Troubleshooting guide

curl works. Your Agent still says “connection error”.

Start by reproducing the check from the Agent's actual subprocess, container, or sandbox. A shell success is a different observation and cannot attest to another runtime.

Measure before changing configuration

  1. Run netokay version and preserve its JSON and exit status.
  2. Run one explicit public target from the failing runtime.
  3. Read the Control and target observations, including unknown fields and route limitations.

Do not widen the target, install an unverified artifact, print proxy values, or claim a unique root cause from one service vantage point.