NinjaOps Fixes
Every page: the error you searched for, why it happens, and the exact commands to fix it. No signup walls, no client-side bloat. Search all 198 fixes
- Cloudflare 522: Connection Timed Out to Your Origin — 522 means Cloudflare TCP-connected nowhere: your origin never answered the handshake.
- Cloudflare 525: SSL Handshake Failed With Origin — You are using Full (strict) mode, and the origin's certificate failed validation.
- Cloudflare 520: Your Origin Returned Something Broken — 520 is Cloudflare shrugging: the origin connected but responded with an invalid/empty reply or crashed the connection.
- Cloudflare 521: Web Server Is Down (Connection Refused) — 521 means Cloudflare reached your origin and it actively refused the connection.
- Cloudflare Error 523: Origin Is Unreachable — 523 means Cloudflare couldn't even open a TCP connection to your origin — DNS points somewhere dead, the origin is down, or a firewall is dropping Cloudflare's IPs.
- Cloudflare Error 524: A Timeout Occurred (Your Origin Is Too Slow) — 524 means Cloudflare connected to your origin, but the response took over 100 seconds (free/pro plans).
- Cloudflare Error 526: Invalid SSL Certificate (Full-Strict Finds a Problem) — 526 fires in Full (strict) mode when your origin's certificate is expired, self-signed, incomplete, or wrong-hostname.
- Cloudflare Error 530 (1016): Origin DNS Error — 530 with code 1016 means Cloudflare tried to resolve your origin's hostname and DNS failed.
- Cloudflare Error 1020: Access Denied (Your WAF Fired on a Real Visitor) — 1020 means a Cloudflare firewall rule matched the request and blocked it — sometimes correctly, sometimes blocking your own users, your monitoring, or your app's own callbacks.
- Cloudflare Error 1101: "Worker Threw a JavaScript Exception" — Your Worker code threw an unhandled exception while handling the request.
- Cloudflare Error 1000: "DNS Points to Prohibited IP" — A Cloudflare-zone DNS record points back at Cloudflare IPs — a loop Cloudflare refuses to proxy.
- Docker Container Exits With Code 137 (OOM Killed) — Exit code 137 means your container received SIGKILL — either the host OOM killer or a cgroup memory limit took it down.
- Docker: 'No Space Left on Device' (and How to Reclaim It Safely) — Docker eats disk via dangling images, dead containers, and unbounded log files.
- Docker Compose Containers Can't Reach Each Other — Compose services talk over a shared network using service names as hostnames.
- Docker: 'Permission Denied While Trying to Connect to the Docker Daemon Socket' — Your user can sudo but can't talk to the Docker daemon without it.
- Docker: 'Bind: Address Already in Use' — Something is already listening on the host port you published.
- Docker Container Exits Right After Starting — The container starts, runs for a second, and dies with no obvious error.
- Docker Compose: depends_on Doesn't Wait for "Ready" — Healthcheck Ordering — Plain depends_on only orders container START, not readiness — the DB starts before your app and still refuses connections.
- Docker: "exec /bin/sh: Exec Format Error" — Wrong Architecture Image — The image's CPU architecture doesn't match the host: amd64 image pulled on an ARM64 machine (or the reverse).
- "Cannot connect to the Docker daemon" — Daemon Down or Permissions — The CLI can't reach dockerd: either the daemon isn't running, your user lacks socket access, or the DOCKER_HOST points somewhere wrong.
- Docker Network Errors: "Endpoint Already Exists" / Sandboxes Left Behind — Docker's per-network bookkeeping gets stuck after failed restarts: containers half-exist in the network sandbox.
- Docker: "Driver Failed Programming External Connectivity on Endpoint" — Docker couldn't wire up the port publish when starting the container: usually the port is taken, iptables is in a bad state, or a stale endpoint from a previous run blocks the name.
- Dockerfile "COPY Failed: File Not Found" — Context, Not Paths — COPY/ADD can't find the file because Docker resolves paths against the build context, not the Dockerfile's directory or your shell's cwd.
- Docker Compose Ignoring Your Environment Variables — Three different mechanisms pass env vars (interpolation, .
