Version: v26.03

Communication Matrix

Source DeviceSource IPSource PortDestination DeviceDestination IPDestination Port (Listening)ProtocolPort DescriptionListening Port ChangeableAuthentication MethodEncryption MethodBelonging PlaneVersionBelonging Service/MicroserviceRemarks
ALLALLALLopenFuyao serverCluster IP6443TCPUsed for third-party systems to obtain aggregation service capabilities provided by openFuyao through this port, is kube-apiserver listening port, this port is SSL encrypted port.YesToken authentication and one-way certificate authenticationTLS1.3(default)/TLS1.2Management plane-kube-apiserver-
ALLALLALLopenFuyao serverCluster IP443TCPUsed for third-party systems to obtain aggregation service capabilities provided by openFuyao through this port, is kube-apiserver listening port, this port is SSL encrypted port.NoToken authentication or one-way certificate authenticationTLS1.3(default)/TLS1.2Management plane-kube-apiserver-
ALLALLALLopenFuyao serverLoopback address10257TCPUsed to access kube-controller-manager HTTPS service, is kube-controller-manager listening port, this port is SSL encrypted port.YesTwo-way certificate authenticationTLS1.3(default)/TLS1.2Management plane-kube-controller-manager-
ALLALLALLopenFuyao serverLoopback address10259TCPUsed to access kube-scheduler HTTPS service, is kube-scheduler listening port, this port is SSL encrypted port.YesTwo-way certificate authenticationTLS1.3(default)/TLS1.2Management plane-kube-scheduler-
ALLALLALLopenFuyao serverCluster IP53TCP/UDPUsed for service domain name resolution, is coredns listening port, only used for domain name resolution.NoNone, adopts TCP standard protocolNoneManagement plane-coredns-
ALLALLALLopenFuyao serverCluster IP9153TCPUsed to collect coredns monitoring metrics.YesNone, adopts TCP standard protocolTLS1.3(default)/TLS1.2Management plane-coredns-
ALLALLALLopenFuyao serverCluster IP8080TCPUsed to check coredns health status.YesNone, adopts TCP standard protocolTLS1.3(default)/TLS1.2Management plane-coredns-
ALLALLALLopenFuyao serverCluster IP2379TCPetcd provides service through this port, this port is SSL encrypted port.YesTwo-way certificate authenticationTLS1.3(default)/TLS1.2Management plane-etcd-
ALLALLALLopenFuyao serverCluster IP2380TCPUsed for communication between etcd cluster members, this port is SSL encrypted port.YesTwo-way certificate authenticationTLS1.3(default)/TLS1.2Management plane-etcd-
ALLALLALLopenFuyao serverCluster IP2381TCPUsed to collect monitoring metrics provided by etcd cluster externally.YesNone, adopts TCP standard protocolTLS1.3(default)/TLS1.2Management plane-etcd-
ALLALLALLopenFuyao serverLoopback address9099HTTPUsed to provide service liveness status check function.YesNone, adopts TCP standard protocolNoneManagement plane and business plane-calico-node-
ALLALLALLopenFuyao serverCluster IP179TCPcalico component bird BGP protocol listening port, used for synchronizing routing between nodes.YesToken authenticationNoneManagement plane and business plane-calico-node-
ALLALLALLopenFuyao serverLoopback address10248TCPUsed to check kubelet health status.YesNone, adopts TCP standard protocolNoneManagement plane and business plane-kubelet-
ALLALLALLopenFuyao serverCluster IP10250TCPUsed to communicate with kube-apiserver, this port is SSL encrypted port.YesToken authentication and certificate authenticationTLS1.3(default)/TLS1.2Management plane and business plane-kubelet-
ALLALLALLopenFuyao serverLoopback address10249TCPUsed to collect monitoring metrics.YesNone, adopts TCP standard protocolNoneManagement plane and business plane-kube-proxy-
ALLALLALLopenFuyao serverLoopback address10256TCPUsed for health status check.YesNone, adopts TCP standard protocolNoneManagement plane and business plane-kube-proxy-

Note:
For Kubernetes official documentation, please refer to Ports and Protocols.

