This message was deleted.
# rke2
a
This message was deleted.
r
My eventual plan is to look through https://projectcalico.docs.tigera.io/security/hosts and try using Calico (via the default Canal or Calico CNIs) to do a firewall. I haven't done it yet, still on the todo list, so not sure how well it'll work. I'd be happy to hear any positives or negatives from your experience if you try it before me.
I've seen people on here state that they've gotten RKE2 working with ufw. Seems odd to me as I'd think anything else managing netfilter would have the potential to interfere, but I haven't tried it myself so am not certain.
h
@rapid-helmet-86074 I have also seen people use UFW, but i dont use ubuntu so not going to help me much. I tried finding a way to exlude adapters from the firewall (dont think it is possible). I could try use iptables natively or try nftables. going to be a bummer i can get the firewall working 😞
r
If I'm using Calico or Canal then using Calico to mimic firewall functionality always seemed safest to me, so that's where I figured it seemed like the right idea. If I tried ufw or similar I'd always be nervous that it'd interfere sometime later when my guard was down and it'd take me days longer to find that it was the cause.
h
Out of interest - is there a guide about this (what you are doing) so i can check it out?
r
I haven't started the Calico part, I'm supporting multiple things so I'm still on just basics with RKE2 & Rancher. Still need to play around with backup/restore & upgrades & get some of the gotchas for that documented before I get to messing with firewall. All I've got firewall-wise is the Calico link above which is on my todo list to go look at later.