As a test, I added a rule to the node security group to allow all traffic from anywhere on all ports, added another rule to allow traffic from the control plane security group to access to all ports (redundant) and put in similar rules to in the control plane security group to allow the node security group to communicate on all ports. I redeploy the rancher-monitoring chart, but no success.