Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

SECURITY-1349An Ubuntu bastion patch window succeeds and SSH trust breaksRoutine patching is completed and later automated SSH clients reject the bastion despite no intended access control changes.SecurityAdvanced14 minProSECURITY-1386A Cilium deny policy looks correct and one egress path remains openA Cilium deny policy looks correct and one egress path remains open focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Policy surprises often come from broader selectors attached through helper layers lik...SecurityAdvanced15 minProSECURITY-1357A Cilium FQDN policy allows a hostname and still blocks trafficA Cilium FQDN policy allows a hostname and still blocks traffic focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy is only as correct as the DNS query that actually leaves the worklo...SecurityAdvanced15 minProSECURITY-1377A Cilium FQDN policy allows the expected hostname and traffic still failsA Cilium FQDN policy allows the expected hostname and traffic still fails focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. FQDN policies operate on real DNS observations, not on the hostname stri...SecurityAdvanced15 minProSECURITY-1336A Cilium network policy blocks unexpected egress only in one security...A Cilium network policy blocks unexpected egress only in one security... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy decisions can stale independently from pod label...SecurityAdvanced15 minProSECURITY-1347A Cilium policy allows one FQDN and still breaks egressA secure namespace uses a service mesh sidecar and later one external dependency fails only under FQDN-based egress controls.SecurityAdvanced15 minProSECURITY-1317A GitHub Actions secret scan starts failing only forked pull requestsA GitHub Actions secret scan starts failing only forked pull requests focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Workflow security failures are often ordering bugs, not missing secret definitions.SecurityAdvanced15 minProSECURITY-1312A Grafana datasource secret rotates successfully and alert rules still failA team rotates monitoring credentials and later finds dashboards healthy while rule evaluations continue to fail with auth errors.SecurityAdvanced15 minProSECURITY-1341A Grafana SSO login succeeds and folder permissions look emptyA company refreshes its IdP schema and later Grafana users log in successfully but lose access to folders they previously owned.SecurityAdvanced15 minProSECURITY-1371A Grafana SSO login succeeds and users land as ViewersAn IdP claim cleanup lands and later every Grafana login works but the expected team roles stop being assigned.SecurityAdvanced15 minProSECURITY-1380A Terraform-managed OIDC trust update is applied and one workspace still...A Terraform-managed OIDC trust update is applied and one workspace still... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote runners can retain assumptions about trust material even...SecurityAdvanced15 minProNETWORK-1339A Tunnel and WARP path look healthy and one internal app still failsA Tunnel and WARP path look healthy and one internal app still fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers can be lost after the edge if internal proxy routing is not exp...NetworkAdvanced15 minProSECURITY-1330A zero trust policy allows the service token and the backend still returns 403A zero trust policy allows the service token and the backend still returns 403 focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Zero Trust success at the edge does not guarantee the origin app...SecurityAdvanced15 minProSECURITY-1327An admission policy rollout breaks only one namespaceAn admission policy rollout breaks only one namespace focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Distributed trust injection systems rarely converge everywhere at the same instant.SecurityAdvanced15 minProSECURITY-1350An AWS OIDC trust policy matches the cluster issuer and one controller still...An AWS OIDC trust policy matches the cluster issuer and one controller... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared IaC can still emit stale identity data if one workspace cached old metadata.SecurityAdvanced15 minProSECURITY-1360An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity maintenance task succeeds broadly and later one controller in one environment alone continues failing IRSA or web-identity auth.SecurityAdvanced15 minProSECURITY-1370An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity refresh completes and later only one environment continues to fail IRSA or web-identity auth for a controller.SecurityAdvanced15 minProSECURITY-1315An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails...An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. STS web identity failures often come from audience mismatch even when issuer and subje...SecurityAdvanced15 minProSECURITY-1340An AWSKRUG-style EKS access pattern uses OIDC and still breaks one controllerAn AWSKRUG-style EKS access pattern uses OIDC and still breaks one controller focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared Terraform code can still render different identity assumptions if...SecurityAdvanced15 minProSECURITY-1353An Elastic API key rotates successfully and one Beats sidecar keeps 401ingA credential rotation is completed and later one logging path continues to fail even though the secret update is visible in the cluster.SecurityAdvanced15 minPro