Swimlane HA K8s firewall rules
This document provides the list of all known connections that Swimlane K8s requires to run. The ports listed below need to be opened on masters/workers nodes.
Note: Any additional services are not listed here.
Protocol | Direction | Port Range | Purpose |
|---|---|---|---|
TCP | Inbound | 22 | SSH |
TCP | Inbound | 443 | Swimlane application |
TCP | Inbound | 6443 | Kubernetes API server |
TCP | Inbound | 2379-2380 | Etcd server client API |
TCP | Inbound | 10250-10252 | Kubelet API, kube-scheduler, kube-controller-manager |
UDP | Inbound | 6783-6784 | Weave data ports |
TCP | Inbound | 6783 | Weave control port |
TCP | Inbound | 30000-32767 | NodePort services |
UDP | Inbound | 514 | Swimlane (Syslog receiver) |
TCP | Inbound | 8800 | For Replicated deployment - console/dashboard/ui |
TCP | Inbound | 9870-9881 | For Replicated deployment - internal communication |
Below is an example of how the above ports are configured using firewalld.