AWS
339 incident problems in AWS environments.
먼저 읽을 가이드
추천 문제
All problems (339)
SECURITY-060GuardDuty member onboarding failsThe delegated admin path looks correct, but one child account never enables the detector because organizational guardrails deny the role creation needed by the service.SecurityAdvanced26 minProSECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProCICD-036CodeDeploy rollback alarm never firesThe blue-green deployment partially shifts traffic, but the rollback condition never triggers because the health alarm watches only the stable target group.CI/CDAdvanced27 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProCICD-052Reusable workflow caller changes the OIDC subject and breaks deploy role trustThe same deployment worked as a repository-local workflow, but it fails after moving into a reusable workflow because the token subject no longer matches the original trust condition.CI/CDAdvanced27 minProCICD-032OIDC subject condition mismatch denies AWS deploy role assumptionGitHub Actions reaches AWS STS, but the trust policy rejects the web identity token because the subject or audience condition no longer matches the branch and environment path.CI/CDAdvanced28 minProCICD-040Terraform apply succeeds in staging but production backend locks a different state tableThe same pipeline logic passes against one workspace, but production never converges because the remote backend, state lock table, or workspace mapping differs subtly.CI/CDAdvanced30 minProSECURITY-1564A secret rotation is complete and one workload still reads the old valueOne workload keeps reading the old secret after a successful rotation.SecurityIntermediate8 minProSECURITY-1594An External Secrets fix lands and one app still gets the old payloadOne app still gets the old payload after an External Secrets fix.SecurityIntermediate8 minProSECURITY-1584An External Secrets merge order is fixed and one app still sees the old payloadOne app still sees the old secret payload after merge-order fixes.SecurityIntermediate8 minProSECURITY-1574An External Secrets merge rule is corrected and one workload still builds the old payloadOne workload still assembles the old secret payload after merge-rule cleanup.SecurityIntermediate8 minProSECURITY-1554A secret rotation completes and one workload still uses the retired valueOne workload keeps using a retired secret after rotation across stores.SecurityIntermediate9 minProK8S-1599An IRSA mapping is fixed and one pod still fails STSOne pod still fails STS after an IRSA mapping fix.KubernetesAdvanced9 minProK8S-1609An IRSA mapping is fixed and one pod still fails STSOne pod still fails STS after an IRSA mapping fix.KubernetesAdvanced9 minProK8S-1579An IRSA issuer changes and one DaemonSet still loses credentialsOne DaemonSet loses credentials after IRSA issuer migration.KubernetesAdvanced10 minProK8S-1589An IRSA service account is corrected and one node still fails STSOne node still fails STS after IRSA service account corrections.KubernetesAdvanced10 minProK8S-1569An IRSA token file rotates and one DaemonSet still loses AWS accessA DaemonSet loses AWS access only on nodes where an init copy path still runs.KubernetesAdvanced10 minProCICD-1501A GitHub OIDC deploy succeeds in test and fails in prodOnly production deploys fail after an AWS federation alias cleanup while test continues to work.CI/CDAdvanced11 minProCICD-1591A GitHub OIDC deployment still fails in one accountDeployments fail only in one account after consolidating environment aliases.CI/CDAdvanced11 minProK8S-1559An IRSA migration completes and one DaemonSet still loses cloud accessA DaemonSet loses AWS access only on older nodes after IRSA migration.KubernetesAdvanced11 minPro