Coinbase Reviews July 14 Outage: Shared-Cluster Configuration Collision Caused About 50 Minutes of Degradation
Coinbase says a routine configuration update unintentionally changed Istio ingress-gateway resources in a shared Kubernetes cluster, pausing workflows across several platforms. This review restores the timeline, customer effects, recovery constraints, and proposed fixes; two other blog posts in the captured batch are unrelated.
Coinbase's July 21 postmortem says a routine change deployed at 12:34 PM ET on July 14 caused a resource-name collision that unintentionally affected the Istio ingress gateway in a shared production Kubernetes cluster. At 12:37 PM ET, inbound traffic to the cluster stopped. Some transfers, card functions, onchain services, Exchange, Prime, and developer-platform workflows failed, were delayed, or paused. The gateway was restored at 1:20 PM ET and the incident was mitigated at 1:23 PM. Coinbase describes roughly 50 minutes of degradation through about 1:25 PM, with remaining queues processing for several more hours, and says customer funds were not at risk.
Key facts
- At 12:34 PM ET on July 14, 2026, Coinbase deployed a routine configuration change; pre-production checks did not detect a resource-name collision.
- The change unintentionally modified resources associated with the Istio ingress gateway in a shared production Kubernetes cluster, and all inbound traffic stopped at 12:37 PM ET.
- Affected functions included retail off-platform trades and deposits or withdrawals, card transactions and management, Base and Solana DEX swaps, Exchange and Prime transfers and settlement, and developer-platform funding and onramp workflows.
- The gateway was restored at 1:20 PM ET and the incident was mitigated at 1:23 PM; the notice summarizes the main degraded state as approximately 50 minutes.
- Most services caught up soon after restoration, while remaining backlogs completed over the following hours; some in-flight transactions appeared stuck rather than failed.
- Coinbase says customer funds were not at risk during the incident; that statement comes from the platform's own postmortem.
- A fake-IRS scam alert and a post-quantum cryptography article captured in the same batch are not evidence for this outage and are excluded from the incident conclusions.
Key timeline
A routine configuration change was deployed to the shared production Kubernetes cluster.
Inbound traffic to the affected cluster stopped and asynchronous workflows paused.
The Istio ingress gateway service was restored.
Coinbase marked the incident mitigated.
The stated main customer-impact interval ended while queued work continued.
Coinbase published the incident postmortem.
Who may be affected
- Customers using Coinbase retail off-platform trading, deposits, or withdrawals during the incident
- Customers using Coinbase Card or DEX swaps on Base or Solana
- Coinbase Exchange and Prime customers with failed or delayed transfers and settlement
- Coinbase Developer Platform customers using onboarding, fund movement, or onramp services
Impact analysis
The direct failure point was a shared infrastructure ingress gateway rather than one trading product. Several customer platforms depended on the same network entry and asynchronous workflow layer, so one configuration collision affected settlement, transfers, card authorization, and onchain services together. Recovery was also slowed by a circular dependency: standard deployment tooling depended on the unavailable gateway, requiring engineers to invoke a cloud-provider rollback through a just-in-time privileged break-glass path. Coinbase's proposed work includes detecting Kubernetes resource-name collisions, separating deployment tooling from managed infrastructure, and regularly exercising emergency access. These are future actions; the postmortem alone does not prove completion or prevent recurrence.
What the announcement does not say
The postmortem gives no affected-user count, regional impact split, complete transaction count, independent third-party forensic review, or completion dates for each corrective action. This article also cannot independently verify the statement that funds were not at risk. The two other captured posts are unrelated and do not increase the evidentiary strength of the incident report.
Risk notes
- A mitigated historical incident does not show that future configuration, network, or shared-infrastructure failures cannot recur.
- Transfers or onchain operations may appear delayed or stuck during an outage; users should avoid duplicate submission until status is verified.
- The postmortem and funds-not-at-risk statement are self-published by Coinbase and are not treated here as an independent audit.
- Corrective actions are stated commitments and design directions whose completion requires later engineering or status evidence.
- This article summarizes official incident information and is not advice about choosing an exchange, holding assets, or trading.
This article is for information only and is not investment, legal, or tax advice. Digital assets are volatile and may result in loss of principal.
Frequently asked questions
How long did the disruption last?
Coinbase describes about 50 minutes of degradation: traffic stopped at 12:37 PM ET, the gateway returned at 1:20 PM, mitigation followed at 1:23 PM, and the main customer-impact window ended around 1:25 PM. Remaining queues took several more hours.
What directly caused the incident?
Coinbase says a routine configuration change created a Kubernetes resource-name collision and unintentionally modified the shared cluster's Istio ingress gateway. Pre-production checks did not identify the collision.
Which services were affected?
The source lists retail off-platform trading and deposits or withdrawals, Coinbase Card, Base and Solana DEX swaps, Exchange and Prime transfers and settlement, plus developer-platform onboarding, funding, and onramp services.
Are the other two Coinbase sources related to the outage?
No. The fake-IRS scam alert and post-quantum cryptography article were other posts captured in the same batch. This review explicitly excludes them from evidence for the July 14 incident.
Official sources
Collected material is used only for fact checking. If this page differs from the original announcement, the official page controls.
已逐項對照 Coinbase 7 月 14 日事故復盤,核對 ET 時間線、共享 Kubernetes 與 Istio 故障點、受影響服務、復原依賴和改進承諾;證據鏈只保留該事故來源,另兩篇無關且未標日期的博客已從文章來源移除。 審核人 coin.t0ols.com 於 2026-07-29T15:09:26.956Z 明確同意公開此版本。