AWS
339 incident problems in AWS environments.
Read first
How to split IAM, TLS, and WAF failures into a security operations flowAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when authentication, authorization, certificate, WAF, and audit log signals mix together and look like a single access failure.Security3 min readHow to isolate an mTLS trust bundle mismatchAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the client certificate, server certificate, CA bundle, and sidecar reload timing differ and the handshake fails.Security3 min readHow to safely diagnose a WAF 403 false positiveAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when it looks like a permissions problem but a specific header, payload, or rule group is blocking legitimate requests.Security3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
CICD-002Recovering a container deployment where the latest tag blocks rollbackCovers how to redesign a safe rollback structure in a pipeline that has no image versioning strategy.ReviewedCI/CDAdvanced25 minProCICD-116Registry cleanup deletes the rollback tag that the audit manifest still references as the approved fallback releaseThe platform kept the primary image, but rollback fails because governance artifacts still point at a tag the registry retention job already removed.ReviewedCI/CDIntermediate16 minFreeK8S-004ImagePullBackOff caused by a missing private registry credentialA situation where the image address is correct but a missing pull secret causes failure in only certain namespaces.ReviewedKubernetesBeginner17 minFreecommand not found only under cron: the script works when run by handcommand not found only (404 and Rewrite Mismatch) is a hands-on troubleshooting drill. cron runs jobs with a minimal PATH. AWS scheduled-jobs needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 scheduled-jobs 문제를 볼 때 서비스 로그...ReviewedLinuxBeginner3 minFreeSSH Permission denied (publickey): cannot log in to a new EC2 instanceSSH Permission denied (publickey): cannot log in to a new EC2 instance is a hands-on troubleshooting drill. Know each AMI's default login user. AWS remote-access needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 remote-ac...ReviewedLinuxBeginner3 minFreeSECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFree
All problems (339)
SSH Permission denied (publickey): cannot log in to a new EC2 instanceSSH Permission denied (publickey): cannot log in to a new EC2 instance is a hands-on troubleshooting drill. Know each AMI's default login user. AWS remote-access needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 remote-ac...ReviewedLinuxBeginner3 minFreecommand not found only under cron: the script works when run by handcommand not found only (404 and Rewrite Mismatch) is a hands-on troubleshooting drill. cron runs jobs with a minimal PATH. AWS scheduled-jobs needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 scheduled-jobs 문제를 볼 때 서비스 로그...ReviewedLinuxBeginner3 minFreeSECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFreeSECURITY-056Secrets Manager rotation updates the writer credential but read replicas still use the old secretRotation completes successfully on the primary path, yet one read-side workload keeps failing because its secret retrieval or cache path was never included in the rotation design.ReviewedSecurityIntermediate21 minFreeCICD-116Registry cleanup deletes the rollback tag that the audit manifest still references as the approved fallback releaseThe platform kept the primary image, but rollback fails because governance artifacts still point at a tag the registry retention job already removed.ReviewedCI/CDIntermediate16 minFreeK8S-004ImagePullBackOff caused by a missing private registry credentialA situation where the image address is correct but a missing pull secret causes failure in only certain namespaces.ReviewedKubernetesBeginner17 minFreeAn AWS access key was pushed to a public GitHub repositoryAn AWS access key was pushed to a public GitHub repository is a hands-on troubleshooting drill. Respond to a leaked cloud credential in the right order: revoke first, investigate, then clean up history. AWS Incident Response Operations needs to be checked by narrowing scope, r...ReviewedSecurityIntermediate18 minFreeS3 AccessDenied: the IAM policy allows it but the bucket policy denies itS3 AccessDenied: the IAM policy allows it but the bucket policy denies it is a hands-on troubleshooting drill. Read the explicit-deny wording in AccessDenied and fix access through the approved path. AWS cloud-security-and-governance needs to be checked by narrowing scope, rec...ReviewedSecurityIntermediate17 minFreeSECURITY-039S3 server access log archive fails after object ownership policy changedCentral logging was working until bucket ownership controls changed, and now write attempts fail even though the destination bucket still exists and the prefix is correct.SecurityIntermediate19 minFreeCICD-070Static asset deploy uploads precompressed files without Content-Encoding metadataThe release finishes green, but browsers download broken assets because the object metadata no longer matches the precompressed files uploaded by the pipeline.CI/CDIntermediate16 minFreeSECURITY-076EKS IRSA token file becomes unreadable after a sidecar changes the shared volume ownershipThe role mapping is correct, but the application cannot assume it because the projected token path no longer matches the runtime user permissions after a sidecar update.SecurityIntermediate17 minFreeCICD-056CloudFront invalidation runs before the new asset manifest is fully publishedThe deployment pipeline clears the CDN correctly, but users still receive broken bundles because the invalidation precedes the final asset upload and manifest sync.CI/CDIntermediate18 minFreeK8S-072ExternalDNS updates the wrong hosted zoneDNS automation is healthy, but one record lands in the wrong zone because two matching filters and ownership assumptions overlap in a way the operator did not expect.KubernetesIntermediate18 minFreeSECURITY-036IMDSv1 remains reachable on a standby node after hardening rolloutPrimary instances were hardened correctly, but a rarely used standby or replacement path still exposes the older metadata service behavior.SecurityIntermediate18 minFreeK8S-103ExternalDNS creates the new record but readiness still failsDNS updates succeed outside the pod, yet the app never heals because its resolver library keeps using stale answers through the rollout.KubernetesIntermediate17 minFreeK8S-038Private registry pull failsThe imagePullSecret is correct, but the runtime on each node still rejects the registry because the certificate authority was never trusted at the container runtime layer.KubernetesIntermediate23 minFreeSECURITY-138EDR tamper protection blocks the planned agent upgrade and leaves hosts pinned to the old policy channel for weeksThe security tool protects itself successfully, but operational drift grows because the upgrade workflow was never granted the right exception path.SecurityIntermediate15 minFreeCICD-126Preview database seeding uses production-like rate limits and the readiness gate never completes before the environment TTL expiresThe preview stack is correct, but data priming takes longer than the lifecycle controller allows.CI/CDIntermediate16 minFreeCICD-002Recovering a container deployment where the latest tag blocks rollbackCovers how to redesign a safe rollback structure in a pipeline that has no image versioning strategy.ReviewedCI/CDAdvanced25 minProK8S-002Analyzing a service failure where the Pod is Running but receives no trafficA scenario for step-by-step checking of Service, Endpoint, readiness probe, and selector mismatch possibilities.KubernetesIntermediate22 minPro