Kubernetes Config and Rollouts
204 incident problems about Kubernetes Config and Rollouts. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (204)
K8S-014An overly aggressive liveness probe keeps restarting even healthy PodsAn overly aggressive liveness probe keeps restarting even healthy Pods is a hands-on troubleshooting drill. A situation where the liveness criteria become too tight during periods of high application load. Kubernetes Config and Rollouts needs to be checked by narrowing scope,...KubernetesIntermediate19 minProK8S-020After a secret rotation, only certain Pods keep using the old credentialA situation where the secret was rotated but, with no rollout trigger, only some workloads still reference the old value.KubernetesIntermediate23 minProK8S-003Interpreting backoffLimit in a batch workload where the Job never finishesAn advanced problem that connects the batch failure retry policy with the container exit code to find the root cause.KubernetesAdvanced27 minProK8S-017Readiness time spikes sharply after a service-mesh sidecar is attachedA situation where the proxy initialization, rather than the application itself, becomes the bottleneck and lengthens startup.KubernetesIntermediate24 minProCICD-094Argo CD sync succeeds but a namespace label policy silently strips the network exemption labelThe app is deployed cleanly, yet the workload breaks because a cluster policy rewrites the namespace labels the app depends on for networking.CI/CDAdvanced18 minProCICD-099Image signing succeeds in CI but the admission policy rejects the signature issuer after root rotationThe build publishes a signed image, yet cluster admission fails because the verifier still trusts the old signing root only.CI/CDAdvanced21 minProK8S-066Projected service account token audience mismatch breaks external Vault authThe pod has a valid token, but external auth still fails because the verifier expects a different audience than the projected token request generated.KubernetesAdvanced21 minProK8S-081Readiness passes but Envoy sidecar cannot reach the control plane after a trust bundle splitThe app container is healthy, yet traffic still fails because the sidecar lost trust in the mesh control plane after the certificate bundle changed unevenly.KubernetesAdvanced21 minProK8S-068FailurePolicy Ignore lets pods start without the required security sidecarThe cluster stays available during webhook trouble, but production traffic later fails because workloads launched without the sidecar contract the platform assumes.KubernetesAdvanced22 minProK8S-028Node drain hangs on long-lived connection podsMaintenance starts correctly, but eviction never finishes because connection draining and termination hooks take too long.KubernetesIntermediate22 minProK8S-087OIDC provider issuer URL rotates and every projected token verifier in the cluster rejects new tokensToken projection still works, but consumers fail because the issuer trust path and JWKS discovery URL changed underneath long-lived verifiers.KubernetesAdvanced22 minProCICD-071Argo CD prune deletes a shared secretThe sync itself succeeds, but a cleanup step removes a namespace-scoped secret that another workload still depends on because ownership boundaries were not encoded safely.CI/CDAdvanced23 minProK8S-026PriorityClass keeps critical jobs alive but starves batch queueThe urgent workload policy solves one problem and silently creates another by preventing lower-priority queues from ever catching up.KubernetesAdvanced27 minProK8S-096PodSecurity admission blocks the debug container flow even though the base workload still runsThe app continues serving traffic, but emergency debugging fails because the current security profile denies the ephemeral container path.KubernetesAdvanced17 minProK8S-080Ingress controller leader election lease stayed in the old namespace after a migrationThe new controller deploys cleanly, yet only one replica ever reconciles because the election objects still point at the namespace pattern from the previous release.KubernetesAdvanced18 minProK8S-091Mutating webhook times out only on large Pod specsSmall workloads admit fine, but larger ones fail because the webhook path includes a proxy with a body-size setting lower than the API server request.KubernetesAdvanced18 minProK8S-073Ephemeral-storage eviction startsThe nodes still have CPU and memory, but pods get evicted because local ephemeral storage fills when retry-heavy request logging lands in emptyDir volumes.KubernetesAdvanced19 minProK8S-092Projected CA bundle on one namespace lags and only that team's jobs fail outbound TLS validationCluster TLS trust is mostly healthy, but one namespace still mounts an older CA bundle and its jobs reject the new upstream certificate path.KubernetesAdvanced19 minProCICD-088Argo CD health check stays degradedThe resource is actually working, but the GitOps controller still blocks promotion because its custom health logic only understands the older API shape.CI/CDAdvanced20 minProK8S-084DaemonSet update stallsThe update strategy looks conservative, but rollout progress stops because the current unavailable state of the tainted group already exceeds the allowed update budget.KubernetesAdvanced20 minPro