This is because even though your container may be up and the kernel will forward traffic to your container, your application might not be ready yet. When your container is flagged as inactive, we add your container’s port to the redirect set which causes TCP traffic destined for your container’s port to be sent to the socket activation server. Socket Activation process receiving redirected container traffic and trying to start said container