https://rancher.com/ logo
Title
c

creamy-pencil-82913

04/20/2023, 5:57 AM
Open an issue on GH and attach as much info as possible, I'll ask the CNI guys to take a look
­čĹŹ 1
a

adamant-soccer-4302

04/25/2023, 9:52 PM
I didn't get to opening a ticket, because shortly after this I identified it was tied to net.ipv4.xfrm4_gc_thresh being too low - increase the number, and the pods that were having issues connecting out to another endpoint suddenly started working
we got the error message 'No buffer space available' when trying to connect to remote services over the ipsec network, but it worked over the host network just fine - cilium was reporting the health endpoint on the worker node was healthy, but the overlay network target was unhealthy over the ipsec network
c

creamy-pencil-82913

04/25/2023, 9:58 PM
interesting. thanks for the follow-up!