Vendor586 problems· 4 reviewed

Kubernetes

586 incident problems in Kubernetes environments.

All problems (586)

SECURITY-1489A Vault agent rotates a certificate and the app still presents the old oneCertificate rotation succeeds in Vault and the application keeps serving the previous certificate until restart.SecurityAdvanced12 minProSECURITY-1363An Elastic API key rotation is successful and one Beats sidecar still failsCredential rotation finishes and later one ingestion path continues to return 401 despite the new secret being present in the cluster.SecurityAdvanced14 minProSECURITY-1386A Cilium deny policy looks correct and one egress path remains openA Cilium deny policy looks correct and one egress path remains open focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Policy surprises often come from broader selectors attached through helper layers lik...SecurityAdvanced15 minProSECURITY-1357A Cilium FQDN policy allows a hostname and still blocks trafficA Cilium FQDN policy allows a hostname and still blocks traffic focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy is only as correct as the DNS query that actually leaves the worklo...SecurityAdvanced15 minProSECURITY-1377A Cilium FQDN policy allows the expected hostname and traffic still failsA Cilium FQDN policy allows the expected hostname and traffic still fails focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. FQDN policies operate on real DNS observations, not on the hostname stri...SecurityAdvanced15 minProSECURITY-1336A Cilium network policy blocks unexpected egress only in one security...A Cilium network policy blocks unexpected egress only in one security... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy decisions can stale independently from pod label...SecurityAdvanced15 minProSECURITY-1347A Cilium policy allows one FQDN and still breaks egressA secure namespace uses a service mesh sidecar and later one external dependency fails only under FQDN-based egress controls.SecurityAdvanced15 minProSECURITY-1327An admission policy rollout breaks only one namespaceAn admission policy rollout breaks only one namespace focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Distributed trust injection systems rarely converge everywhere at the same instant.SecurityAdvanced15 minProSECURITY-1353An Elastic API key rotates successfully and one Beats sidecar keeps 401ingA credential rotation is completed and later one logging path continues to fail even though the secret update is visible in the cluster.SecurityAdvanced15 minProSECURITY-1343An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected-old-api-key-volume)An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Cluster secret updates do not automatically mean every pod reop...SecurityAdvanced15 minProSECURITY-1318A Kubernetes admission webhook serves valid TLS and requests still failA cluster rotates webhook serving certs in place and later admission failures appear even though the pod and service remain healthy.SecurityAdvanced16 minProSECURITY-1309mTLS resumes fine after certificate rotation on one service and fails on anotherA rotation campaign updates bundles cluster-wide and only one workload or sidecar continues failing mutual TLS handshakes.SecurityAdvanced16 minProSECURITY-1564A secret rotation is complete and one workload still reads the old valueOne workload keeps reading the old secret after a successful rotation.SecurityIntermediate8 minProSECURITY-1594An External Secrets fix lands and one app still gets the old payloadOne app still gets the old payload after an External Secrets fix.SecurityIntermediate8 minProSECURITY-1584An External Secrets merge order is fixed and one app still sees the old payloadOne app still sees the old secret payload after merge-order fixes.SecurityIntermediate8 minProSECURITY-1574An External Secrets merge rule is corrected and one workload still builds the old payloadOne workload still assembles the old secret payload after merge-rule cleanup.SecurityIntermediate8 minProSECURITY-1554A secret rotation completes and one workload still uses the retired valueOne workload keeps using a retired secret after rotation across stores.SecurityIntermediate9 minProSECURITY-1604An External Secrets template is fixed and one pod still renders the old credentialOne pod still renders the old credential after an External Secrets fix.SecurityAdvanced9 minProK8S-1599An IRSA mapping is fixed and one pod still fails STSOne pod still fails STS after an IRSA mapping fix.KubernetesAdvanced9 minProK8S-1609An IRSA mapping is fixed and one pod still fails STSOne pod still fails STS after an IRSA mapping fix.KubernetesAdvanced9 minPro