AWS
339 incident problems in AWS environments.
먼저 읽을 가이드
추천 문제
All problems (339)
CICD-112Cache warming publishes a stale base image to the internal mirror and every subsequent build inherits the vulnerable layerThe dependency warmup stage succeeds, yet later builds are compromised by a mirrored base image that bypassed the freshness policy.CI/CDAdvanced18 minProCICD-100Canary traffic shifts correctly but a legacy cron node keeps running the old job image out of bandThe service path looks promoted, but background jobs still operate on the old release because the scheduler pool was not included in the rollout boundary.CI/CDAdvanced18 minProK8S-1232CoreDNS pods are healthy but one namespace still fails resolutionA hardened namespace loses name resolution after a node-local DNS optimization or add-on change, while the rest of the cluster remains healthy.KubernetesAdvanced18 minProK8S-1261CoreDNS stays Pending on a private EKS clusterK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced18 minProK8S-1266CoreDNS stays Pending on a private EKS clusterA cluster expansion seems successful until CoreDNS and other essential pods remain Pending despite healthy node registration.KubernetesAdvanced18 minProCICD-122Cosign verification succeeds on the public digest, but deployment pulls from a private mirror that serves a different manifestSupply chain checks pass during build, yet the runtime artifact is not the one that was signed because the mirror rewrites the digest target.CI/CDAdvanced18 minProK8S-1264Pods resolve names intermittentlyK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced18 minProK8S-1269Pods resolve names intermittentlyCluster DNS appears green in dashboards, but application pods on certain nodes still time out when resolving service or external names.KubernetesAdvanced18 minProK8S-1275Pods schedule normally but lose persistent IP assignmentPods begin failing to start with networking errors on nodes that still appear lightly loaded from a compute perspective.KubernetesAdvanced18 minProCICD-1228Self-hosted runner reaches the artifact store but uploads still failA self-hosted runner can download code and dependencies but starts failing only on artifact upload calls.CI/CDAdvanced18 minProLINUX-1212Socket directory vanishes after rebootA daemon expects its socket directory to exist at boot, but a cleanup rule removes it before startup recreates it.LinuxAdvanced18 minProK8S-125The kubelet credential provider cache expires before the node refreshes its cloud identity, and private registry pulls fail only after several hoursNew pods work immediately after boot, but later image pulls break because two credential lifecycles drift apart.KubernetesAdvanced18 minProCICD-127The release pipeline signs the SBOM for the original image digest, but a last-minute rebuild produces a new digest that goes out unsignedEvery compliance report points at a valid attestation, just not for the image that actually ships.CI/CDAdvanced18 minProCICD-228A deploy pipeline signs the container image but not the values bundle that actually changes runtime behavior during a failover rehearsalSupply-chain checks pass for the binary artifact while the configuration artifact remains unsigned and mutable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-1251A hotfix workflow builds the right image but the production deploy still reuses the previous digestA hotfix release is approved and deployed quickly, but post-deploy checks reveal the cluster still runs the previous image build.CI/CDAdvanced19 minProCICD-476A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProCICD-478A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProCICD-186A reviewed Terraform plan applies under a different provider context during a failover rehearsalThe diff appears safe, yet the runtime alias or account context points at different infrastructure during apply. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProK8S-1246A Service has endpoints and pods are Ready but requests still failA newly introduced node class hosts healthy pods, but clients reaching those pods still time out while the same Service works from older nodes.KubernetesAdvanced19 minProK8S-1251A Service has healthy pods and endpoints but requests still failA new node group joins an EKS cluster and only pods placed there start failing for Service traffic despite being fully Ready.KubernetesAdvanced19 minPro