Architecture
The student examines the broken architecture diagram and identifies the responsible component. The cluster is running Ceph Tentacle (20.2.x); the incident is one a production operator must diagnose from the evidence presented.
Symptoms
- S3 client receives AccessDenied on a valid request
- Other RGW users can access the same bucket
- radosgw-admin log show lists the access denied errors
Evidence
- radosgw-admin user info shows the user has caps but no bucket policy
- radosgw-admin bucket list —uid=<user> confirms the bucket exists
- radosgw-admin zone get shows the data pool is healthy
Student investigation
The student follows the methodology: define the symptom, determine the impact, gather evidence, identify the component, form a hypothesis, test safely, restore, validate.
Progressive hints
- Hint 1: check the cluster state with
ceph -sfirst. - Hint 2: read
ceph health detailand identify the affected PGs / OSDs / daemons. - Hint 3: use
ceph osd tree,ceph pg dump, orceph mds statas the next-level diagnostic. - Hint 4: the root cause is documented in the frontmatter
root_causefield.
Validation
The student runs the verification steps and confirms the symptom cleared.
Root cause
See the frontmatter root_cause field.
Remediation
Apply the fix from the frontmatter remediation field.
Prevention
Apply the prevention measures from the frontmatter prevention field.