Cloudflare
239 incident problems in Cloudflare environments.
먼저 읽을 가이드
추천 문제
All problems (239)
NETWORK-1419A new SaaS subdomain is onboarded to a shared CDN and only one campus failsA new SaaS subdomain is onboarded to a shared CDN and only one campus fails focuses on edge-routing and asks the reader to isolate the key signal in Cloudflare. On shared CDN platforms, a hostname can inherit an older policy bundle long after...NetworkAdvanced13 minProNETWORK-1439A newly onboarded export hostname fails from one campusA newly onboarded SaaS export domain fails only from one policy-routed campus path.NetworkAdvanced13 minProNETWORK-1449A newly onboarded export hostname fails from one campusA new export domain fails only from one campus path after a trust bundle update.NetworkAdvanced13 minProNETWORK-1409A SaaS export endpoint fails only from one campusA SaaS export endpoint fails only from one campus focuses on edge-routing and asks the reader to isolate the key signal in Cloudflare. Shared CDN policy trees can misclassify new hostnames long after DNS looks correct everywhere else.NetworkAdvanced13 minProSECURITY-1325A WAF managed rule blocks only one mobile clientA WAF ruleset update is followed by selective failures affecting only one legacy mobile client integration.SecurityIntermediate13 minProNETWORK-1441An HTTP/3 origin check passes in staging and fails in productionAn HTTP/3 origin check passes in staging and fails in production focuses on edge-routing and asks the reader to isolate the key signal in Cloudflare. Transport upgrades can change header normalization in ways signature code never anticipated.NetworkAdvanced13 minProNETWORK-1391A CDN hostname serves HTTP/2 cleanly and API uploads fail over HTTP/3Uploads fail only for clients that negotiate HTTP/3 while ordinary browsing and HTTP/2 API calls remain healthy.NetworkAdvanced14 minProSECURITY-1355A Cloudflare Access app is protected on 443 and an alternate admin port...A Cloudflare Access app is protected on 443 and an alternate admin port... focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the main hostname does not automatically...SecurityAdvanced14 minProSECURITY-1391A Cloudflare Access application protects the dashboard and one API path stays...A Cloudflare Access application protects the dashboard and one API path... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Machine-auth exceptions can unintentionally shadow user-facing policy when hos...SecurityAdvanced14 minProNETWORK-1343A Cloudflare cache purge succeeds for URLs and stale content remainsA caching optimization rollout works initially and later targeted purges stop removing stale content even though the API accepts every request.NetworkAdvanced14 minProNETWORK-1361A Cloudflare proxied hostname returns intermittent 526A proxied site looks healthy and later only some requests return 526 when traffic lands on a specific origin server.NetworkAdvanced14 minProNETWORK-1381A QUIC-enabled edge works for browsers and the enterprise proxy breaks API...A QUIC-enabled edge works for browsers and the enterprise proxy breaks API... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Protocol negotiation bugs can hide in header mutation behavior that differs...NetworkAdvanced14 minProSECURITY-1389A remediation feed is healthy and one region ignores itA remediation feed is healthy and one region ignores it focuses on incident-response and asks the reader to isolate the key signal in Cloudflare. Security feed drift can come from edge cache key design, not from the upstream deci...SecurityAdvanced14 minProSECURITY-1401An access proxy protects the user API and one newly split service path is...An access proxy protects the user API and one newly split service path is... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Security regressions often come from route shadowing, not from a mis...SecurityAdvanced14 minProSECURITY-1399An edge remediation list is updated and one POP still serves stale allow...An edge remediation list is updated and one POP still serves stale allow... focuses on incident-response and asks the reader to isolate the key signal in Cloudflare. Edge caching bugs can live in fetch path variants, not only in the visibl...SecurityAdvanced14 minProSECURITY-1375Cloudflare Access protects the main hostname and an alternate admin listener...Cloudflare Access protects the main hostname and an alternate admin... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge access controls are only as complete as the hos...SecurityAdvanced14 minProNETWORK-1315A Cloudflare cache rule speeds up one static route and later stale security headers persistA zone hardens response headers and one route continues serving an older header set even after the transform rule is changed.NetworkAdvanced15 minProNETWORK-1321A Cloudflare proxied hostname returns 526 only from one backend pool memberA Cloudflare proxied hostname returns 526 only from one backend pool member focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Intermittent 526 errors often mean your origins are not serving the...NetworkAdvanced15 minProNETWORK-1325A split horizon DNS setup works on LAN and fails at the edgeA hybrid network uses different answers for internal and public clients and later some edge users resolve to the wrong target after an upstream cache change.NetworkAdvanced15 minProNETWORK-1305Full strict mode returns 526 only on an alternate hostnameA new vanity or fallback hostname is added and only that path starts returning 526 through Cloudflare.NetworkAdvanced15 minPro