Name: envoy-gateway-gateway-helm-certgen-2q9gh Namespace: envoy-gateway-system Priority: 0 Service Account: envoy-gateway-gateway-helm-certgen Node: controller/199.204.45.23 Start Time: Mon, 30 Mar 2026 20:47:19 +0000 Labels: app=certgen batch.kubernetes.io/controller-uid=9455db61-287d-4af7-9a60-5c7e45c58955 batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen controller-uid=9455db61-287d-4af7-9a60-5c7e45c58955 job-name=envoy-gateway-gateway-helm-certgen Annotations: Status: Succeeded IP: 172.24.0.18 IPs: IP: 172.24.0.18 Controlled By: Job/envoy-gateway-gateway-helm-certgen Containers: envoy-gateway-certgen: Container ID: containerd://f5ee06e28e3e7f54bcdcf1e55b129f71d39bbde3e21eabd207183912b98f74e2 Image: docker.io/envoyproxy/gateway:v1.7.0 Image ID: docker.io/envoyproxy/gateway@sha256:66bfa45b557aeb086223064261d51dfb983fe962f35f821f8135e67e1b1a981f Port: Host Port: SeccompProfile: RuntimeDefault Command: envoy-gateway certgen State: Terminated Reason: Completed Exit Code: 0 Started: Mon, 30 Mar 2026 20:48:13 +0000 Finished: Mon, 30 Mar 2026 20:48:13 +0000 Ready: False Restart Count: 0 Environment: ENVOY_GATEWAY_NAMESPACE: envoy-gateway-system (v1:metadata.namespace) KUBERNETES_CLUSTER_DOMAIN: cluster.local Mounts: /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-gc5dq (ro) Conditions: Type Status PodReadyToStartContainers False Initialized True Ready False ContainersReady False PodScheduled True Volumes: kube-api-access-gc5dq: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt Optional: false DownwardAPI: true QoS Class: BestEffort Node-Selectors: Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Warning FailedScheduling 5m17s default-scheduler 0/1 nodes are available: 1 node(s) had untolerated taint {node.kubernetes.io/not-ready: }. no new claims to deallocate, preemption: 0/1 nodes are available: 1 Preemption is not helpful for scheduling. Normal Scheduled 65s default-scheduler Successfully assigned envoy-gateway-system/envoy-gateway-gateway-helm-certgen-2q9gh to controller Warning FailedCreatePodSandBox 30s kubelet Failed to create pod sandbox: rpc error: code = Unknown desc = failed to setup network for sandbox "eaf944301f49a228b5f6669b0fbb9f9611220ae73f2678bbf89cb1525cee150c": plugin type="cilium-cni" failed (add): unable to connect to Cilium daemon: failed to create cilium agent client after 30.000000 seconds timeout: Get "http://localhost/v1/config": dial unix /var/run/cilium/cilium.sock: connect: no such file or directory Is the agent running? Normal Pulling 14s kubelet Pulling image "docker.io/envoyproxy/gateway:v1.7.0" Normal Pulled 11s kubelet Successfully pulled image "docker.io/envoyproxy/gateway:v1.7.0" in 2.942s (2.942s including waiting). Image size: 73032550 bytes. Normal Created 11s kubelet Created container: envoy-gateway-certgen Normal Started 11s kubelet Started container envoy-gateway-certgen