<a id="co-troubleshooting"></a>

# Troubleshoot Confluent for Kubernetes

Troubleshoot common Confluent for Kubernetes issues and find the diagnostics
tools covered in the following topics.

The examples in this section assume the default namespace you set in
[Create a namespace for CFK](co-prepare.md#co-create-namespace).

## In this section

<span id="co-support-bundle"></span>
<span id="co-support-bundle-create"></span>
<span id="co-sample-support-bundle"></span>
<span id="co-debug"></span>
<span id="co-kraft-mds-ssl-auth"></span>
<span id="co-c3-mds-certificates"></span>
<span id="co-orphaned-resource"></span>
<span id="co-kraft-mds-config-override"></span>
<span id="co-jaas-class-change"></span>
<span id="issue-co-helm-charts-returns-an-image-pull-secret-error"></span>
<span id="issue-co-helm-charts-are-not-found"></span>
<span id="issue-unable-to-install-ak-on-kubernetes-1-23-or-higher-with-aws-ebs"></span>
<span id="issue-an-error-returns-while-applying-a-crd-during-an-upgrade"></span>
<span id="issue-the-co-helm-release-secret-exceeds-the-co-short-secret-size-limit"></span>
<span id="issue-an-error-caused-by-an-extra-semicolon-character-in-the-jaas-configuration"></span>
<span id="issue-kraft-crash-loops-with-an-ssl-authentication-error"></span>
<span id="issue-c3-cannot-use-auto-generated-certificates-for-mds-or-ccloud-sr"></span>
<span id="issue-ksqldb-cannot-use-auto-generated-certificates-for-ccloud"></span>
<span id="issue-error-for-running-sr-with-mismatching-replication-factor"></span>
<span id="issue-errors-with-container-process-and-directory-permissions-when-deploying-cp-6-2-x"></span>
<span id="issue-unable-to-delete-kubernetes-resources"></span>
<span id="issue-confluentrolebindings-stuck-in-deleting"></span>
<span id="issue-kafkatopic-is-stuck-in-deleting-delete-requested-state"></span>
<span id="issue-ak-listeners-cannot-share-the-same-tls-secret-reference"></span>
<span id="issue-i-have-a-storageclass-that-does-not-have-the-reclaimpolicy-set-to-retain"></span>
<span id="issue-co-fails-to-start-up-with-an-error-about-the-clusterlink-cr"></span>
<span id="issue-co-sends-delete-topics-requests-for-auto-mirrored-topics"></span>
<span id="issue-tls-enabled-ksqldb-fails-to-start-with-a-crash-loop"></span>
<span id="issue-unable-to-connect-to-identity-provider-with-self-signed-certificates-when-using-oauth-oidc-authentication-for-ak"></span>
<span id="issue-ak-cluster-id-mismatch-between-ak-kraft-cr-status-and-the-cluster"></span>
<span id="issue-ak-brokers-fail-to-start-when-configuring-oauth-oidc-authentication"></span>
<span id="issue-use-different-authentication-for-internal-and-external-listeners"></span>
<span id="issue-request-create-acls-is-not-authorized-errors-after-kraft-migration"></span>
<span id="issue-oauth-bearer-callback-handler-class-mismatch-error"></span>
<span id="issue-c3-2-0-fails-when-deployed-with-cp-8-0-or-later"></span>
<span id="issue-scale-down-ak-brokers-in-a-multi-rack-availability-zone-deployment"></span>
<span id="issue-authentication-failures-when-using-co-3-0-with-cp-7-x"></span>
<span id="issue-unable-to-download-connectors-using-on-demand-url"></span>
<span id="issue-cluster-link-creation-failed-on-mtls-with-rbac-enabled"></span>
<span id="issue-ak-pods-in-crashloopbackoff-with-the-error-that-no-space-is-left-on-device"></span>
- [Common Deployment Issues](co-troubleshoot-deployment.md#co-troubleshoot-deployment): Resolve common Helm chart and
  Kubernetes issues encountered while deploying CFK.
- [Common Configuration Issues](co-troubleshoot-configuration.md#co-troubleshoot-configuration): Resolve common Confluent Platform component
  configuration issues.
- [Common Upgrade Issues](co-troubleshoot-upgrade.md#co-troubleshoot-upgrade): Resolve issues encountered while upgrading
  CFK or Confluent Platform.
- [Common Migration Issues](co-troubleshoot-migration.md#co-troubleshoot-migration): Resolve issues encountered during ZooKeeper
  to KRaft migration.
- [Common Authentication Issues](co-troubleshoot-authentication.md#co-troubleshoot-authentication): Resolve OAuth/OIDC, SASL, and
  mTLS authentication issues.
- [Common Networking Issues](co-troubleshoot-networking.md#co-troubleshoot-networking): Resolve TLS certificate and listener
  networking issues.
- [Known Issues](co-troubleshoot-known-issues.md#co-troubleshoot-known-issues): Review known issues and their
  workarounds.
- [Support Bundle and Diagnostics](co-troubleshoot-diagnostics.md#co-troubleshoot-diagnostics): Generate a support bundle and collect
  heap dumps, thread dumps, logs, and metrics.
