Vendor339 problems· 9 reviewed

AWS

339 incident problems in AWS environments.

All problems (339)

CICD-1491A GitHub Actions OIDC deploy works in one region and fails in anotherA multi-region deployment pipeline starts failing only in the disaster recovery account after environment names were cleaned up.CI/CDAdvanced12 minProCICD-1541A GitHub deployment job passes approvals and still failsDeployments fail only in one account after moving the production workflow into a new path.CI/CDAdvanced12 minProCICD-1521A GitHub environment approval passes and the deploy job still failsOnly production deploys fail after a workflow file move even though approvals complete normally.CI/CDAdvanced12 minProCICD-1531A GitHub OIDC deployment works in one account and fails in anotherDeployments fail only in one account after moving repositories under a new GitHub organization.CI/CDAdvanced12 minProSECURITY-1480A secret rotation succeeds and RDS auth still failsDatabase logins fail intermittently after secrets rotation while some requests still succeed on long-lived workers.SecurityAdvanced12 minProSECURITY-1470A secrets rotation completes and database auth still failsDatabase auth fails intermittently after a secrets rotation while some workers continue to function.SecurityAdvanced12 minProCICD-1459A Vault login action succeeds and Terraform still uses stale AWS credentialsA Vault login action succeeds and Terraform still uses stale AWS credentials focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Credential freshness bugs often come from wrapper ordering around expo...CI/CDAdvanced12 minProSECURITY-1491An IAM access analyzer finding is resolved and a cross-account role still grants accessA cross-account role remains reachable from a retired account even after the primary stack set shows the fix applied.SecurityAdvanced12 minProSECURITY-1501An IAM access finding is resolved and a cross-account role still grants accessA retired external account can still assume a role from one region after the main fix is applied.SecurityAdvanced12 minProSECURITY-1511An IAM access finding is resolved and a cross-account role still grants accessA retired external account can still assume a role from one region after the primary fix is applied.SecurityAdvanced12 minProSECURITY-1483An OpenSearch snapshot repository stays registered and restores failSnapshot restores fail only after KMS alias rotation while repository verification still passes.SecurityAdvanced12 minProCICD-1408A CodeBuild local cache speeds most jobs and one privileged image build...A CodeBuild local cache speeds most jobs and one privileged image build... focuses on Artifact Promotion and asks the reader to isolate the key signal in AWS. Local cache reuse can inherit ownership assumptions from the most privil...CI/CDAdvanced13 minProK8S-1459A Karpenter consolidation plan looks correct and still churns one poolA Karpenter consolidation plan looks correct and still churns one pool focuses on autoscaling and asks the reader to isolate the key signal in AWS. Consolidation churn often comes from timing assumptions around when a new node is trul...KubernetesAdvanced13 minProK8S-1423A cluster autoscaler adds nodes and pending pods still stay unscheduledA cluster autoscaler adds nodes and pending pods still stay unscheduled focuses on scheduler-behavior and asks the reader to isolate the key signal in AWS. Capacity can look available on paper while scheduler caches and...KubernetesAdvanced14 minProK8S-1413A cluster autoscaler scale-up looks correct and pending pods remain...A cluster autoscaler scale-up looks correct and pending pods remain... focuses on scheduler-behavior and asks the reader to isolate the key signal in AWS. Autoscaler failures can come from stale node template metadata rather than from a...KubernetesAdvanced14 minProCICD-1418A CodeBuild privileged step pushes a multi-arch image and the next pipeline...A CodeBuild privileged step pushes a multi-arch image and the next pipeline... focuses on Artifact Promotion and asks the reader to isolate the key signal in AWS. A successful push does not guarantee every referenced architectur...CI/CDAdvanced14 minProK8S-1433A scale-up event adds nodes and pending pods remain unscheduledA scale-up event adds nodes and pending pods remain unscheduled focuses on scheduler-behavior and asks the reader to isolate the key signal in AWS. New nodes can be present and still unusable when simulation metadata lags behind the act...KubernetesAdvanced14 minProK8S-1443A scale-up says pending pods will fit and they stay unscheduledA node pool migration completes and target workloads remain pending.KubernetesAdvanced14 minProCICD-1412A Terraform apply succeeds in staging and fails in productionA Terraform apply succeeds in staging and fails in production focuses on execution-context and asks the reader to isolate the key signal in AWS. Distributed backend changes can create stale lock perceptions even when Terraform itself releases t...CI/CDAdvanced14 minProCICD-1350A blue-green deploy to ECS looks clean and the old task set keeps serving a subset of trafficA platform team automates blue-green promotion and later sees mixed user behavior even though the deployment controller reports success.CI/CDAdvanced15 minPro