@astrid oh and the worker nodes have to reach the apiserver of course and the apiserver (and maybe other control-plane components, not sure rn) need to reach the worker nodes - so the two connections we have is an IP:Port for apiserver and IP:Port for Konnectivity for the way back - but in your case you could probably just route from control-plane to worker network, but not allow the other way around