Running RKE2 with a bridge as the primary interface for multis. I see the docs want firewalld disabled but I don't want non cluster members to have access to the etcd port, etc. Any solutions here?
c
creamy-pencil-82913
08/28/2025, 12:55 AM
etcd is protected by tls mutual authentication, what’s the threat model?
s
silly-balloon-22613
08/28/2025, 12:56 AM
Compliance teams. In theory ddos and zero days as well
c
creamy-pencil-82913
08/28/2025, 12:57 AM
unfortunately part of what comes with multus is no network policy support. you’re basically running pods with host network.
creamy-pencil-82913
08/28/2025, 12:57 AM
don’t expose your control-plane directly to hostile networks
s
silly-balloon-22613
08/28/2025, 12:59 AM
Trust me I hear you and not planning on it but defense in depth is important. Just looking to see if anyone has a solution