AWS
339 incident problems in AWS environments.
먼저 읽을 가이드
추천 문제
All problems (339)
CICD-1398A blue-green deployment on ECS keeps a percentage of traffic on the old task...A blue-green deployment on ECS keeps a percentage of traffic on the old... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Traffic shifting can be cached at layers your deployment controller does...CI/CDAdvanced15 minProCICD-1378A blue-green ECS rollout passes health gates and some users still see the old versionA blue-green deployment looks successful in metrics and later a subset of sessions keep behaving like they never left the old version.CI/CDAdvanced15 minProCICD-1368A blue-green rollout to ECS promotes traffic and one customer cohort still...A blue-green rollout to ECS promotes traffic and one customer cohort still... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Traffic shifting success does not guarantee user stickiness aligned with th...CI/CDAdvanced15 minProCICD-1388A canary release promotes itself automatically and still rolls backA canary release promotes itself automatically and still rolls back focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Progressive delivery decisions are only as good as the baseline context that ge...CI/CDAdvanced15 minProCICD-1330A deployment health gate reports success and the service still rolls backA blue-green deployment setup passes all automated checks and still causes a rollback once user traffic hits the newly promoted target.CI/CDAdvanced15 minProCICD-1358An ECS blue-green deploy reports healthy and user sessions still breakA blue-green rollout succeeds operationally and later certain authenticated users continue interacting with the old version long after traffic weight changed.CI/CDAdvanced15 minProK8S-1335An EKS workload reaches AWS APIs and still fails one secret fetchAn EKS workload reaches AWS APIs and still fails one secret fetch focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Cross-cluster portability often fails at subtle identity defaults rather than at obvio...KubernetesAdvanced15 minProCICD-1312A GitHub deployment uses OIDC successfully and Terraform still failsA team migrates to OIDC and still sees Terraform acting as an old IAM principal in only one workflow path.CI/CDAdvanced16 minProCICD-1304A remote state lock looks cleared in DynamoDB but the next plan still refuses to runAn interrupted deployment unblocks the lock table but later runs still refuse to proceed with a lock-style error.CI/CDAdvanced16 minProCICD-357A reusable workflow signs container images correctly while downstream promotion retags an unsigned digest from a side repository during a staged decommissionSupply-chain controls protect the main path, but a side promotion lane bypasses the signed artifact. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDIntermediate16 minProK8S-1263An ALB target group stays unhealthyK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced16 minProK8S-1309An EKS add-on update looks clean but new pods cannot get IPsScaling or upgrading node groups suddenly reduces pod density while the network add-on still reports healthy.KubernetesAdvanced16 minProK8S-1262Cluster autoscaler sees unschedulable pods but never scalesK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced16 minProCICD-1303Terraform init succeeds but apply failsA team refactors shared credentials logic and later only apply fails while init and state refresh continue to work.CI/CDAdvanced16 minProSECURITY-114A bucket policy blocks public reads, but the legacy website endpoint still exposes content through an old object ACLThe new policy appears strict, yet one access path bypasses it because object-level permissions were left behind from the static site era.SecurityAdvanced17 minProSECURITY-158A cross-account access analyzer stays green, but a new resource policy grants a service principal wildcard that the analyzer scope does not flag in this org layoutVisibility tooling is present, yet its scope is narrower than the real exposure surface.SecurityAdvanced17 minProCICD-151A deployment freeze opens for one hour, but the delayed approval queue starts the rollout after the window closes and the policy engine revokes credentials mid-releaseEverything was approved at the right time, yet execution drifted outside the governance boundary.CI/CDAdvanced17 minProK8S-1265A LoadBalancer Service works from inside the cluster but external traffic...A LoadBalancer Service works from inside the cluster but external traffic... focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. Success from inside the cluster can hide that the backend applies different policy...KubernetesAdvanced17 minProK8S-1270A LoadBalancer Service works from inside the cluster but external traffic...A LoadBalancer Service works from inside the cluster but external traffic... focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. Success from inside the cluster can hide that the backend applies different policy...KubernetesAdvanced17 minProSECURITY-144A new KMS grant allows the backup role to decrypt snapshots, but the grant was created in one region and cross-region restore still failsThe permission exists, just not in the control-plane scope the recovery workflow actually uses.SecurityAdvanced17 minPro