Some checks failed
validate / lint (push) Failing after 1s
host_vars/gpu-node.yaml's ufw_allowed_ports has overridden (not extended) the common role's default list since the node was added, silently dropping the Flannel VXLAN (8472/udp), K3s API (6443/tcp), and Kubelet (10250/tcp) rules every other node gets. Went unnoticed because kubectl logs/exec/stats tunnel through the agent's outbound connection to the k3s server rather than needing a direct inbound path - but real pod dataplane traffic (e.g. tts-gateway on nik-gpu resolving DNS against CoreDNS on nik-debian) needs actual VXLAN connectivity and was blackholing. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>