# Ingress firewall: block everything that is not listed here. Loopback and # replies to outgoing connections are always allowed by Talos. # # Public TCP ports served by sish must match port-bind-range in # kubernetes/base/sish/config.yml (plus :80 HTTP and :2222 sish SSH). # Closed on purpose: flannel VXLAN 4789/udp (single node, unauthenticated), # etcd 2379-2383, kubelet 10250, kube-proxy 10256, trustd 50001 (only needed # when other nodes join). apiVersion: v1alpha1 kind: NetworkDefaultActionConfig ingress: block --- apiVersion: v1alpha1 kind: NetworkRuleConfig name: sish-public portSelector: ports: - 22 # gitea ssh (raw tcp forward) - 80 # sish http, routed by Host header - 443 # sish tls, routed by SNI - 2222 # sish ssh endpoint for connectors (public key auth) - 20000-20099 # reserved for raw tcp forwards protocol: tcp ingress: - subnet: 0.0.0.0/0 - subnet: ::/0 --- # Talos API (apid) and Kubernetes API, both mTLS / client-cert authenticated apiVersion: v1alpha1 kind: NetworkRuleConfig name: talos-and-kube-api portSelector: ports: - 50000 - 6443 protocol: tcp ingress: - subnet: 0.0.0.0/0 - subnet: ::/0 --- # CoreDNS forwards to the Talos host DNS (forwardKubeDNSToHost), which pods reach # on the host, so the pod network needs DNS to the node apiVersion: v1alpha1 kind: NetworkRuleConfig name: pod-dns portSelector: ports: - 53 protocol: udp ingress: - subnet: 10.244.0.0/16 --- apiVersion: v1alpha1 kind: NetworkRuleConfig name: pod-dns-tcp portSelector: ports: - 53 protocol: tcp ingress: - subnet: 10.244.0.0/16