...An OAuth callback succeeds on the identity provider but the app rejects the... focuses on Identity And Access and asks the reader to isolate the key signal. OIDC callback bugs can be reverse-proxy identity bugs wearing an auth mask.SecurityAdvanced17 minProSECURITY-1271JWT verification fails after a planned key rotationAn OIDC issuer rotates signing keys and one downstream service alone begins rejecting valid tokens.SecurityAdvanced17 minProCICD-1294Parallel OIDC jobs fail sporadicallyA repository changes many workflow files at once and suddenly several OIDC-enabled jobs begin failing randomly.CI/CDAdvanced17 minProCICD-1260Runner registration succeeds but later reconnects fail with access deniedRunner registration succeeds but later reconnects fail with access denied focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. A token that can register a runner is not automatically sufficient for the runner's ste...CI/CDAdvanced17 minProCICD-1289A canary deploy health check stays redA canary deployment begins failing only after a cluster or auth dependency upgrade, even though application code and rollout logic are unchanged.CI/CDAdvanced18 minProSECURITY-1241A login loop persists after a successful OIDC callbackOne hostname or browser completes the login flow while another loops indefinitely even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1246An OIDC login loop continues after a successful callbackOne hostname or browser completes the sign-in flow and another loops forever even though the provider logs a successful callback.SecurityAdvanced18 minPro