Runtime Configuration
147 incident problems about Runtime Configuration. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (147)
K8S-1253A StatefulSet volume reattaches after reschedule but write access still failsAfter a node failure, a stateful workload restarts on another node and immediately fails on file permissions despite the volume attaching cleanly.KubernetesAdvanced19 minProK8S-1248A StatefulSet volume reattaches successfully but startup still failsAfter a node event, a stateful workload comes back on another node and immediately fails with permission errors against an attached data volume.KubernetesAdvanced19 minProNETWORK-1388A hardware load balancer health check passes and real traffic failsA hardware load balancer health check passes and real traffic fails focuses on runtime-configuration and asks the reader to isolate the key signal in NGINX. A green health check can be meaningless if it asks a simpler protocol question th...NetworkIntermediate10 minProNETWORK-1386A Cloudflare page rule or transform looks correct and one admin path still bypasses authA transform rules rollout simplifies URLs and later only one protected path begins bypassing the expected edge auth behavior.NetworkIntermediate11 minProK8S-1386A Loki or OpenSearch logging pipeline works and one tenant disappearsA log-cardinality cleanup lands and later one team loses log visibility while ingestion overall still looks healthy.KubernetesIntermediate11 minProSECURITY-1395A Prometheus or Alertmanager basic-auth secret rotates and one instance still...A Prometheus or Alertmanager basic-auth secret rotates and one instance... focuses on Identity And Access and asks the reader to isolate the key signal in grafana. Rotation bugs can hide in file rendering and comparison behavio...SecurityIntermediate11 minProSECURITY-1400A Vault dynamic DB credential works and one app still rejects itDynamic credentials are rolled out and one application alone starts rejecting them despite the DB and Vault role being correct.SecurityIntermediate11 minProSECURITY-1390A Vault-issued short-lived database credential works in staging and fails in...A Vault-issued short-lived database credential works in staging and fails... focuses on Identity And Access and asks the reader to isolate the key signal in hashicorp. Dynamic secret adoption can fail on local validation code that was wri...SecurityIntermediate11 minProNETWORK-1396An edge auth rule should block a path and one localized URL stays openA multilingual or encoded URL path reaches an origin route that should have been blocked by edge auth.NetworkIntermediate11 minProNETWORK-1400An ingest tier cutover looks complete and one proxy pool keeps using the old...An ingest tier cutover looks complete and one proxy pool keeps using the... focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Negative caching can distort cutovers even when positive record TTLs are...NetworkIntermediate11 minProNETWORK-1390An OpenSearch ingest node remains reachable and query latency spikesAn OpenSearch ingest node remains reachable and query latency spikes focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Infrastructure cutovers often fail at intermediate cache layers that keep targeti...NetworkIntermediate11 minProNETWORK-1392A BGP route reflector session is healthy and one site's routes lose preferenceA BGP route reflector session is healthy and one site's routes lose preference focuses on routing-protocols and asks the reader to isolate the key signal in Cisco. Route preference bugs often come from attribute mutation upst...NetworkIntermediate12 minProNETWORK-1382A BGP session is established and routes never winA BGP session is established and routes never win focuses on routing-protocols and asks the reader to isolate the key signal in Cisco. Route policy chains can break when one stage renames communities another stage still depends...NetworkIntermediate12 minProK8S-1378A cert-manager HTTP01 challenge failsA global ingress annotation cleanup lands and later only HTTP01 certificate renewals begin to fail.KubernetesIntermediate12 minProK8S-1368A cert-manager HTTP01 challenge fails (http01-solver-ingress-inherited-global-https-redirect)A cert-manager HTTP01 challenge fails (http01-solver-ingress-inherited-global... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary challenge routes can inherit cluster-wide ingress behavio...KubernetesIntermediate12 minProNETWORK-1375A log ingest NGINX location works for normal requests and large client posts...A log ingest NGINX location works for normal requests and large client... focuses on runtime-configuration and asks the reader to isolate the key signal in NGINX. Breaking a server block into includes can silently shrink limits on paths that d...NetworkIntermediate12 minProSECURITY-1378A Prometheus alert reaches Alertmanager and never pages the right teamAn alerting pipeline cleanup merges relabel rules and later some incidents stop paging the owning team even though alerts still fire.SecurityIntermediate12 minProNETWORK-1380A WAF bypass rule appears correct and never matchesA CDN logging format is updated and later allowlists, bypass rules, or enrichment behave as though every request came from the wrong IP.NetworkIntermediate12 minProK8S-1348A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to-https-by-global-annotation)A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary ingress objects can inherit global behaviors that break...KubernetesIntermediate13 minProLINUX-1396A journald remote forwarder remains active and drops burstsA journald remote forwarder remains active and drops bursts focuses on incident-response and asks the reader to isolate the key signal in Linux. Package splits can move config authority between units while leaving the main service name...LinuxAdvanced13 minPro