Failed to create pod sandbox: plugin type="calico" failed (add): ... (FailedCreatePodSandBox)
The kubelet couldn’t set up the pod’s network sandbox — almost always a CNI plugin problem or exhausted pod IPs.
Seen on:
Kubernetes
Meaning
Before containers start, the runtime creates a sandbox and asks the CNI (Calico, Cilium, Flannel, AWS VPC CNI) for an IP. Failures: CNI pods down, IP pool or ENI/subnet exhausted (EKS “failed to assign an IP address to container”), or stale CNI config.
Common causes
- CNI daemonset pod not running on the node
- IP address pool / subnet exhausted (EKS VPC CNI)
- CNI config/version mismatch after upgrade
- Node-level issue (iptables, kernel modules)
⚡ Quick fix
- Check CNI pods on that node
- On EKS check free IPs in the subnet and the max-pods per instance
- Restart the CNI pod / drain and replace the node
Detailed fix by platform
Kubernetes
- bash
kubectl get pods -n kube-system -o wide | grep -E 'calico|cilium|aws-node|flannel' kubectl describe pod web-0 | grep -A3 FailedCreatePodSandBox
How to diagnose
- CNI — Pod healthy on that node?
- IPs — Subnet free IPs, max pods
- Node — Only one node affected?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- actively refused it HttpRequestException: No connection could be made because the target machine actively refused it (localhost:5001)
- CannotPullContainerError ECS task stopped: CannotPullContainerError: pull image manifest has been retried ... / ref pull has been retried
- default backend - 404 Ingress returns "404 Not Found" / "default backend - 404" (ingress-nginx)
Most viewed in Kubernetes
- error converting YAML to JSON error converting YAML to JSON: yaml: line 12: did not find expected key
- is waiting to start Error from server (BadRequest): container "x" in pod "y" is waiting to start: ContainerCreating
- kubectl connection refused kubectl: The connection to the server localhost:8080 was refused — did you specify the right host or port?
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026