【发布时间】:2021-06-30 06:10:43
【问题描述】:
我有一个带有 3 个节点(2 个工作线程)的单主 kubeadm 集群设置。 在启用防火墙之前,我可以通过本地计算机上的 kubectl 代理访问 kubernetes-dashboard。 我的防火墙(ufw)配置是: 主节点
Status: active
To Action From
-- ------ ----
22/tcp ALLOW Anywhere
6443/tcp ALLOW Anywhere
2379:2380/tcp ALLOW Anywhere
10250/tcp ALLOW Anywhere
10251/tcp ALLOW Anywhere
10252/tcp ALLOW Anywhere
10255/tcp ALLOW Anywhere
80/tcp ALLOW Anywhere
443/tcp ALLOW Anywhere
8443/tcp ALLOW Anywhere
22/tcp (v6) ALLOW Anywhere (v6)
6443/tcp (v6) ALLOW Anywhere (v6)
2379:2380/tcp (v6) ALLOW Anywhere (v6)
10250/tcp (v6) ALLOW Anywhere (v6)
10251/tcp (v6) ALLOW Anywhere (v6)
10252/tcp (v6) ALLOW Anywhere (v6)
10255/tcp (v6) ALLOW Anywhere (v6)
80/tcp (v6) ALLOW Anywhere (v6)
443/tcp (v6) ALLOW Anywhere (v6)
8443/tcp (v6) ALLOW Anywhere (v6)
工作节点
Status: active
To Action From
-- ------ ----
10250/tcp ALLOW Anywhere
10255/tcp ALLOW Anywhere
30000:32767/tcp ALLOW Anywhere
22/tcp ALLOW Anywhere
10250/tcp (v6) ALLOW Anywhere (v6)
10255/tcp (v6) ALLOW Anywhere (v6)
30000:32767/tcp (v6) ALLOW Anywhere (v6)
22/tcp (v6) ALLOW Anywhere (v6)
是否有我忘记允许的端口?或者它可能来自其他东西?
谢谢!
【问题讨论】:
标签: kubernetes firewall kubeadm kubernetes-dashboard ufw