Vendor586 problems· 4 reviewed

Kubernetes

586 incident problems in Kubernetes environments.

All problems (586)

K8S-1601A Cilium restore succeeds and one node still tags flows wrongOne node still tags flows wrong after a Cilium restore.KubernetesAdvanced10 minProK8S-1583A Gateway API listener is correct and one envoy pod still routes oldOne gateway pod still routes old traffic after listener refactoring.KubernetesAdvanced10 minProK8S-1593A Gateway API route changes and one listener still serves the old backendOne listener still serves the old backend after a Gateway API route change.KubernetesAdvanced10 minProK8S-1603A Gateway listener change is correct and one pod still routes oldOne gateway pod still routes old after a listener change.KubernetesAdvanced10 minProK8S-1610A mesh egress restriction is correct and one proxy still allows the old SANOne proxy still allows the old SAN after mesh egress fixes.KubernetesAdvanced10 minProK8S-1600A mesh egress restriction updates and one proxy still allows the old hostOne proxy still allows the old host after mesh egress restriction updates.KubernetesAdvanced10 minProCICD-1575An ApplicationSet renders the new branch map and one app still deploys the old refOne Argo CD application keeps syncing the old branch after branch map cleanup.CI/CDAdvanced10 minProNETWORK-1608An Envoy route failover is correct and one path still warms the old clusterOne route still warms the old cluster after an Envoy failover update.NetworkAdvanced10 minProSECURITY-1415An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs often come from inode and watcher semantics rather...SecurityIntermediate10 minProSECURITY-1425An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload problems are often inode or watcher issues, not stale data issues.SecurityIntermediate10 minProSECURITY-1435An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs are often inode or watcher issues, not stale data issues.SecurityIntermediate10 minProSECURITY-1445An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs are often inode or watcher issues, not stale content.SecurityIntermediate10 minProK8S-1579An IRSA issuer changes and one DaemonSet still loses credentialsOne DaemonSet loses credentials after IRSA issuer migration.KubernetesAdvanced10 minProK8S-1589An IRSA service account is corrected and one node still fails STSOne node still fails STS after IRSA service account corrections.KubernetesAdvanced10 minProK8S-1569An IRSA token file rotates and one DaemonSet still loses AWS accessA DaemonSet loses AWS access only on nodes where an init copy path still runs.KubernetesAdvanced10 minProK8S-1581A Cilium endpoint restore works and one node still denies trafficOne node still denies traffic after endpoint restore and label normalization.KubernetesAdvanced11 minProK8S-1591A Cilium node restore completes and one service still routes wrongOne node still routes wrong after Cilium restore and CIDR recycling.KubernetesAdvanced11 minProCICD-1516A Flux automation commit updates the image tag and the cluster still deploys old bitsOne cluster keeps deploying the older image even though Git and registry tags look correct.CI/CDAdvanced11 minProCICD-1526A Flux image update lands and rollback failsRollbacks fail only after digest alias cleanup in a GitOps image automation flow.CI/CDAdvanced11 minProK8S-1509A Gateway API canary route attaches and all traffic still lands on stableCanary weights never take effect on one controller revision after a Gateway API migration.KubernetesAdvanced11 minPro