Requests hang for exactly five seconds sometimes.
A five second hang is almost always a DNS timeout, often IPv6 lookups failing before the IPv4 retry. Check with dig +trace and compare getent hosts to a direct query. In containers the usual culprit is a search domain list that turns one lookup into five.
An old device cannot connect since we tightened TLS.
Check the cipher suite overlap first:
openssl s_client -connect example.com:443 -tls1_2 -servername example.com
The honest answer is often that the device cannot be supported without weakening security for everyone, which is a decision to make explicitly rather than by config drift.
Large responses hang while small ones work.
Classic MTU or path MTU discovery failure, usually with a tunnel in the path. Test by lowering the MTU on one side and retrying; if it fixes it, the real problem is ICMP being blocked somewhere, which is what breaks discovery.
