NGINX
274 incident problems in NGINX environments.
먼저 읽을 가이드
추천 문제
All problems (274)
K8S-091Mutating webhook times out only on large Pod specsSmall workloads admit fine, but larger ones fail because the webhook path includes a proxy with a body-size setting lower than the API server request.KubernetesAdvanced18 minProK8S-151The ingress controller trusts X-Forwarded-Proto from the external load balancer, but an internal hop rewrites it and secure redirects begin loopingTLS is terminated correctly, yet downstream protocol awareness is now inconsistent across hops.KubernetesAdvanced18 minProSECURITY-198An updated trust bundle reaches the app while the sidecar or proxy path still pins the previous set during a failover rehearsalThe main process trusts the new chain and an adjacent component still rejects it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced19 minProSECURITY-1194Basic auth on one route hides that the file-upload path uses a different location blockThe visible admin page is protected, but the upload path still reaches the backend unauthenticated because it matches another location rule.SecurityIntermediate19 minProSECURITY-1190Scanner reports the upload path is openA basic-auth recipe from community forums was added to NGINX. The visible admin UI is protected, but an adjacent upload path still reaches the backend unauthenticated.SecurityIntermediate19 minProNETWORK-1210HTTPS health checks pass on one hostname while the real route failsAn edge service returns healthy responses to probes on one host name, while customers still see TLS errors on another.NetworkAdvanced22 minProSECURITY-011Reverse proxy strips security header needed for SSO callbackThe identity provider finishes correctly, but the application rejects the callback because a forwarded security header never arrives.SecurityIntermediate22 minProK8S-1209One ingress route still breaks WebSocket upgradesA platform keeps WebSockets behind ingress plus an edge proxy and only one upgraded route returns 400.KubernetesAdvanced23 minProNETWORK-1200Reverse proxy timeout tuning hides that one upstream path is serializing requests unexpectedlyRaising timeout values improves symptoms temporarily, but the real issue is that a supposedly parallel backend path became serialized and now stalls under modest load.NetworkAdvanced23 minProK8S-1564A cert-manager HTTP01 solver is patched and one order still failsHTTP01 validation fails only on one ingress path after solver updates.KubernetesIntermediate9 minProCICD-1564An Argo CD sync hook runs and one app still reports stale healthOne Argo CD app stays unhealthy after a sync-hook secret rotation.CI/CDIntermediate9 minProK8S-1472A cert-manager HTTP01 challenge reaches the ingress and still failsCertificate issuance fails only after canary ingress annotations are added for a blue-green rollout.KubernetesIntermediate10 minProNETWORK-1461A chained proxy protocol setup logs the wrong client IPGeo ACLs and audit logs break after a second proxy tier is inserted in front of the app.NetworkIntermediate10 minProNETWORK-1388A hardware load balancer health check passes and real traffic failsA hardware load balancer health check passes and real traffic fails focuses on runtime-configuration and asks the reader to isolate the key signal in NGINX. A green health check can be meaningless if it asks a simpler protocol question th...NetworkIntermediate10 minProCICD-1597A Helm provenance job still fails through one proxyOne Helm provenance path still fails through a proxy after signer cleanup.CI/CDAdvanced10 minProCICD-1607A Helm provenance job validates at origin and still fails through one edgeOne edge path still fails Helm provenance after signer cleanup.CI/CDAdvanced10 minProCICD-1506A Jenkins inbound agent connects and console streaming freezesJenkins agents stay online while only console logs freeze after proxy policy tightening.CI/CDIntermediate10 minProNETWORK-1398A load balancer monitor says healthy and clients fail POST requestsA load balancer monitor says healthy and clients fail POST requests focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Health checks often overestimate availability when they bypass the security or...NetworkIntermediate10 minProNETWORK-1471A proxy chain preserves client IP for HTTP and breaks gRPC audit trailsClient IP auditing works for REST traffic and fails only for gRPC after a proxy refactor.NetworkIntermediate10 minProSECURITY-1466A SAML ACS route verifies signatures and still fails destination checksSAML sign-in fails only after a reverse proxy cleanup removed explicit external port handling.SecurityIntermediate10 minPro