2 ms·
Ask HN: Rancher and Kubernetes, is a firewall required?
Hi, I haven't had much luck asking this around so let's try here....
I usually create the servers for my K8s clusters manually using the Hetzner Cloud console, then with Ansible I create users, disable password/root auth, install fail2ban and configure a firewall to allow all traffic between the nodes, open the K8s API port 6443 to my IP, open 22, 80 and 443 to the public; install Docker. Then I deploy Kubernetes with Rancher. This way I feel like the servers are OK from small/scripted attacks at least.
I am now trying to use a node driver that adds support for HC to Rancher, so that it can create the servers and deploy kubernetes automatically, which is convenient. Rancher doesn't install fail2ban or configure a firewall though... so I am worried that this way it could be easier for someone to compromise the cluster.
I have tried adding to the node driver some cloud-init configuration that does most of what Ansible does, but I can't get Rancher todeploy K8s likely because of firewall. After a few minutes Rancher deletes the servers from Hetzner Cloud and recreates them to try again, in a sort of loop. If I remove the firewalld configuration then Rancher can successfully deploy Kubernetes. So I don't know how to force Rancher to use the private network for the communication between the nodes, or otherwise how to configure the firewall to allow traffic between the nodes regardless of the interface/ip, because I cannot know in advance the ips of the servers created by Rancher.
Does anyone have any idea of how I could fix this kind of setup? I would like to let Rancher create and manage the servers as it's easier, but I would also like peace of mind that it's not easy to compromise my clusters. Also, do you use Rancher this way? Do you use a firewall with Kubernetes in general?
Thanks a lot in advance for your help!