FailedCreatePodSandBox ☸️ Kubernetes

Failed to create pod sandbox: plugin type="calico" failed (add): ... (FailedCreatePodSandBox)

The kubelet couldn’t set up the pod’s network sandbox — almost always a CNI plugin problem or exhausted pod IPs.

Seen on: Kubernetes

Meaning

Before containers start, the runtime creates a sandbox and asks the CNI (Calico, Cilium, Flannel, AWS VPC CNI) for an IP. Failures: CNI pods down, IP pool or ENI/subnet exhausted (EKS “failed to assign an IP address to container”), or stale CNI config.

Common causes

  • CNI daemonset pod not running on the node
  • IP address pool / subnet exhausted (EKS VPC CNI)
  • CNI config/version mismatch after upgrade
  • Node-level issue (iptables, kernel modules)

⚡ Quick fix

  1. Check CNI pods on that node
  2. On EKS check free IPs in the subnet and the max-pods per instance
  3. Restart the CNI pod / drain and replace the node

Detailed fix by platform

Kubernetes

  1. bash
    kubectl get pods -n kube-system -o wide | grep -E 'calico|cilium|aws-node|flannel'
    kubectl describe pod web-0 | grep -A3 FailedCreatePodSandBox

How to diagnose

  1. CNI — Pod healthy on that node?
  2. IPs — Subnet free IPs, max pods
  3. Node — Only one node affected?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.