Skip to content

Commit 65230c5

Browse files
committed
Add ufw to known issues
Addresses k3s-io/k3s#2059 by adding information on the modifications needed to run k3s with ufw enabled Signed-off-by: t0xicCode <[email protected]>
1 parent 94f8ec5 commit 65230c5

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

content/k3s/latest/en/known-issues/_index.md

+9
Original file line numberDiff line numberDiff line change
@@ -15,3 +15,12 @@ If you are running iptables in nftables mode instead of legacy you might encount
1515
**RootlessKit**
1616

1717
Running K3s with RootlessKit is experimental and has several [known issues.]({{<baseurl>}}/k3s/latest/en/advanced/#known-issues-with-rootlesskit)
18+
19+
**Ufw**
20+
21+
UFW firewall rules are evaluated prior to the kube-proxy rules, so traffic to cluster services can be blocked. Traffic from the service and pod networks should be allowed in ufw to ensure that the kube-proxy rules are evaluated. Given the default values, the following will allow traffic from those network through the ufw portion, before reaching the kube-proxy rules.
22+
23+
```
24+
sudo ufw allow from 10.42.0.0/16 to any
25+
sudo ufw allow from 10.43.0.0/16 to any
26+
```

0 commit comments

Comments
 (0)