NGINX
274 incident problems in NGINX environments.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
Ingress 404 Not Found: only the newly added www host returns 404Ingress 404 Not Found: only the newly added www host returns 404 is a hands-on troubleshooting drill. Check that the request's host name matches an Ingress rule. NGINX Kubernetes Ingress and Traffic needs to be checked by narrowing scope, recent change, and the current live si...ReviewedKubernetesBeginner3 minFreenginx 403 with (13: Permission denied): only the newly uploaded filenginx 403 with (13: Permission denied): only the newly uploaded file is a hands-on troubleshooting drill. Read file permissions to see why nginx cannot open a file. NGINX file-permissions needs to be checked by narrowing scope, recent change, and the current live signal before...ReviewedLinuxBeginner3 minFreeNETWORK-020The CDN cache is fine, but a TLS version difference with the origin fails only miss requestsA situation where most requests are cache hits and look fine, but origin communication breaks only in the cache-miss segment.ReviewedNetworkIntermediate24 minPro502 Bad Gateway: every page fails after a PHP upgrade502 Bad Gateway: every page fails (Network Services And Operations) is a hands-on troubleshooting drill. Read nginx's upstream error to see why it cannot reach php-fpm. NGINX Network Services And Operations needs to be checked by narrowing scope, recent change, and the current...ReviewedNetworkBeginner3 minFree502 Bad Gateway: Nginx cannot connect to its upstream after an app upgrade502 Bad Gateway: Nginx cannot connect to its upstream is a hands-on troubleshooting drill. Read Nginx's upstream error to find why the proxy cannot reach the app. NGINX Network Services And Operations needs to be checked by narrowing scope, recent change, and the current live...ReviewedNetworkBeginner14 minFree504 Gateway Timeout: only the order list fails after a table migration504 Gateway Timeout: only the order list fails is a hands-on troubleshooting drill. A 504 means the upstream answered too slowly; find out why. NGINX Network Services And Operations needs to be checked by narrowing scope, recent change, and the current live signal before rollb...ReviewedNetworkBeginner3 minFree
All problems (274)
nginx 403 with (13: Permission denied): only the newly uploaded filenginx 403 with (13: Permission denied): only the newly uploaded file is a hands-on troubleshooting drill. Read file permissions to see why nginx cannot open a file. NGINX file-permissions needs to be checked by narrowing scope, recent change, and the current live signal before...ReviewedLinuxBeginner3 minFree502 Bad Gateway: every page fails after a PHP upgrade502 Bad Gateway: every page fails (Network Services And Operations) is a hands-on troubleshooting drill. Read nginx's upstream error to see why it cannot reach php-fpm. NGINX Network Services And Operations needs to be checked by narrowing scope, recent change, and the current...ReviewedNetworkBeginner3 minFree504 Gateway Timeout: only the order list fails after a table migration504 Gateway Timeout: only the order list fails is a hands-on troubleshooting drill. A 504 means the upstream answered too slowly; find out why. NGINX Network Services And Operations needs to be checked by narrowing scope, recent change, and the current live signal before rollb...ReviewedNetworkBeginner3 minFreeIngress 404 Not Found: only the newly added www host returns 404Ingress 404 Not Found: only the newly added www host returns 404 is a hands-on troubleshooting drill. Check that the request's host name matches an Ingress rule. NGINX Kubernetes Ingress and Traffic needs to be checked by narrowing scope, recent change, and the current live si...ReviewedKubernetesBeginner3 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFree502 Bad Gateway: Nginx cannot connect to its upstream after an app upgrade502 Bad Gateway: Nginx cannot connect to its upstream is a hands-on troubleshooting drill. Read Nginx's upstream error to find why the proxy cannot reach the app. NGINX Network Services And Operations needs to be checked by narrowing scope, recent change, and the current live...ReviewedNetworkBeginner14 minFreeNETWORK-011A proxy-header problem that works with curl but looks like a CORS error only in the browserA proxy-header problem that works with curl but looks like a CORS error only... is a hands-on troubleshooting drill. A situation where it is not an actual network outage but a response-header policy that fails only browser requests. NGINX Firewall and Proxy Paths needs to be c...NetworkBeginner16 minFreeSECURITY-052ACME HTTP-01 renewal failsTLS worked yesterday, but automated renewal now fails because the well-known challenge route is treated like an untrusted request pattern by the current edge policy.SecurityIntermediate20 minFreeSECURITY-077Custom WAF allow rule matches but a later managed rule still blocks the requestThe operator sees the expected custom rule fire, yet traffic remains blocked because the final decision is made by a later managed rule with stronger action priority.SecurityIntermediate16 minFreeSECURITY-082TLS offload proxy re-encrypts with a deprecated cipher set and only one partner API rejects itClient-facing certificates look modern, but one partner integration breaks because the upstream re-encryption profile still uses a weaker legacy policy.SecurityIntermediate17 minFreeSECURITY-064WAF bot challenge protects the browser path but blocks webhook callbacks from non-browser clientsThe site is safer for humans, but an integration silently breaks because the challenged path now assumes browser behavior that the webhook sender never provides.SecurityIntermediate17 minFreeSECURITY-073mTLS client authentication failsThe certificate is valid and trusted, but client auth still fails because the service enforces a SAN type that the issued cert never included.SecurityIntermediate18 minFreeSECURITY-067Certificate transparency alert points to a legacy SAN certificate still trusted by one proxy pathThe newly issued certificate is intentional, but one forgotten proxy still trusts the older SAN chain and continues to present the unexpected path.SecurityIntermediate19 minFreeSECURITY-131A CSP report-only endpoint loops back through the same proxy path and turns a small XSS burst into an internal traffic floodDetection remains enabled, but the reporting path amplifies rather than observes the incident.SecurityIntermediate15 minFreeK8S-098Gateway route hostname matches but TLS mode passthrough prevents the expected path rewriteThe route is attached, yet behavior differs because the chosen TLS handling mode bypasses the HTTP features the operator expected to apply.KubernetesIntermediate16 minFreeK8S-089Probe succeeds on localhost but the service mesh policy blocks real pod-to-pod callsThe container reports healthy, yet callers still fail because the readiness command bypasses the same network policy and sidecar path used in production traffic.KubernetesIntermediate16 minFreeK8S-082Ingress path works externally but internal probes failUser traffic succeeds through one route, yet health probes and some internal paths fail because the controller still speaks the wrong protocol to the service.KubernetesIntermediate17 minFreeK8S-075Service mesh sidecar intercept excludes the health port on one Deployment onlyThe mesh is healthy in the cluster overall, but one workload fails readiness because its sidecar capture rules skip the port the probe is supposed to reach.KubernetesIntermediate17 minFreeK8S-085Gateway API route is accepted but the ReferenceGrant does not cover the namespace of the backend serviceThe route object itself looks valid, yet traffic never forwards because the cross-namespace backend reference is not explicitly granted.KubernetesIntermediate18 minFreeK8S-055Gateway API route is Accepted but never serves trafficThe route object looks healthy in status output, but the parent listener does not actually match the requested hostname and path combination.KubernetesIntermediate22 minFree