* Whitelist internal traffic between controllers and workers * Switch to tag-based firewall policies rather than source IP
* Calico on GCE with IP-in-IP encapsulation and MTU 1440 * Calico on DO with IP-in-IP encapsulation and MTU 1440 * Digital Ocean firewalls don't support IPIP protocol yet