ingress-firewall best practice operation #12045
Unanswered
DrummyFloyd
asked this question in
Q&A
Replies: 1 comment 2 replies
-
|
The documentation provides pretty extensive list of rules. It's hard to guess what is wrong, but it feels like your rules use Please keep in mind that it's host firewall, and most of the time only host addresses should be there. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment

Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
i've read a lot about this feature (doc + Discussion already present) and i started to try with the
--mode=tryonly on one of my control planei've got 3 ControlPlane and 1 worker at the moment on my config
and the ingress firewall tested
i've follow the best pratice wrote in the documentation, + 1 taht would limit the access to the
etcd/metricsservers to only some subnetbut once i tried , see many log error about some
443endpoint failling to be reached...Error
so i had this new manifest
but again got many other error but with different port like
10250...so i don't really understand what i'm doing wrong here, i don't want to try many stuff, and being locked out of my cluster by mistake ..
any guidance advise to hardening the cluster would be great thank you
Beta Was this translation helpful? Give feedback.
All reactions