The VM whose clock ran eleven seconds fast
TLS handshakes started failing on one small virtual machine, but only some of the time. The certificate was fine. The clock was not: after the host paused the guest for a live migration, the VM came back eleven seconds in the future.
chrony will normally slew the clock gradually, which is what you want on a busy server and exactly what you do not want right after a jump. The fix was one line:
makestep 1.0 3
That lets chrony step the clock if it is more than a second off during the first three updates, and slew gently afterwards. Since then the drift graph is flat.