With https://github.com/ubicloud/ubicloud/pull/2036 we started to apply firewall rules to the in subnet communication as well. This impacts PG because the primary <-> standby communication is through private networking. Therefore, we are adding explicit rules to allow the full subnet range on port 5432 by default.