- docker push: "Requested Access to the Resource Is Denied" — You're authenticated, but as the wrong user or against the wrong repo path.
- Docker Compose: "Network Has Active Endpoints" — Force-Minus-Danger — Compose won't remove a network while containers (including orphans from other projects) still use it.
- Docker: "Conflict. The Container Name Is Already in Use" — A stopped (or running) container already holds the name — names are unique regardless of state.
- Docker Compose: "The Variable Is Not Set. Defaulting to a Blank String" — Compose warns when ${VAR} in the YAML has no value, then substitutes empty — which surfaces later as a broken image name, empty password, or skipped config.
- Docker: "Pull Access Denied" — Registry Auth, Names, and Rate Limits — The registry refused the pull: not authenticated, the image name is wrong (the classic missing namespace), or the Hub rate limit hit.
- Git: "Your Local Changes to the Following Files Would Be Overwritten" — The operation would stomp uncommitted changes in the affected files.
- git clone: "fatal: Early EOF" — Large Repos and Flaky Networks — The transfer died mid-packfile: usually a network drop or a server-side cutoff on a huge clone.
- Git: "error: gpg Failed to Sign the Data" (Signed Commits) — Git asked GPG to sign and it refused: no secret key (or expired), GPG can't reach the agent/TTY for the passphrase, or the terminal environment broke after a config change.
- Git Says "You Are in 'Detached HEAD' State" — Detached HEAD means you checked out a commit instead of a branch — new commits can be lost.
- Git Push Rejected: "Non-fast-forward" / "Fetch First" — The remote has commits you don't have locally.
- Resolving Git Merge Conflicts Without Breaking History — A conflict means two branches changed the same lines.
- Git: "Another Git Process Seems to Be Running" (index.lock) — A crashed or still-running Git command leaves .
- ".gitignore Isn't Working" — Because the Files Are Already Tracked — gitignore only prevents *untracked* files from being added.
- Git: "Refusing to Merge Unrelated Histories" — The two branches share no common ancestor — GitHub-created repos with a seed commit vs your local repo, or a repo re-initialized from scratch.
- git clone: "Permission denied (publickey)" — GitHub/GitLab Rejects Your Key — The remote asked for SSH auth and your key didn't work: not loaded, wrong key on the account, or sshd config quirks.
- git push: "Pre-receive Hook Declined" — Branch Protection Talking — The server's pre-receive hook (usually branch protection) rejected the push.
- Git: "fatal: Not a Git Repository (or Any of the Parent Directories)" — Git walked up the directory tree and found no .
- Git Rebase Conflict: Continue, Skip, Abort — Choosing Correctly — A rebase stops at each conflicting commit.
- Git: fatal: Detected Dubous Ownership (Safe Directory) — Since CVE-2022-24765, git refuses to operate when the repo owner differs from the current user — classic in containers, WSL, and shared mounts.
- Kubernetes Pod Stuck in CrashLoopBackOff — CrashLoopBackOff is not the error — it is Kubernetes giving up on restarting a container that keeps dying.
- Kubernetes Pod Stuck in ImagePullBackOff — The kubelet cannot pull your container image.
- kubectl: 'Connection Refused' on Port 6443 — kubectl cannot reach the API server.
- Kubernetes Pod Stuck in Pending (Nothing Is Wrong With It) — Pending means the scheduler cannot find a home for the pod.
- Kubernetes Ingress Returns 404 for Everything — The controller is up and answering — that is why you get a tidy 404.
- Kubernetes Node Stuck in NotReady — The API server remembers the node, but kubelet stopped reporting.
- Kubernetes Service Gives 'Connection Refused' to a Live Pod — Your app pod is Running and the Service exists — but connections refuse.
- Helm Release Stuck in 'pending-upgrade' — A failed upgrade left the release in limbo and Helm refuses to continue.
- Kubernetes: Weird TLS/Cert Errors Everywhere (Check the Clock) — Expired-looking x509 errors, 'token invalid', or nodes failing to join with intact certs is the classic symptom of clock skew.
