HashiCorp
100 incident problems in HashiCorp environments.
먼저 읽을 가이드
추천 문제
All problems (100)
SECURITY-1461A Vault Agent rotates the certificate and one JVM still presents the old chainAn mTLS client keeps presenting the retired chain after Vault Agent rotates the file-backed certificate.SecurityAdvanced12 minProSECURITY-1471A Vault Agent rotates the leaf cert and the app still presents the old chainA restarted JVM still serves the old chain when Vault Agent rotates secrets just after process bootstrap.SecurityAdvanced12 minProCICD-1459A Vault login action succeeds and Terraform still uses stale AWS credentialsA Vault login action succeeds and Terraform still uses stale AWS credentials focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Credential freshness bugs often come from wrapper ordering around expo...CI/CDAdvanced12 minProSECURITY-1452A Vault Transit key rotates and one app tier still rejects JWE tokensEncrypted tokens fail only in one app tier after Transit key rotation while decryption still works elsewhere.SecurityAdvanced12 minProSECURITY-1486An OPA bundle rollout succeeds and one deny rule still firesA deny rule that should be gone continues firing after a successful policy bundle rollout.SecurityAdvanced12 minProSECURITY-1475An OPA bundle verifies and stale deny rules persistA policy refactor appears deployed while one deny rule from the old package path still fires in production.SecurityAdvanced12 minProSECURITY-1465An OPA bundle verifies and still serves stale policyOne sidecar still accepts bundles signed with a revoked key even after JWKS rotation.SecurityAdvanced12 minProSECURITY-1429A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when apps only invalidate p...SecurityAdvanced14 minProSECURITY-1439A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minProSECURITY-1449A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minProSECURITY-1419A service binding receives a tighter policy and one application tier keeps...A service binding receives a tighter policy and one application tier keeps... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can persist when applications couple reloads to secret change...SecurityAdvanced14 minProSECURITY-1409A service binding receives the correct policy on first rollout and later...A service binding receives the correct policy on first rollout and later... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Permission drift can survive policy rollout when pooled connections cache earlie...SecurityAdvanced14 minProCICD-1412A Terraform apply succeeds in staging and fails in productionA Terraform apply succeeds in staging and fails in production focuses on execution-context and asks the reader to isolate the key signal in AWS. Distributed backend changes can create stale lock perceptions even when Terraform itself releases t...CI/CDAdvanced14 minProSECURITY-1322A Vault policy looks permissive and KV reads still failA service token is updated and later can enumerate secrets but cannot actually read the intended values from Vault.SecurityAdvanced14 minProSECURITY-1302Vault KV access works in the UI and fails in automationOperators validate access in the UI and later the service account still gets permission denied on KV reads.SecurityIntermediate14 minProCICD-1392A Terraform apply detects no drift and a production rollout still targets the...A Terraform apply detects no drift and a production rollout still targets... focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Terraform Cloud can hide behavior differences in workspace metadata layers you...CI/CDAdvanced15 minProCICD-1402A Terraform Cloud drift detection run is clean and production still divergesA Terraform Cloud drift detection run is clean and production still diverges focuses on execution-context and asks the reader to isolate the key signal in hashicorp. Remote runners can preserve provider behavior through cache...CI/CDAdvanced15 minProCICD-1382A Terraform Cloud plan is clean and apply failsA governance fix is published and later one workspace still fails or passes against logic no one can reproduce locally.CI/CDAdvanced15 minProCICD-1390A Terraform destroy plan targets the right stack and fails halfwayA Terraform destroy plan targets the right stack and fails halfway focuses on cluster-maintenance and asks the reader to isolate the key signal in hashicorp. Destroy failures often reveal stale read paths in provider aliases that normal ap...CI/CDAdvanced15 minProCICD-1400A Terraform module upgrade succeeds in plan and crashes at applyA Terraform module upgrade succeeds in plan and crashes at apply focuses on execution-context and asks the reader to isolate the key signal in hashicorp. Provider upgrades often surface hidden assumptions in policy engines about list ordering...CI/CDAdvanced15 minPro