Kubernetes
586 incident problems in Kubernetes environments.
먼저 읽을 가이드
추천 문제
All problems (586)
K8S-1526A CoreDNS update rolls out and one namespace still resolves stale endpointsOnly one namespace sees stale endpoints after a CoreDNS update.KubernetesIntermediate9 minProK8S-1536A CoreDNS update rolls out and one namespace still resolves stale endpointsOnly one namespace sees stale endpoints after a CoreDNS update.KubernetesIntermediate9 minProK8S-1578A namespaceSelector update lands and one webhook still ignores a namespaceOne webhook ignores a namespace after a selector label rename.KubernetesIntermediate9 minProK8S-1566A NodeLocal DNSCache restart succeeds and one namespace still gets NXDOMAINOne namespace sees NXDOMAIN only after search suffix changes.KubernetesIntermediate9 minProK8S-1556A NodeLocal DNSCache rollout completes and one namespace still resolves stale service IPsOne namespace sees intermittent traffic to an old service IP after DNS cache rollout.KubernetesIntermediate9 minProK8S-1494A cert-manager renewal updates the secret and ingress still serves the old certificateGateway API traffic keeps serving an old cert after a secret renewal that works fine on classic Ingress.KubernetesIntermediate10 minProK8S-1504A cert-manager renewal updates the secret and the gateway still serves the old certificateGateway API traffic serves the old cert after secret renewal while classic ingress updates fine.KubernetesIntermediate10 minProK8S-1400A cleanup job deletes old ReplicaSets and one rollback becomes impossibleA cleanup job deletes old ReplicaSets and one rollback becomes impossible focuses on Deployment Governance and asks the reader to isolate the key signal in Kubernetes. Operational rollback tooling often depends on annotations and histor...KubernetesIntermediate10 minProK8S-1464A CoreDNS loop appears on one Ubuntu node poolCoreDNS loop warnings start only after one worker image line moves to a newer Ubuntu release.KubernetesIntermediate10 minProK8S-1485A CSI restore mounts fine and the app still sees readonly filesA restored workload mounts its volume and still cannot write after a storage-side restore into a reused path.KubernetesIntermediate10 minProK8S-1476A CSI volume mounts and the app still cannot writeA stateful app fails to write only after a restore into a reused mount path with subPath enabled.KubernetesIntermediate10 minProK8S-1419A host-network ingress addon starts rejecting trafficA host-network ingress addon starts rejecting traffic focuses on edge-routing and asks the reader to isolate the key signal in Kubernetes. Host-networked addons can fail because of node-side cleanup helpers that know old ports but not ne...KubernetesIntermediate10 minProK8S-1429A host-network ingress addon stays Ready and one new health endpoint never...A host-network ingress addon stays Ready and one new health endpoint never... focuses on edge-routing and asks the reader to isolate the key signal in Kubernetes. Host-networked addon failures can be caused by background host cleanup loops...KubernetesIntermediate10 minProK8S-1439A host-network ingress addon stays Ready and one new health port still failsA host-network ingress addon stays Ready and one new health port still fails focuses on edge-routing and asks the reader to isolate the key signal in Kubernetes. Host-network addon regressions often come from node-level port management, not p...KubernetesIntermediate10 minProK8S-1558An admission webhook cert rotates and one API server still reports x509 errorsOnly one API server reports x509 webhook errors after certificate rotation.KubernetesIntermediate10 minProK8S-1568An admission webhook manifest is updated and one namespace still ignores itOne namespace still ignores the webhook after the manifest was hardened.KubernetesIntermediate10 minProK8S-1478An Istio AuthorizationPolicy allows JWT traffic and still blocks browser clientsBrowsers fail against a service while direct token-bearing requests from curl still succeed.KubernetesIntermediate10 minProK8S-1469An Istio WebSocket path keeps the TCP session and still loses authNormal API calls pass and WebSocket upgrades lose authentication after a routing cleanup.KubernetesIntermediate10 minProK8S-1462A cert-manager DNS01 challenge hits the right zone and still failsWildcard issuance fails for one delegated subzone while the provider confirms the TXT record is present.KubernetesIntermediate11 minProK8S-1444A cert-manager DNS01 challenge loopsIssuance breaks only after a hardened runtime class rollout.KubernetesIntermediate11 minPro