- kubectl Returns 401 Unauthorized — The API server rejected your credential — expired token, stale kubeconfig, or a certificate issue.
- Kubernetes PVC Stuck in Pending — A PersistentVolumeClaim that never binds means no StorageClass default, a provisioning gap, or a topology conflict.
- Kubernetes: "Volume Node Affinity Conflict" (PVC Zone Pinning) — A PersistentVolumeClaim exists in one availability zone; the scheduler can only put pods on nodes in that zone.
- Pod Pending: "0/1 nodes are available: 1 node(s) had untolerated taint" — The scheduler found a node but refuses to use it: the node carries a taint your pod doesn't tolerate.
- Pod Pending: "Insufficient memory" — Requests, Node Pressure, or Limits Lie — The scheduler skips nodes that lack free memory for your pod's *request*.
- kubectl "Context Deadline Exceeded" — API Server Too Slow or Unreachable — kubectl gave up waiting on the API server.
- Kubernetes Pods Can't Resolve Service Names (CoreDNS/ndots Debug) — nslookup works for external names but service-name lookups fail — or everything DNS is flaky.
- Kubernetes ConfigMap Changed but Pods Don't See It — Volume-mounted ConfigMaps update (slowly, and only for some subPath cases); envFrom/Env vars NEVER update.
- Kubernetes Ingress 502 / "Connection Refused by Upstream" — Service Chain Debug — Ingress → Service → Endpoints → Pod: a 502 means the chain broke at one link.
- kubectl: "No Configuration Has Been Provided" — Kubeconfig Absent or Broken — kubectl can't find a kubeconfig with a current context: file missing, KUBECONFIG pointing nowhere, or context deleted.
- Kubernetes Evicting Pods: Node Under Memory/Disk Pressure — The kubelet evicts pods when a node runs low on memory or disk.
- kubectl: "x509: Certificate Signed by Unknown Authority" — kubectl doesn't trust the API server's certificate authority.
- SSH: 'Permission Denied (publickey)' — The server rejected your key.
- Cron Job 'Installed' but Never Runs — Cron failures are boringly consistent: PATH differences, silent script errors, or the crontab you think is installed isn't.
- systemd Service Keeps Failing: Reading the Actual Error — Do not guess from status alone — journalctl for the unit has the exact stack trace or exit code.
- Disk 'Full' But df Shows Free Space (Inode Exhaustion) — Storage has two limits: bytes and inode counts.
- apt: 'Could Not Get Lock /var/lib/dpkg/lock-frontend' — Another apt/dpkg process is mid-run — usually unattended-upgrades doing its job.
- SSH Connection Times Out (Hanging Before Auth) — A hang then 'Connection timed out' means packets are being silently dropped — firewall, wrong IP, or nothing listening.
- Find Which Process Is Using a Port (Linux) — The fastest reliable answer on a modern Linux is one ss command — here's the exact invocation, plus why netstat output misleads people.
- make: "No Rule to Make Target" — Missing Files and Missing Prerequisites — make can't find (or infer) a rule to build a requested target.
- "bash: command not found" — PATH, Packages, and the Right Name — The shell searched every PATH directory and didn't find an executable by that name.
- systemd: "Start Request Repeated Too Quickly" (and Failed Units) — The unit crashed, systemd backed off, and now start attempts hit the rate limiter — masking the original failure.
- "Too many open files" — ulimit, systemd, and Container Limits — Each process has an open-file-descriptor ceiling.
- The Linux OOM Killer Is Taking Out Your Services — When memory (plus swap) is exhausted, the kernel kills the highest badness-scored process.
- Adding Swap on Linux Without a Reinstall (the 4-Command Version) — A 2–4GB swap file takes four commands and gives your server a memory cushion.
- Logrotate Isn't Rotating — Logs Grow Forever — Silent log growth fills disks at 3am.
- /var/log/journal Consuming Gigabytes: Cap journald For Real — systemd-journald grows logs until told to stop.
- Server Load Is High — Find What's Actually Causing It — High load means runnable tasks are waiting.
- "<User> is not in the sudoers file. This incident will be reported." — Your account lacks sudo rights (or lost them).
