VIPs, DNS, and a Conntrack Ghost: Post-mortem of an Intermittent Ingress Outage
While building a DNS round robin ingress design for multiple Traefik instances, I accidentally built an asymmetric packet path that my hypervisor firewall interpreted as “INVALID” and quietly dropped. The cluster looked guilty. The underlay did the crime.