NGINX
274 incident problems in NGINX environments.
먼저 읽을 가이드
추천 문제
All problems (274)
NETWORK-1495An NGINX ingress proxy serves HTTP/2 correctly and one backend still sees plain HTTPA migrated backend still receives HTTP on one path after the rest of the platform has moved to HTTPS upstreams.NetworkAdvanced11 minProNETWORK-1505An NGINX upstream migration enables TLS and one backend still sees HTTPA migrated backend still receives HTTP on one path after the rest of the platform moves to HTTPS upstreams.NetworkAdvanced11 minProCICD-1544An OCI mirror serves the new image and signature verification still failsSignature verification fails only through one mirror tier after edge caching is enabled.CI/CDAdvanced11 minProNETWORK-1515An upstream TLS migration succeeds and one backend still receives HTTPA migrated backend still receives HTTP on one path after the platform moves to HTTPS upstreams.NetworkAdvanced11 minProNETWORK-1525An upstream TLS migration succeeds and one backend still receives HTTPA migrated backend still receives HTTP on one path after moving to HTTPS upstreams.NetworkAdvanced11 minProSECURITY-1366A ban pipeline targets the proxy instead of the attackerA reverse proxy is inserted or reconfigured and automated bans later start punishing the proxy instead of abusive clients.SecurityIntermediate12 minProCICD-1494A BuildKit cache import looks healthy and one branch still cold-buildsA branch-based build farm loses cache hits only behind one internal registry proxy after HTTP optimization changes.CI/CDAdvanced12 minProCICD-1502A BuildKit cache import works on one runner group and misses on anotherOnly one runner group cold-builds after a proxy redirect optimization in front of the registry.CI/CDAdvanced12 minProSECURITY-1481A Keycloak login works and one app still loopsOIDC login loops only for one app after proxy host rewrites were centralized.SecurityAdvanced12 minProCICD-1540A registry cleanup deletes a layer and one release job still fetches itA deleted OCI layer remains fetchable only through one edge cache after cleanup.CI/CDAdvanced12 minProCICD-1530A registry cleanup deletes an image layer and one release job still fetches itA deleted OCI layer remains fetchable only through one edge cache after cleanup.CI/CDAdvanced12 minProCICD-1560A registry retention rule deletes untagged blobs and one build still succeedsA stale build works only through one proxy after registry retention cleanup.CI/CDAdvanced12 minProNETWORK-1460A segmented campus path works for HTTP and breaks WebSocketsA segmented campus path works for HTTP and breaks WebSockets focuses on edge-routing and asks the reader to isolate the key signal in NGINX. Proxy behavior for upgrade headers can change by negotiated protocol branch, not only by route.NetworkAdvanced12 minProCICD-1520An OCI registry cleanup finishes and one release job still pulls a deleted layerA deleted OCI layer remains fetchable only through one proxy tier after cleanup.CI/CDAdvanced12 minProSECURITY-1362An OpenSearch dashboards login loops after proxy hardeningA reverse proxy is hardened and later users start bouncing between the IdP and dashboards without ever reaching an authenticated session.SecurityIntermediate12 minProSECURITY-1356A Fail2ban or CrowdSec pipeline bans the proxy IPA reverse proxy is inserted and automated bans later begin targeting the proxy instead of the actual abusive clients.SecurityIntermediate13 minProSECURITY-1414A hardened proxy blocks normal admin verbs and one legacy WebDAV endpoint...A hardened proxy blocks normal admin verbs and one legacy WebDAV endpoint... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can escape security controls when named locations do n...SecurityAdvanced13 minProSECURITY-1424A hardened proxy blocks normal admin verbs and one legacy WebDAV path still...A hardened proxy blocks normal admin verbs and one legacy WebDAV path still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass controls when named locations do not inher...SecurityAdvanced13 minProSECURITY-1444A hardened proxy protects the main admin route and an internal DAV alias still permits writesA proxy looks hardened and a legacy authoring endpoint still accepts writes through one alias path.SecurityAdvanced13 minProSECURITY-1434A hardened proxy protects the main admin route and an internal DAV alias...A hardened proxy protects the main admin route and an internal DAV alias... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass expected auth when named locations do not inhe...SecurityAdvanced13 minPro