Kubernetes
586 incident problems in Kubernetes environments.
먼저 읽을 가이드
추천 문제
All problems (586)
K8S-1551A Cilium policy rollout finishes and one node still bypasses egress rulesOne node bypasses egress policy after identity translation rules change.KubernetesAdvanced12 minProK8S-1501A Cilium policy rollout looks correct and one namespace still drops east-west trafficCross-cluster service traffic fails only from one node pool after a Cilium peering update.KubernetesAdvanced12 minProK8S-1531A Cilium rollout finishes and one service path still dropsTraffic drops only from one node after a service rollout on Cilium.KubernetesAdvanced12 minProK8S-1491A Cilium upgrade completes and east-west traffic still dropsCross-cluster service calls fail only between one peered segment after a Cilium control-plane upgrade.KubernetesAdvanced12 minProK8S-1511A Cilium upgrade finishes and one node still drops service trafficOnly one node drops service traffic after a high-churn rolling update on a Cilium cluster.KubernetesAdvanced12 minProNETWORK-1476A DoH migration works for browsers and breaks one service meshMesh sidecars fail only during cold start after a DNS-over-HTTPS migration.NetworkAdvanced12 minProK8S-1493A Kubernetes API priority and fairness change lands and kubelet heartbeats still starveNode heartbeats degrade only for fresh autoscaled nodes after API priority and fairness tuning.KubernetesAdvanced12 minProK8S-1570A mesh sidecar updates and one workload still uses the old outbound clusterOne workload stays on the old outbound cluster after sidecar update.KubernetesAdvanced12 minProK8S-1530A mesh trust policy updates and one sidecar still rejects peersOne workload rejects mesh peers after a trust domain alias cleanup.KubernetesAdvanced12 minProK8S-1540A mesh trust policy updates and one sidecar still rejects peersOne workload rejects mesh peers after a trust alias cleanup.KubernetesAdvanced12 minProK8S-1520A service mesh mTLS policy updates and one sidecar still rejects peersOnly one workload rejects mesh peers after a trust domain alias cleanup.KubernetesAdvanced12 minProK8S-1560A service mesh revision switch succeeds and one workload still routes to the old control planeOne workload remains on the old control plane after a mesh revision switch.KubernetesAdvanced12 minProK8S-1503An API priority and fairness update lands and kubelet heartbeats still starveNode heartbeats degrade only for fresh autoscaled nodes after APF tuning.KubernetesAdvanced12 minProSECURITY-1373An Elastic logging sidecar reconnects (elastic-sidecar-mounted-new-secret-but-kept-old-key-in-env-file)An Elastic logging sidecar reconnects (elastic-sidecar-mounted-new-secret-but... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Projected secret updates do not guarantee the process r...SecurityIntermediate12 minProK8S-1471A Cilium egress gateway policy looks correct and one namespace still leaks direct trafficCompliance checks fail only on readiness or liveness probes after an egress-gateway rollout.KubernetesAdvanced13 minProK8S-1461A Cilium policy allows the namespace and still blocks node-local DNSPods on one node pool lose DNS right after node-local DNS and host firewall hardening are enabled together.KubernetesAdvanced13 minProK8S-1449A host-network ingress stays ready and still fails trafficHost-network ingress remains ready while user traffic fails after firewall automation changed.KubernetesAdvanced13 minProK8S-1459A Karpenter consolidation plan looks correct and still churns one poolA Karpenter consolidation plan looks correct and still churns one pool focuses on autoscaling and asks the reader to isolate the key signal in AWS. Consolidation churn often comes from timing assumptions around when a new node is trul...KubernetesAdvanced13 minProSECURITY-1396A Cilium egress deny policy appears tight and one init container still...A Cilium egress deny policy appears tight and one init container still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Short-lived container phases can expose timing windows that st...SecurityAdvanced14 minProSECURITY-1367A Cilium FQDN policy allows the configured hostname and still blocks trafficA service mesh is enabled and only name-based egress policy begins failing for one dependency path.SecurityAdvanced14 minPro