Source DeviceSource IPSource PortDestination DeviceDestination IPDestination Port (Listening)ProtocolPort DescriptionListening Port ChangeableAuthentication MethodEncryption MethodBelonging PlaneVersionBelonging Service/MicroserviceRemarks
ALLALLALLopenFuyao serverPodIP443TCPingress-nginx-controller service portNoUsername and password authenticationTLS1.3(default)/TLS1.2Business plane-ingress-nginx-controller-
ALLALLALLopenFuyao serverCluster IP443TCPingress-nginx-controller service portNoUsername and password authenticationTLS1.3(default)/TLS1.2Business plane-ingress-nginx-controller-
ALLALLALLopenFuyao serverIngressIP30010TCPImport node management interface external access portNoUsername and password authenticationTLS1.3(default)/TLS1.2Business plane-ingress-nginx-controller-
ALLALLALLopenFuyao serverIngressIP31616TCPBusiness cluster & management cluster management interface external access portNoUsername and password authenticationTLS1.3(default)/TLS1.2Business plane-ingress-nginx-controller-
ALLALLALLopenFuyao serverCluster IP9072TCPweb-terminal-service backend Pod access portYestoken authenticationTLS1.3(default)/TLS1.2Business plane-web-terminal-service-
ALLALLALLopenFuyao serverPodIP9072TCPweb-terminal-service backend Service access portYestoken authenticationTLS1.3(default)/TLS1.2Business plane-web-terminal-service-
ALLALLALLopenFuyao serverPodIP80TCPmonitoring-service backend Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-monitoring-service-
ALLALLALLopenFuyao serverPodIP9096TCPInternal authentication server Pod access portYesTwo-way certificate authenticationTLS1.3Business plane-oauth-server-
ALLALLALLopenFuyao serverCluster IP9096TCPInternal authentication server Service access portYesTwo-way certificate authenticationTLS1.3Business plane-oauth-server-
ALLALLALLopenFuyao serverPodIP9095TCPAuthentication webhook Pod access portYesTwo-way certificate authenticationTLS1.3Business plane-oauth-webhook-
ALLALLALLopenFuyao serverCluster IP9095TCPAuthentication webhook Service access portYesTwo-way certificate authenticationTLS1.3Business plane-oauth-webhook-
ALLALLALLopenFuyao serverPodIP9175TCPUser management service Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-user-management-operator-
ALLALLALLopenFuyao serverCluster IP80TCPUser management service Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-user-management-operator-
ALLALLALLopenFuyao serverPodIP9093TCPApplication management service backend Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-application-management-service-
ALLALLALLopenFuyao serverCluster IP80TCPApplication management service backend Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-application-management-service-
ALLALLALLopenFuyao serverPodIP9093TCPApplication marketplace service backend Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-marketplace-service-
ALLALLALLopenFuyao serverCluster IP80TCPApplication marketplace service backend Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-marketplace-service-
ALLALLALLImport nodePodIP8080TCPCluster lifecycle management frontend Pod access portYesNone, adopts TCP standard protocolNoneManagement plane-installer-website-
ALLALLALLImport nodeCluster IP80TCPCluster lifecycle management frontend Service access portYesNone, adopts TCP standard protocolNoneManagement plane-installer-website-
ALLALLALLImport nodePodIP9210TCPCluster lifecycle management backend Pod access portYesNone, adopts TCP standard protocolNoneManagement plane-installer-service-
ALLALLALLImport nodeCluster IP80TCPCluster lifecycle management backend Service access portYesNone, adopts TCP standard protocolNoneManagement plane-installer-service-
ALLALLALLImport nodePodIP8080TCPImport node external provided console frontend Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-bke-console-website-
ALLALLALLImport nodeCluster IP80TCPImport node external provided console frontend Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-bke-console-website-
ALLALLALLImport nodePodIP9037TCPImport node external provided console backend Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-bke-console-website-
ALLALLALLImport nodeCluster IP80TCPImport node external provided console backend Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-bke-console-website-
ALLALLALLopenFuyao serverPodIP9093TCPExtension component management backend Pod access portYesNone, adopts TCP standard protocolNoneBusiness plane-plugin-management-service-
ALLALLALLopenFuyao serverCluster IP80TCPExtension component management backend Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-plugin-management-service-
ALLALLALLopenFuyao serverCluster IP9100TCPNode Exporter Service access portYesNone, adopts TCP standard protocolNoneBusiness plane-node-exporter-
ALLALLALLImport nodeContainer IP2049TCPImport node external provided nfsserver mount service portNoNone, adopts TCP standard protocolNoneBusiness plane-bocloud_nfs_registry-
ALLALLALLImport nodeContainer IP36443HTTPSImport node external K8s API portNoToken authentication and one-way certificate authenticationTLS1.3(default)/TLS1.2Business plane-kubernetes-
ALLALLALLImport nodeContainer IP38080HTTPImport node external provided charts service portNoNone, adopts TCP standard protocolNoneBusiness plane-bocloud_chart_registry-
ALLALLALLImport nodeContainer IP40080HTTPImport node external provided yum source service portNoNone, adopts TCP standard protocolNoneBusiness plane-bocloud_yum_registry-
ALLALLALLImport nodeContainer IP40443HTTPSImport node external provided image source service portNoOne-way certificate authenticationTLS1.3(default)/TLS1.2Business plane-bocloud_image_registry-
ALLALLALLopenFuyao serverCluster IP8443HTTPSHealth check probe portYesOne-way certificate authenticationTLS1.3(default)/TLS1.2Business plane-bbkeagent-deployer-
ALLALLALLopenFuyao serverLoopback address58080HTTPSystem service listening portYesNone, adopts TCP standard protocol wNoneBusiness plane-bkeagent-

Note:
For communication port information of components installed through application marketplace, please understand from relevant component provider.