Vendor339 problems· 9 reviewed

AWS

339 incident problems in AWS environments.

All problems (339)

K8S-1193Node stays NotReadyA node image refresh followed public upgrade guidance. New nodes join, but one networking daemonset fails to initialize and the nodes never reach a stable Ready state.KubernetesAdvanced26 minProSECURITY-1383An OpenSearch snapshot repository remains registered and backups failAn OpenSearch snapshot repository remains registered and backups fail focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Repository auth failures can persist after IAM fixes when the node keeps pre...SecurityAdvanced14 minProSECURITY-1380A Terraform-managed OIDC trust update is applied and one workspace still...A Terraform-managed OIDC trust update is applied and one workspace still... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote runners can retain assumptions about trust material even...SecurityAdvanced15 minProSECURITY-1350An AWS OIDC trust policy matches the cluster issuer and one controller still...An AWS OIDC trust policy matches the cluster issuer and one controller... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared IaC can still emit stale identity data if one workspace cached old metadata.SecurityAdvanced15 minProSECURITY-1360An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity maintenance task succeeds broadly and later one controller in one environment alone continues failing IRSA or web-identity auth.SecurityAdvanced15 minProSECURITY-1370An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity refresh completes and later only one environment continues to fail IRSA or web-identity auth for a controller.SecurityAdvanced15 minProSECURITY-1315An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails...An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. STS web identity failures often come from audience mismatch even when issuer and subje...SecurityAdvanced15 minProSECURITY-1340An AWSKRUG-style EKS access pattern uses OIDC and still breaks one controllerAn AWSKRUG-style EKS access pattern uses OIDC and still breaks one controller focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared Terraform code can still render different identity assumptions if...SecurityAdvanced15 minProSECURITY-1329An IdP secret rotation succeeds and one workload still failsAn OIDC signing key is rotated and only one service path keeps rejecting freshly minted tokens for a while afterward.SecurityAdvanced15 minProSECURITY-1321An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy-change)An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. OIDC loops often come from callback identity drift rather than from bad user cr...SecurityAdvanced16 minProSECURITY-098CloudFront signed cookie scope excludes the websocket upgrade host and only the browser terminal loses authStatic pages load normally, but the interactive browser tool fails because the signed cookie domain or path does not cover the upgraded endpoint host.SecurityAdvanced16 minProCICD-097S3 static site deploy uploads the new assets but old signed URLs stay embedded in the manifestThe files exist in the bucket, yet clients keep failing because the generated manifest still references stale signed asset URLs from the previous build.CI/CDAdvanced16 minProSECURITY-149A CloudFront signed URL policy covers the main asset host, but a redirect to the image host drops the signature scope and private media leaks a 403 loopThe control is present, yet the delivery path crosses hostnames that do not share the same authorization contract.SecurityAdvanced17 minProSECURITY-381A snapshot policy copies encrypted data correctlyA snapshot policy copies encrypted data correctly focuses on cloud-security-and-governance and asks the reader to isolate Permission Denied in AWS. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다.SecurityAdvanced17 minProSECURITY-135An AWS IAM permissions boundary copied from a template blocks kms:Decrypt in the break-glass role and recovery automation fails during an incidentThe emergency role exists, yet one inherited boundary quietly removes the exact permission the runbook requires.SecurityAdvanced17 minProSECURITY-154An IAM role trust policy is updated for the new OIDC issuer, but the condition key still references the old provider path and federated deploys failThe identity provider appears swapped successfully, yet the claim-matching logic is still anchored to the previous issuer structure.SecurityAdvanced17 minProSECURITY-150An incident containment playbook revokes the VM role, but the host's metadata proxy cache keeps serving old credentials for several minutesThe control plane moved fast, yet runtime revocation lag created a dangerous grace period.SecurityAdvanced17 minProSECURITY-096AWS IAM role session policy shrinks access below the base role and only one Lambda path fails decryptThe role seems correct, yet decryption still fails because the assumed session adds a restrictive inline policy at invocation time.SecurityAdvanced17 minProSECURITY-318A backup or snapshot path is readable while cross-account or cross-region recovery still lacks the exact decrypt or restore permission it needs during a failover rehearsalThe artifact exists and the recovery scope where it matters is still unauthorized. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-234A backup snapshot restores while the copy role still lacks the right to re-encrypt in the target account during a failover rehearsalDisaster recovery looks viable until the protected copy has to become live elsewhere. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minPro