- "Read-only file system" — The Disk or the Kernel Lost Trust — A filesystem going read-only is usually the kernel protecting data after I/O errors — or a deliberately read-only mount.
- "Target is Busy" / "Device or Resource Busy" When Unmounting — Something is using the mount: a process with open files, a shell cd'd into it, or a container with a bind mount.
- apt: "Unable to locate package" — Sources, Spelling, or Release — apt can't find the package in any configured repository.
- systemd "Failed to start: Unit not found" — Name, Path, or [Install] — The unit you referenced doesn't exist as systemd sees it — typo, missing file, or an unreadable path.
- Linux "Operation Not Permitted" — Capability or Namespace Limits — Distinct from 'Permission denied': EPERM means the operation itself is disallowed for your process — lacking a capability, restricted by seccomp/AppArmor, or namespaced away in containers.
- Bash "Syntax Error Near Unexpected Token" — and the Windows Line-Ending Trap — Bash rejects the script at parse time.
- "passwd: Authentication Token Manipulation Error" — PAM couldn't complete the password change: shadow file locked, read-only filesystem, or a module in the chain failing.
- "Cannot Allocate Memory" at fork — With Free RAM: pids.max and overcommit — fork() fails EAGAIN when the process hits a limit that isn't RAM: the pids cgroup ceiling (common in containers) or overcommit accounting.
- "sudo: No TTY Present and No Askpass Program Specified" — sudo needs a password but has no terminal to ask on — cron, CI, and scripts.
- "Segmentation Fault (Core Dumped)" — A Practical Diagnosis Order — Segfaults mean a process touched memory it shouldn't.
- "Error While Loading Shared Libraries: Cannot Open Shared Object File" — The binary wants a library the loader can't find: missing package, wrong arch, or a non-standard install dir that needs ldconfig.
- "Exec Format Error" — Wrong Architecture or Corrupt Binary — The kernel can't execute the file: it's the wrong arch (ARM vs x86), a glibc/musl mismatch variant, or the file isn't actually a binary.
- "No Route to Host" — Networking's Different Beast from Connection Refused — The host is reachable at the IP layer but nothing accepts or passes your connection: a REJECT firewall rule (as opposed to DROP's timeout), a bad route, or a down host in a routed setup.
- bash: /bin/bash^M: Bad Interpreter — Windows Line Endings — A script saved with Windows CRLF line endings embeds a literal carriage return in the shebang: the kernel looks for /bin/bash^M, which doesn't exist.
- bash: fork: retry: Resource Temporarily Unavailable — The kernel refused to create a new process: nproc limit (RLIMIT_NPROC) or the system's pid_max is exhausted.
- systemd: Failed to Start — Unit File Changed on Disk / Not Found — Two variants with one remedy family: a unit genuinely missing, or the manager holding stale state after you edited/installed a unit.
- Python UnicodeDecodeError: 'utf-8' Codec Can't Decode — The Encoding Truth — You read bytes as UTF-8 and they aren't.
- pip error: externally-managed-environment (PEP 668) — Debian 12+, Ubuntu 23.
- ModuleNotFoundError: No Module Named X — Interpreter and Path Mismatch — The module is probably installed — just not for the interpreter you're running, or not on sys.
- Python "ssl.SSLCertVerificationError: unable to get local issuer certificate" — Python can't verify the server's chain: missing intermediate on the server, outdated certifi bundle, or a corporate proxy re-signing traffic.
- Python "ImportError: cannot import name" — Circular Imports and Shadowing — The module imported, but the name you asked for isn't there yet — circular imports are the headline cause, followed by stale bytecode, shadowing a stdlib/package name, and version drift.
- pip: "Could Not Find a Version That Satisfies the Requirement" — pip couldn't find ANY version of that package for your interpreter.
- Python ModuleNotFoundError: The Path, The Name, or The Environment — ModuleNotFoundError means Python looked in sys.
- pip: "Can't Connect to HTTPS URL because the SSL Module Is Not Available" — Your Python was built without working OpenSSL bindings — typical for source builds, pyenv on newer distros, or an interpreter built against a dev package that isn't installed.