rndc is executed by designate worker to send commands to bind. designate worker is hosted on the internal API network but deployed bind is hosted on the public API network. Due to the asymmetric routing and strict reverse path filtering, this results in rndc calls hanging when a worker tries to execute a command on a bind on another node. This is 100% reproducible with multi-controller deployments.
Closing as a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=2073026. While slightly different, they are the same functional issue (networking issues between rndc and bind instances) *** This bug has been marked as a duplicate of bug 2073026 ***