HashiCorp
100 incident problems in HashiCorp environments.
Read first
When the CI cache restores the wrong dependency graphAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when package.json, the lockfile, and artifacts no longer agree even after a cache hit.CI/CD3 min readWhen GitHub Actions succeeds but only the rollout failsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the build logs look fine but the failure surfaces only on the target deploy cluster or runtime.CI/CD3 min readThe checking order when GitHub Actions succeeds but only the deploy failsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the workflow is green but the failure happens only in the rollout, promotion, or health check stage.CI/CD3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
All problems (100)
CICD-1616A Terraform apply fails in one workspaceOne Terraform workspace still fails after environment slug cleanup.ReviewedCI/CDBeginner7 minFreeCICD-1626A secret rotation is complete and one step still failsOne CI step still fails after a secret rename.CI/CDBeginner7 minFreeCICD-1647A Terraform variable set is attached and one workspace still failsOne workspace still fails after an environment code cleanup.CI/CDBeginner7 minFreeCICD-1657A Terraform variable set is attached and one workspace still failsOne workspace still fails after an environment suffix cleanup.CI/CDBeginner7 minFreeCICD-1667A Terraform workspace has values and one apply still failsOne Terraform apply still fails after an environment suffix cleanup.CI/CDBeginner7 minFreeSECURITY-1460A machine identity rotates and pooled outbound TLS sessions keep failingA machine identity rotates and pooled outbound TLS sessions keep failing focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Credential rotation can fail in connection pools that treat TLS session state as...SecurityAdvanced12 minProSECURITY-1489A Vault agent rotates a certificate and the app still presents the old oneCertificate rotation succeeds in Vault and the application keeps serving the previous certificate until restart.SecurityAdvanced12 minProSECURITY-1380A Terraform-managed OIDC trust update is applied and one workspace still...A Terraform-managed OIDC trust update is applied and one workspace still... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote runners can retain assumptions about trust material even...SecurityAdvanced15 minProSECURITY-1350An AWS OIDC trust policy matches the cluster issuer and one controller still...An AWS OIDC trust policy matches the cluster issuer and one controller... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared IaC can still emit stale identity data if one workspace cached old metadata.SecurityAdvanced15 minProSECURITY-1360An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity maintenance task succeeds broadly and later one controller in one environment alone continues failing IRSA or web-identity auth.SecurityAdvanced15 minProSECURITY-1370An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity refresh completes and later only one environment continues to fail IRSA or web-identity auth for a controller.SecurityAdvanced15 minProSECURITY-1340An AWSKRUG-style EKS access pattern uses OIDC and still breaks one controllerAn AWSKRUG-style EKS access pattern uses OIDC and still breaks one controller focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared Terraform code can still render different identity assumptions if...SecurityAdvanced15 minProSECURITY-1301A Vault AppRole login succeeds and database credentials still expire earlyAn app authenticates with AppRole and later loses its dynamic credentials long before the advertised secret lifetime should end.SecurityAdvanced16 minProSECURITY-1313A Vault AppRole rollout works in staging and fails in productionA Vault AppRole rollout works in staging and fails in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. CIDR-bound auth often fails on hidden NAT differences rather than on Vault role misconfigu...SecurityAdvanced16 minProCICD-1493A Terraform Cloud speculative plan finishes and the comment never appearsDevelopers see completed speculative plans in Terraform Cloud but no PR comment after enabling an internal webhook relay.CI/CDAdvanced11 minProSECURITY-1493A Vault token revocation succeeds and an app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token was revoked during an incident response action.SecurityAdvanced11 minProSECURITY-1503A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token was revoked.SecurityAdvanced11 minProSECURITY-1513A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token is revoked.SecurityAdvanced11 minProSECURITY-1523A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after Vault revocation.SecurityAdvanced11 minProCICD-1578A Vault transit key rotates and one signing job still emits the old key versionOne signing job keeps using an old transit key version after rotation.CI/CDAdvanced11 minPro