We are investigating intermittent connectivity from existing hkg1 Node.js 22 Functions to the public HTTPS endpoint green-cip.cn-shanghai.aliyuncs.com:443.
In one protected diagnostic deployment on 2026-10-09 around 23:19 UTC, an unsigned GET completed DNS, TCP and certificate-validated TLS and returned HTTP 404 in about 0.37 seconds. In another around 23:21 UTC, an unsigned GET and a fresh Node https POST with agent:false resolved the same destination address but did not complete TCP or TLS within their bounded 12- and 15-second measurements. The application fetch recorded UND_ERR_CONNECT_TIMEOUT. An independent control HTTPS endpoint responded in the failing invocation.
There was no failed vendor HTTP response or RequestId, and no user photos were sent. A Singapore comparison had an isolated success followed by failures, so changing region is not a verified correction. Diagnostic deployments have been removed and production networking remains unchanged.
We have supplied private measurements to the vendor and the Vercel support assistant. On our Hobby account, the support form does not allow a case under Vercel Functions or Secure Compute & Static IPs. Can a Vercel team member advise how to investigate destination-specific egress routing or filtering, and what minimal evidence should be collected after a concrete correction? We are not asking to bypass certificate validation or image moderation.
These are application observations, not packet captures. We have not established the actual source NAT address/port used toward the failed destination or identified the responsible network.