Use Cases
Software Products MSPs Schools Development & Marketing DevOps Agencies Help Desk
 
Internet Status Blog Pricing Log In Try IsDown for free now

Outage in Firezone Production

Gateways failure to reconnect to control plane API

Resolved Minor
December 23, 2025 - Started about 2 months ago - Lasted 2 days
Official incident page

Incident Report

At December 23, 3:50 PM UTC, we rolled a minor fix to our Entra authentication adapter out to production. Deploys to production are generally considered safe and are designed not to cause any packet loss or downtime for customers. Shortly after, at December 23, 4:10 PM UTC, we noticed a discrepancy in the number of nodes that successfully rejoined their control "channels" - that is, the message channel clients/gateways use to receive connection intents and configuration updates. These channels are separate from the actual WebSocket transport underlying them. The discrepancy here looks to have been very small, in the single-digit % of nodes. Upon noticing this discrepancy, we restarted API node services on each affected API node to trigger a full reset of the control plane WebSocket for these nodes. At or around December 23, 4:50 PM, UTC we verified all nodes were successfully reconnected, restoring full functionality.

Need to monitor Firezone Production outages?

  • Monitor all your external dependencies in one place
  • Get instant alerts when outages are detected
  • Be the first to know if service is down
  • Show real-time status on private or public status page
  • Keep your team informed
Latest Updates ( sorted recent to last )
RESOLVED about 2 months ago - at 12/25/2025 01:04PM

At December 23, 3:50 PM UTC, we rolled a minor fix to our Entra authentication adapter out to production. Deploys to production are generally considered safe and are designed not to cause any packet loss or downtime for customers.

Shortly after, at December 23, 4:10 PM UTC, we noticed a discrepancy in the number of nodes that successfully rejoined their control "channels" - that is, the message channel clients/gateways use to receive connection intents and configuration updates. These channels are separate from the actual WebSocket transport underlying them. The discrepancy here looks to have been very small, in the single-digit % of nodes.

Upon noticing this discrepancy, we restarted API node services on each affected API node to trigger a full reset of the control plane WebSocket for these nodes.

At or around December 23, 4:50 PM, UTC we verified all nodes were successfully reconnected, restoring full functionality.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 5850 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook