An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
Thank you for your patience while we worked closely with the AKS engineering team to investigate this issue.
Based on the investigation conducted by the AKS and AzSecPack engineering teams, the issue has now been isolated and the root cause identified. Although the symptoms appeared as Azure CNI failures with errors such as "Failed to allocate pool: Failed to delegate" and "signal: bus error," the underlying cause was not related to IP exhaustion or networking capacity constraints.
The investigation determined that, under specific timing conditions, a race condition within the AzSecPack CertsInUse component could leave the SymCrypt OpenSSL provider configuration file in an invalid state during node initialization. This subsequently impacted OpenSSL initialization on affected Azure Linux 3 FIPS-enabled nodes and manifested as Azure CNI failures during pod startup.
The engineering team has developed a fix that makes the configuration update process atomic, preventing the configuration file from becoming corrupted even if the process is interrupted. In addition, the Azure Linux team is evaluating further improvements to increase resiliency during the FIPS initialization process.
As a mitigation, the engineering team recommends setting AzSecKeysinuseEngineInstall=False prior to node pool creation until the permanent fix is broadly available. This mitigation has been validated by the product group and is currently considered the preferred workaround.