Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

CICD-1576A GitLab runner token rotates and one autoscaled runner still registers with the old tokenOne autoscaled runner group keeps failing registration after token rotation.CI/CDIntermediate9 minProCICD-1504A reusable workflow respects required reviewers and one environment still blocksProduction approvals fail only after a GitHub team rename while the new slug is visible in settings.CI/CDIntermediate9 minProLINUX-1474A sudo rule exists and automation still loses accessAutomation loses sudo only after a package update introduces a new deny-style drop-in file.LinuxIntermediate9 minProLINUX-1464A sudoers drop-in works for admins and fails in automationAutomation loses sudo access after an OS refresh while admins still think the rule exists.LinuxIntermediate9 minProLINUX-1473A chrony source looks healthy and Kerberos still failsKerberos login failures appear after one NTP pool moves to a provider with a different leap smear strategy.LinuxIntermediate10 minProLINUX-1460A newly granted group still does not unlock accessA user gains access in the directory and one host continues denying it for a while.LinuxIntermediate10 minProLINUX-1395A sudoers rule looks correct and a command still prompts for a passwordAn automation wrapper is introduced and later a previously passwordless command begins prompting unexpectedly.LinuxIntermediate10 minProK8S-1478An Istio AuthorizationPolicy allows JWT traffic and still blocks browser clientsBrowsers fail against a service while direct token-bearing requests from curl still succeed.KubernetesIntermediate10 minProCICD-1481A reusable workflow deploys fine in staging and fails in prodA shared release workflow starts failing only in production repos after environment approvals were tightened.CI/CDIntermediate11 minProK8S-1388A cert-manager DNS01 challenge keeps creating TXT records in the wrong zoneA cert-manager DNS01 challenge keeps creating TXT records in the wrong zone focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. DNS01 failures often come from conflicting zone normal...KubernetesIntermediate12 minProLINUX-1380A deployment sync finishes cleanly and one application loses ACLsA deployment sync finishes cleanly and one application loses ACLs focuses on Deployment Governance and asks the reader to isolate the key signal in Linux. Rsync regressions can preserve bytes perfectly while destroying the metadata your app ac...LinuxIntermediate12 minProCICD-1393A Docker build passes locally and fails in CIA Docker build passes locally and fails in CI focuses on Identity And Access and asks the reader to isolate the key signal in docker. Runner image updates can change BuildKit mount semantics even when the Dockerfile stays untouched.CI/CDIntermediate12 minProCICD-1367A GitHub Actions reusable workflow works on push and fails on...A GitHub Actions reusable workflow works on push and fails on... focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Reusable workflow refactors often break secret flow at the boundary, not inside...CI/CDIntermediate12 minProCICD-1369A package publish to an organization registry works from one repo and fails...A package publish to an organization registry works from one repo and fails... focuses on Artifact Promotion and asks the reader to isolate the key signal in GitHub. A shared workflow can still produce different auth behavior because t...CI/CDIntermediate12 minProCICD-1379A package publish to an organization registry works from one repo and fails...A package publish to an organization registry works from one repo and fails... focuses on Artifact Promotion and asks the reader to isolate the key signal in GitHub. Shared workflow logic does not mean shared effective auth scope when th...CI/CDIntermediate12 minProCICD-1349A package publish works from one GitHub environment and fails in anotherA release workflow is duplicated across environments and later one environment alone fails authentication despite matching secret names in the YAML.CI/CDIntermediate12 minProLINUX-1357A package reinstall restores the binary and SELinux still blocks executionA recovery action reinstalls a package and later the service still fails even though the required binary now exists again.LinuxIntermediate12 minProCICD-1359A private package publish succeeds once and later 403sA private package publish succeeds once and later 403s focuses on Artifact Promotion and asks the reader to isolate the key signal in GitHub. Inherited tokens can cross workflow boundaries while losing the authority implied by the o...CI/CDIntermediate12 minProCICD-1377A reusable GitHub workflow works on push and fails on pull_request_targetA shared workflow is refactored and later one trigger context loses authentication even though the secrets still exist in the repository.CI/CDIntermediate12 minProLINUX-1355A sudo rule works locally and fails through a bastionA host update passes basic tests and later operators notice sudo MFA behaves differently only when entering through a jump host.LinuxIntermediate12 minPro