NGINX
274 incident problems in NGINX environments.
먼저 읽을 가이드
추천 문제
All problems (274)
SECURITY-1487A SAML assertion validates and browser login still failsSAML login works in test tools and fails in browsers after a callback hostname migration.SecurityIntermediate10 minProSECURITY-1496A SAML metadata refresh succeeds and SP-initiated login still loopsSP-initiated SAML login loops only for one realm after an IdP metadata and signing cert refresh.SecurityIntermediate10 minProSECURITY-1506A SAML metadata refresh succeeds and SP-initiated login still loopsSP-initiated SAML login loops only for one realm after metadata refresh.SecurityIntermediate10 minProSECURITY-1516A SAML metadata refresh succeeds and SP-initiated login still loopsSP-initiated SAML login loops only for one realm after metadata refresh.SecurityIntermediate10 minProSECURITY-1476A SAML response validates and still fails only in browsersSAML login works in test tools and fails in browsers only after cookie defaults change on the callback domain.SecurityIntermediate10 minProK8S-1460An ingress snippet policy blocks only one classAn ingress snippet policy blocks only one class focuses on edge-routing and asks the reader to isolate the key signal in NGINX. Admission allowlists often key off controller metadata that seems unrelated to the snippet itself.KubernetesIntermediate10 minProNETWORK-1468An NGINX stream route stops matching long SNI namesOnly newly branded hostnames fall through to the default upstream on the stream ingress tier.NetworkIntermediate10 minProNETWORK-1478An NGINX stream SNI route works for short names and misroutes long tenant namesOnly long tenant hostnames on high-latency links fall through to the default upstream.NetworkIntermediate10 minProNETWORK-1484An NGINX upstream DNS update is correct and one pool still serves dead backendsTraffic continues hitting dead backend IPs after a DNS cutover behind NGINX.NetworkIntermediate10 minProCICD-1498A Helm chart release signs successfully and provenance verification still failsChart verification fails only for downloads served through one edge tier after a naming normalization change.CI/CDAdvanced11 minProCICD-1567A Helm provenance check passes at origin and fails through one proxyChart verification fails only through one proxy tier after migrating to OCI charts.CI/CDAdvanced11 minProNETWORK-1444A proxy protocol health check passes and real traffic failsLoad balancer checks stay green while production requests fail after enabling Proxy Protocol features.NetworkIntermediate11 minProSECURITY-1455A SAML response verifies and one ACS path still rejects itSAML login works on one path and fails only behind a proxy that now terminates TLS differently.SecurityIntermediate11 minProNETWORK-1394A TCP stream proxy still passes traffic and client IP allowlists failA TCP stream proxy still passes traffic and client IP allowlists fail focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Source identity failures can come from protocol version mismatch even when tr...NetworkIntermediate11 minProNETWORK-1384An NGINX stream proxy accepts TLS and backend auth breaksAn NGINX stream proxy accepts TLS and backend auth breaks focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Proxy protocol misalignment often shows up as auth or allowlist failures rather th...NetworkIntermediate11 minProCICD-1505An OCI Helm promotion completes and provenance verification failsHelm OCI provenance checks fail only behind one edge cache after promotion succeeds.CI/CDAdvanced11 minProK8S-1378A cert-manager HTTP01 challenge failsA global ingress annotation cleanup lands and later only HTTP01 certificate renewals begin to fail.KubernetesIntermediate12 minProK8S-1368A cert-manager HTTP01 challenge fails (http01-solver-ingress-inherited-global-https-redirect)A cert-manager HTTP01 challenge fails (http01-solver-ingress-inherited-global... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary challenge routes can inherit cluster-wide ingress behavio...KubernetesIntermediate12 minProNETWORK-1375A log ingest NGINX location works for normal requests and large client posts...A log ingest NGINX location works for normal requests and large client... focuses on runtime-configuration and asks the reader to isolate the key signal in NGINX. Breaking a server block into includes can silently shrink limits on paths that d...NetworkIntermediate12 minProNETWORK-1416A path-based auth gateway protects the admin UI and one encoded traversal...A path-based auth gateway protects the admin UI and one encoded traversal... focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. URI security bugs often come from normalization order mismatches between layers, not...NetworkIntermediate12 minPro