Topic163 problems

Reverse Proxy Security

163 incident problems about Reverse Proxy Security. Start with the reviewed ones.

All problems (163)

CICD-1344A Docker registry behind NGINX accepts pushes and later large uploads hangA reverse proxy config is reorganized for clarity and later only larger image pushes start hanging or failing halfway through upload.CI/CDAdvanced15 minProNETWORK-1334A Palo Alto decryption bypass fixes browsers and one API client still failsA Palo Alto decryption bypass fixes browsers and one API client still fails focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. TLS validation often depends on auxiliary hosts beyond the visible appl...NetworkAdvanced15 minProCICD-1374A private registry behind NGINX logs in correctly and larger pushes hangA private registry behind NGINX logs in correctly and larger pushes hang focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Shared security includes can quietly undo streaming behavior required by...CI/CDAdvanced15 minProCICD-1354A registry behind NGINX accepts auth and fails large pushesA registry behind NGINX accepts auth and fails large pushes focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Security includes can accidentally revert performance-critical streaming directives on special...CI/CDAdvanced15 minProSECURITY-1292A SameSite fix solves desktop login and still breaks mobile webview SSOAn auth hardening change appears successful until mobile app login starts looping while desktop login remains normal.SecurityIntermediate15 minProSECURITY-1272A SameSite hardening change breaks SSO only on one browser flowA cookie hardening rollout leaves some browsers or embedded login flows broken while ordinary browser login still succeeds.SecurityIntermediate15 minProSECURITY-1300A signed download URL validates in staging but fails in productionSigned file links work in staging and fail only behind the production proxy or CDN path.SecurityIntermediate15 minProSECURITY-1288A signed URL looks valid but file downloads still failDownloads begin failing only after a reverse-proxy or CDN change, even though the signed URL generator code did not change.SecurityIntermediate15 minProNETWORK-1325A split horizon DNS setup works on LAN and fails at the edgeA hybrid network uses different answers for internal and public clients and later some edge users resolve to the wrong target after an upstream cache change.NetworkAdvanced15 minProNETWORK-1314A Traefik edge route works on HTTP and fails on WebSocketsA reverse proxy hardening change lands and only long-lived upgraded connections begin failing while standard traffic remains healthy.NetworkAdvanced15 minProNETWORK-1326A Traefik passthrough route works with one certificate and later breaksA Traefik passthrough route works with one certificate and later breaks focuses on protocol-interoperability and asks the reader to isolate the key signal in traefik. Passthrough routers are coupled to hostname identity even when they do...NetworkAdvanced15 minProSECURITY-1278An app trusts X-Forwarded-Proto from one proxy hop and starts misclassifying secure requestsA reverse proxy or CDN is inserted ahead of an existing app and secure redirect or cookie behavior becomes inconsistent.SecurityIntermediate15 minProNETWORK-1341An NGINX ingress passes health checks and long uploads failAn NGINX ingress passes health checks and long uploads fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Health checks rarely exercise the timeout and buffering profile of the largest request path.NetworkAdvanced15 minProNETWORK-1331An NGINX reverse proxy keeps one upstream marked healthyAn NGINX reverse proxy keeps one upstream marked healthy focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. A healthy keepalive pool can hide failures that only happen on new TLS handshakes.NetworkAdvanced15 minProK8S-1339An OpenSearch cluster behind Kubernetes ingress looks healthy and still drops...An OpenSearch cluster behind Kubernetes ingress looks healthy and still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Session loops can come from two valid cookies that disagree...KubernetesAdvanced15 minProNETWORK-1336An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk-ingest)An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Edge proxies can be the bottleneck when UI and ingest paths share one...NetworkAdvanced15 minProNETWORK-1305Full strict mode returns 526 only on an alternate hostnameA new vanity or fallback hostname is added and only that path starts returning 526 through Cloudflare.NetworkAdvanced15 minProNETWORK-1371One member in a proxied origin pool works from direct tests and Cloudflare...One member in a proxied origin pool works from direct tests and Cloudflare... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Cloudflare. TLS issues behind a pool can hide on one member when direct test...NetworkAdvanced15 minProNETWORK-1304A Cloudflare Tunnel reports healthy and WebSocket traffic still failsCloudflare Tunnel works for ordinary HTTP routes and later one real-time feature fails only through a new upstream proxy hop.NetworkAdvanced16 minProNETWORK-1311A Cloudflare Tunnel stays healthy and origin mTLS still failsA private service is published through Tunnel and later only the mTLS-protected route fails after an origin proxy change.NetworkAdvanced16 minPro