AWS
339 incident problems in AWS environments.
먼저 읽을 가이드
추천 문제
All problems (339)
CICD-133A blue-green DNS cutover succeeds, but the CDN origin pin remains on the old backend and a percentage of traffic never movesThe authoritative name points correctly, yet cached origin metadata upstream still holds users on the retired stack.CI/CDAdvanced18 minProCICD-155A blue-green switch updates the public ALB target group, but internal service discovery still resolves to the blue stack and background jobs keep writing thereThe front door moved cleanly, yet internal callers remain on the previous environment because they use a different discovery source.CI/CDAdvanced18 minProSECURITY-180A cloud permission exists in one region while the recovery workflow executes in another scope during a failover rehearsalThe right grant is present and absent at the same time depending on where the workflow actually runs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-124A presigned URL is valid, but the CDN cache key ignores one scoping parameter and content becomes reusable outside the intended request contextObject access control is strong at origin, yet the edge cache weakens it by collapsing distinct authorization contexts.SecurityAdvanced18 minProSECURITY-160A ransomware isolation workflow snapshots the volumes correctly, but the snapshot retention tag is missing and cleanup automation deletes the evidence before triage startsContainment worked, yet incident preservation failed because the evidence path lacked lifecycle protection.SecurityAdvanced18 minProCICD-142A reusable workflow updates its permissions block, but the caller workflow still downgrades the token scope and deployment cannot assume the cloud roleThe shared workflow looks fixed, yet the effective identity is still too narrow because the caller constrains it further.CI/CDAdvanced18 minProSECURITY-104A rotated KMS key policy omits the legacy alias and historical backup decrypt operations fail during recoveryNew encrypt operations work, but restore testing fails because the recovery path still references an alias that the new policy no longer permits.SecurityAdvanced18 minProSECURITY-282A trust policy validates the new OIDC issuer while one condition key still matches the old claim path during a failover rehearsalThe provider migration is half-complete and federated access still fails on the detail that matters. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-210An authorization token is valid for one delivery host while the content path crosses into another during a failover rehearsalAuthorization is scoped correctly and the asset path does not stay where the token applies. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-110Argo CD ignoreDifferences hides drift in service account annotations and the workload loses cloud identity on syncGit and cluster appear in sync, yet the runtime identity broke because a diff-ignore rule masked the exact annotation that binds the pod to its cloud role.CI/CDAdvanced18 minProSECURITY-111CloudTrail shows the access denies, but the missing service-linked role auto-creation was never logged in the regional trail you checkedThe permissions symptom is real, yet the causal event lives in a different audit scope than the one the team has been searching.SecurityAdvanced18 minProCICD-102OIDC exchange fails only in reusable workflowsA shared workflow refactor succeeds for linting but deployment breaks because the federated identity provider expects a different token audience than the child workflow emits.CI/CDAdvanced18 minProSECURITY-216Runtime credential caches keep serving access long after central revocation completed during a failover rehearsalThe security team acts quickly and the runtime still lives in the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-079Secrets Manager rotation succeeds but the application keeps reading the old current version stageThe rotation Lambda finishes, yet the service still fails login because the stage labels and the consumer refresh path are out of sync.SecurityAdvanced18 minProSECURITY-099Security group egress hardening blocks the OCSP responder and only strict TLS clients fail validationCertificates are current, yet a subset of clients fail because the server-side environment can no longer complete revocation checks through the hardened egress policy.SecurityAdvanced18 minProCICD-113Signing verifies the tarball provenance but deployment consumes an OCI reference that was never attestedThe release report shows a verified artifact, but the runtime image came from a different reference path than the object the signing step covered.CI/CDAdvanced18 minProCICD-204A blue-green cutover moves public ingress while internal service discovery stays on the previous stack during a failover rehearsalPublic traffic shifts cleanly but batch or backend callers continue writing into the old environment. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-168A reusable workflow assumes a broader OIDC scope than the caller actually grants during a failover rehearsalThe shared logic is valid, but the effective token permissions are still narrower than the deployment step needs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-068CloudFront keeps serving stale index.html after a blue-green cutoverThe new environment is healthy, but users still load references to the old asset set because cache invalidation and origin switch ordering were not coordinated.CI/CDAdvanced19 minProCICD-079Mutable image tag makes an ECS rollback pull a newer build than the failed releaseThe rollback logic points at the previous task definition, yet the service still launches the wrong container because both revisions refer to the same mutable image tag.CI/CDAdvanced19 minPro