Kubernetes Advanced About 30 min +250 XP

Ledger Deployer Is Forbidden to Patch

The payments deploy job's service account gets Forbidden on every Deployment patch, so the ledger change it carries cannot roll out.

Stage 4 of 4 in Breach Response.

Briefing

The breach response is on its last stage: every automation account was re-provisioned from the new access review, and the payments deploy job is the first to run since.

It can read and list its Deployment, but the rollout step fails with Forbidden when it applies the image change, and the ledger change it carries is stuck.

The job's service account and RoleBinding both exist and look correct at a glance.

With the clock running, Sam has offered to bind the account to cluster-admin just for tonight and scope it down in the morning.

The fix is yours to find: hints, the recovery checks and the debrief unlock inside the incident.

How it plays

  1. 01

    Get paged

    The alert fires and the clock starts. Read the page and the briefing.

  2. 02

    Investigate

    Work in a simulated shell with realistic output: logs, configs, services.

  3. 03

    Fix it

    Change the system the way you would in production. Hints are there if you get stuck.

  4. 04

    Prove it

    Automated checks verify the recovery, then the debrief explains what happened.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.