Kubernetes Ingress and Traffic
114 incident problems about Kubernetes Ingress and Traffic. Start with the reviewed ones.
Read first
When the ConfigMap changed but the Pod keeps using the old valuesAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when values don't refresh after a ConfigMap update because of envFrom, subPath, volume projection, or rollout trigger differences.Kubernetes3 min readWhen CoreDNS is Running but only DNS lookups failAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the CoreDNS Pod looks healthy but failures occur in the kube-dns path, upstream, node-local-dns, or policy.Kubernetes3 min readWhat to check first when CrashLoopBackOff appearsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a Pod restarts repeatedly and the real cause is left in the previous logs and events.Kubernetes3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
K8S-030Ingress class mismatch sends traffic to the wrong controllerIngress class mismatch sends traffic to the wrong controller is a hands-on troubleshooting drill. Routing rules are valid, but the ingress object is reconciled by a different controller than the team expected. Kubernetes Ingress and Traffic needs to be checked by narrowing sco...ReviewedKubernetesIntermediate19 minFreeK8S-034NetworkPolicy allows the app service but blocks CoreDNS resolutionThe namespace appears to have the right egress rules for the application path, yet pods still fail because DNS traffic to kube-dns was never permitted.ReviewedKubernetesIntermediate18 minFreeIngress 404 Not Found: only the newly added www host returns 404Ingress 404 Not Found: only the newly added www host returns 404 is a hands-on troubleshooting drill. Check that the request's host name matches an Ingress rule. NGINX Kubernetes Ingress and Traffic needs to be checked by narrowing scope, recent change, and the current live si...ReviewedKubernetesBeginner3 minFreeK8S-002Analyzing a service failure where the Pod is Running but receives no trafficA scenario for step-by-step checking of Service, Endpoint, readiness probe, and selector mismatch possibilities.KubernetesIntermediate22 minProK8S-009Only certain APIs return 404 due to an Ingress path-rewrite rule mismatchCovers a path-rewrite problem where health checks pass but only real user requests fail.KubernetesIntermediate24 minProK8S-017Readiness time spikes sharply after a service-mesh sidecar is attachedA situation where the proxy initialization, rather than the application itself, becomes the bottleneck and lengthens startup.KubernetesIntermediate24 minPro
All problems (114)
Ingress 404 Not Found: only the newly added www host returns 404Ingress 404 Not Found: only the newly added www host returns 404 is a hands-on troubleshooting drill. Check that the request's host name matches an Ingress rule. NGINX Kubernetes Ingress and Traffic needs to be checked by narrowing scope, recent change, and the current live si...ReviewedKubernetesBeginner3 minFreeK8S-030Ingress class mismatch sends traffic to the wrong controllerIngress class mismatch sends traffic to the wrong controller is a hands-on troubleshooting drill. Routing rules are valid, but the ingress object is reconciled by a different controller than the team expected. Kubernetes Ingress and Traffic needs to be checked by narrowing sco...ReviewedKubernetesIntermediate19 minFreeK8S-034NetworkPolicy allows the app service but blocks CoreDNS resolutionThe namespace appears to have the right egress rules for the application path, yet pods still fail because DNS traffic to kube-dns was never permitted.ReviewedKubernetesIntermediate18 minFreeK8S-072ExternalDNS updates the wrong hosted zoneDNS automation is healthy, but one record lands in the wrong zone because two matching filters and ownership assumptions overlap in a way the operator did not expect.KubernetesIntermediate18 minFreeK8S-098Gateway route hostname matches but TLS mode passthrough prevents the expected path rewriteThe route is attached, yet behavior differs because the chosen TLS handling mode bypasses the HTTP features the operator expected to apply.KubernetesIntermediate16 minFreeK8S-089Probe succeeds on localhost but the service mesh policy blocks real pod-to-pod callsThe container reports healthy, yet callers still fail because the readiness command bypasses the same network policy and sidecar path used in production traffic.KubernetesIntermediate16 minFreeK8S-082Ingress path works externally but internal probes failUser traffic succeeds through one route, yet health probes and some internal paths fail because the controller still speaks the wrong protocol to the service.KubernetesIntermediate17 minFreeK8S-075Service mesh sidecar intercept excludes the health port on one Deployment onlyThe mesh is healthy in the cluster overall, but one workload fails readiness because its sidecar capture rules skip the port the probe is supposed to reach.KubernetesIntermediate17 minFreeK8S-085Gateway API route is accepted but the ReferenceGrant does not cover the namespace of the backend serviceThe route object itself looks valid, yet traffic never forwards because the cross-namespace backend reference is not explicitly granted.KubernetesIntermediate18 minFreeK8S-055Gateway API route is Accepted but never serves trafficThe route object looks healthy in status output, but the parent listener does not actually match the requested hostname and path combination.KubernetesIntermediate22 minFreeK8S-077CoreDNS negative caching masks a fixed service record long after the backend issue is goneThe service entry is corrected, but clients still fail because the resolver path is serving a negative cache response longer than operators expect.KubernetesIntermediate16 minFreeK8S-078NodeLocal DNSCache keeps using the old upstream after a ConfigMap updateCluster DNS works partially, but one set of nodes still forwards to the retired resolver because the node-local cache path never reloaded the new upstream config.KubernetesIntermediate17 minFreeK8S-093Service selector is correct but EndpointSlice labels point the controller at the wrong shardThe Service definition looks fine, yet traffic still misses the intended backend because a generated EndpointSlice path is bound to an outdated label set.KubernetesIntermediate17 minFreeK8S-067StatefulSet ordinal DNS looks healthy but traffic is emptyPod names resolve as expected, yet clients get no working backend because the Service that should back ordinal DNS no longer selects the current pods.KubernetesIntermediate17 minFreeK8S-057CoreDNS stub domain forwards the internal zone to the wrong upstreamMost cluster DNS works, but one internal zone fails because the custom forwarding block points at an outdated resolver target.KubernetesIntermediate18 minFreeK8S-064NetworkPolicy allows UDP 53 but blocks DNS TCP fallback for large responsesMost lookups appear healthy, yet one domain consistently fails because the policy only permits the UDP path and the resolver falls back to TCP for bigger answers.KubernetesIntermediate18 minFreeK8S-1723An Ingress host is accepted and one route still failsOne route still fails after an Ingress host update.KubernetesBeginner6 minFreeK8S-1743An Ingress host is accepted and one route still failsOne route still fails after an Ingress update.KubernetesBeginner6 minFreeK8S-1763An Ingress host is accepted and one route still failsOne route still fails after an Ingress update.KubernetesBeginner6 minFreeK8S-1733An Ingress host is correct and one route still failsOne route still fails after an Ingress update.KubernetesBeginner6 minFree