Kubernetes
586 incident problems in Kubernetes environments.
먼저 읽을 가이드
추천 문제
All problems (586)
K8S-1348A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to-https-by-global-annotation)A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary ingress objects can inherit global behaviors that break...KubernetesIntermediate13 minProK8S-1466A CSI snapshot restore mounts cleanly and the app still sees stale dataA rollback appears complete, yet one stateful workload continues reading old blocks until the pod is recreated.KubernetesAdvanced13 minProK8S-1318A DaemonSet upgrade seems fine until one node class loses logsA node image refresh lands and later only some nodes stop yielding host logs while the collector DaemonSet still reports Ready.KubernetesIntermediate13 minProK8S-1450A StatefulSet rollback looks done and one canary stays on the new specA rollback completes and one member still shows the newer behavior.KubernetesAdvanced13 minProK8S-1457A Velero CSI restore recreates PVCs and one workload still failsA CSI-based restore partially succeeds and one workload remains stuck recreating its PVC.KubernetesAdvanced13 minProK8S-1408A Velero restore looks successful and the app still never comes readyA Velero restore looks successful and the app still never comes ready focuses on backup-restore and asks the reader to isolate the key signal in Kubernetes. Restore tooling can omit keys it classifies as generated metadata even when applications...KubernetesAdvanced13 minProCICD-1476An Argo CD wave order looks correct and one namespace still deadlocksA GitOps rollout hangs only after a generate policy starts creating extra namespace-scoped resources.CI/CDAdvanced13 minProK8S-1382A cert-manager CA injector updates one namespace and misses anotherA cert-manager CA injector updates one namespace and misses another focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Injection drift can come from label schema changes that silently drop one object...KubernetesAdvanced14 minProK8S-1394A cert-manager HTTP01 solver pod comes up and challenges still failA cert-manager HTTP01 solver pod comes up and challenges still fail focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Challenge traffic may reach a different address family than the one o...KubernetesAdvanced14 minProK8S-1397A Cilium FQDN policy allows package mirrors and node bootstrap still failsA Cilium FQDN policy allows package mirrors and node bootstrap still fails focuses on cluster-maintenance and asks the reader to isolate the key signal in Kubernetes. FQDN policy allows are only effective after the observation path has se...KubernetesAdvanced14 minProK8S-1387A Cilium host firewall rollout blocks node-local DNSA Cilium host firewall rollout blocks node-local DNS focuses on incident-response and asks the reader to isolate the key signal in Kubernetes. Host firewall rollouts require a different mental model from workload identity policy.KubernetesAdvanced14 minProK8S-1455A device plugin returns healthy after a node image rollback and the kubelet still refuses allocationsAllocations fail only on nodes rolled back to the previous image after a failed upgrade.KubernetesAdvanced14 minProK8S-1412A Gatekeeper constraint rejects only one object kindA Gatekeeper constraint rejects only one object kind focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Admission inconsistencies can be limited to one versioned path or kind even when the c...KubernetesAdvanced14 minProK8S-1432A Gatekeeper rollout looks healthy and one forbidden object still slipsA Gatekeeper rollout looks healthy and one forbidden object still slips focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Inconsistent policy enforcement can come from earlier admission fai...KubernetesAdvanced14 minProK8S-1442A Gatekeeper rule looks healthy and one forbidden object still landsForbidden resources appear only during admission load spikes.KubernetesAdvanced14 minProK8S-1422A Gatekeeper upgrade looks healthy and one team still creates forbidden...A Gatekeeper upgrade looks healthy and one team still creates forbidden... focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Inconsistent policy enforcement can come from earlier admiss...KubernetesAdvanced14 minProK8S-1369A Hubble flow view shows allowed workload traffic and the app still failsOperators investigate a connectivity problem with Hubble and later discover the deny occurred outside the workload flow view they trusted.KubernetesAdvanced14 minProK8S-1379A Hubble workload view shows allowed traffic and the app still failsOperators rely on Hubble to debug traffic and later discover the actual block was outside the workload path it visualized.KubernetesAdvanced14 minProK8S-1403A node provisioning workflow applies a taint-removal patch and new workloads...A node provisioning workflow applies a taint-removal patch and new... focuses on scheduler-behavior and asks the reader to isolate the key signal in Kubernetes. Placement bugs can come from when a field becomes visible to the scheduler, not whe...KubernetesAdvanced14 minProK8S-1428A Velero restore brings back CRDs and one controller never stabilizesA Velero restore brings back CRDs and one controller never stabilizes focuses on admission-control and asks the reader to isolate the key signal in Kubernetes. Restore order can matter long after everything exists if early...KubernetesAdvanced14 minPro