k8s/cilium
after months of digging on and off I finally have a working cluster. I am pretty sure no one tests cluster nic + external nic where you can cannot route from node1 to node2external over node1internal.
anyway the fix for now is to disable the host firewall option 😬


