subctl diagnose command has been enhanced to check for potential firewall issues that may be blocking ESP traffic and will provide an appropriate error message.publishNotReadyAddresses flag on the service.podCIDR is exclusively used for single-node deployments.