GitHub user weizhouapache added a comment to the discussion: CKS Firewall and 
scaling cluster problem if default firewall rules delete

> @weizhouapache Hey, thanks for your reply. What do you think about the 
> security risk with the default firewall rules? I mean opening 0.0.0.0/0 for 
> ports 6443 and 2222–22xx.

@baltazorbest 
port 2222-22xx can only be used for SSH with private key, it has low risk I 
think
port 6443 is used for K8S api server, it has low risk too

of course it can be improved, please keep eye on #11758
I am closing this as duplicated


GitHub link: 
https://github.com/apache/cloudstack/discussions/11783#discussioncomment-14738597

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to