Firewall Configuration#
The following table lists the network endpoints for Edge Orchestrator and edge nodes. You can use this to configure Edge Orchestrator firewall ingress rules appropriate for your network environment.
BIOS Onboarding accesses
tinkerbell-haproxy.{domain}.You can access all other services from edge nodes agents, UI, and APIs of Edge Orchestrator.
Source |
Destination |
Protocol:Port |
Description |
|---|---|---|---|
Edge Orchestrator UI and API |
{domain} |
Web UI |
|
Edge Orchestrator UI and API |
web-ui.{domain} |
Web UI |
|
Edge Orchestrator API |
api.{domain} |
Tenancy API |
|
Edge Orchestrator UI and API |
keycloak.{domain} |
Identity and Access Management |
|
Edge Orchestrator UI and API |
observability-admin.{domain} |
Observability |
|
Edge Orchestrator UI and API |
observability-ui.{domain} |
Observability |
|
Edge Orchestrator UI and API |
registry-oci.{domain} |
Harbor* UI |
|
Edge Orchestrator UI and API |
vault.{domain} |
Vault* UI |
|
Edge node |
infra-node.{domain} |
Edge Infrastructure Manager |
|
Edge node |
attest-node.{domain} |
Edge Infrastructure Manager |
|
Edge node |
onboarding-node.{domain} |
Edge Infrastructure Manager |
|
Edge node |
onboarding-stream.{domain} |
Edge Infrastructure Manager |
|
Edge node |
release.{domain} |
Release service token |
|
Edge node |
metrics-node.{domain} |
Observability |
|
Edge node |
telemetry-node.{domain} |
Observability |
|
Edge node |
logs-node.{domain} |
Observability |
|
Edge node |
tinkerbell-server.{domain} |
Onboarding |
|
Edge node |
update-node.{domain} |
Edge Infrastructure Manager |
|
Edge node |
tinkerbell-haproxy.{domain} |
BIOS onboarding |
To install Edge Orchestrator and Edge Node, the following Egress rules are required:
Source |
Destination |
Description |
|---|---|---|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Installation files |
|
Edge Orchestrator |
Container images |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Orchestrator |
Helm Chart |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |
|
Edge Node |
Onboarding |