Rancher Network Interactive
© 2026 Krumware LLC
LOCAL (UPSTREAM) CLUSTER · RANCHER MANAGER RKE2 v1.36 · 3 server nodes (HA)
DOWNSTREAM CLUSTERSProvisioned (RKE2 / K3s) · Imported · Hosted (EKS / AKS / GKE)
SUSE Rancher Prime
Deployment network
Rancher Manager 2.15 on RKE2 v1.36  ·  Local (upstream) cluster, downstream clusters and configured destinations
Hover or tap any box, arrow or flow label for details. Click to pin; Esc to close.
Core connection Optional / configured In-cluster traffic Arrow = connection initiator; moving dots show which side opens the connection
CONFIGURED DESTINATIONS
Users / CLI
Rancher UI · kubectl · Rancher CLI
Terraform / API tokens
Joining nodes
Custom-cluster nodes, node-driver VMs, CAPI machines and Elemental hosts
F7 · install script + registration via Rancher URL
Ingress · Traefik (RKE2 default) · L4 load balancer
443 · HTTPS / WSS · TLS termination (cert-manager, Let’s Encrypt or BYO) · 80 → 443
Rancher server
cattle-system · HTTP :80 behind ingress
API · Dashboard UI · Steve
Auth providers · cluster proxy
Tunnel server (remotedialer)
Provisioning
v2prov
rancher-machine
Node drivers
EKS · AKS · GKE operators
Fleet controller
cattle-fleet-system
fleet-controller
gitjob · helmops
Bundles → BundleDeployments
Rancher Turtles
cattle-turtles-system
CAPI core controllers
Providers via CAPIProvider
Webhook & operators
rancher-webhook :9443 (admission)
elemental-operator
system-upgrade-controller
Rancher Backups
rancher-backup operator
Resource-set tarballs (encrypted)
Restore / migrate Rancher
RKE2 control plane · Canal CNI · CoreDNS
kube-apiserver :6443 · supervisor :9345 · etcd :2379 / 2380
kubelet :10250 · Canal VXLAN UDP 8472
Rancher agents
cattle-system · cattle-fleet-system
cattle-cluster-agent
Deployment · WSS tunnel to Rancher (F2)
rancher-system-agent
Per node, provisioned clusters · plans (F3)
fleet-agent
Pulls BundleDeployments, reports status (F4)
system-upgrade-controller
Rolls RKE2 / K3s version upgrades
rancher-webhook
Admission :9443 for Rancher RBAC CRDs
Cluster runtime
kube-apiserver :6443 · kubelet :10250
RKE2 supervisor :9345 · etcd :2379/2380
CNI: Canal · Calico · Cilium
Ingress: Traefik · DNS: CoreDNS
OBSERVABILITY
Monitoring
kube-prometheus-stack: Prometheus · Alertmanager · Grafana
rancher-monitoring-dashboards: UI service proxies
Logging
rancher-logging: Fluent Bit agents → Fluentd → outputs
STORAGE & BACKUP
Longhorn
longhorn-manager :9500 · instance-manager · CSI
Replicas sync node-to-node; backup target S3 / NFS
etcd snapshots
Scheduled by RKE2 / K3s; local disk and S3 (F10)
SECURITY & POLICY
SUSE Security (NeuVector)
controller · enforcer (per node) · scanner · manager :8443
Kubewarden
policy-server admission webhooks · policies from OCI (F8)
Rancher Compliance
CIS benchmark scans (rancher-compliance)
VIRTUALIZATION & OS
Harvester
Imported via Virtualization Management; node driver, CSI and cloud provider for guest clusters on Harvester VMs
Elemental
elemental-register on SUSE Linux Micro hosts → Rancher 443 (F7)
F9
Identity provider
LDAP / AD: TCP 389 / 636* · OIDC, SAML, Entra ID, GitHub: HTTPS 443*
Rancher server → IdP; browser redirect for SAML / OIDC
F8
Git, Helm & OCI sources
Git: HTTPS 443* / SSH 22* · Helm / OCI: HTTPS 443*
Fleet gitjob & helmops · app catalogs · Kubewarden policies
F6
Infrastructure & cloud APIs
Harvester · vSphere · AWS / Azure / GCP · EKS / AKS / GKE: HTTPS 443*
SSH 22* to node-driver VMs · imported cluster API (6443*) at registration
F10
Backup storage
S3-compatible: HTTPS 443* · NFS: TCP 2049*
rancher-backup · etcd snapshots · Longhorn backup target
F11
Image & chart repositories
registry.rancher.com (Prime) · chart repos: HTTPS 443*
system-default-registry / private mirror for air-gap
F12
Alert & log destinations
Alertmanager: Slack, PagerDuty, webhook 443* · SMTP 587*
Logging outputs: Elasticsearch, Splunk, Loki, S3 · 443*
F13
SUSE Observability
Agents → SUSE Observability ingress: HTTPS 443*
Optional; flows detailed in the SUSE Observability deployment network
F14 DNS UDP/TCP 53* · NTP UDP 123*    Node-to-node (every RKE2 cluster) 9345 · 6443 · 10250 · 2379–2380 · UDP 8472 (Canal VXLAN) · 5473 (Calico Typha) · 30000–32767 NodePort
Downstream clusters need no inbound connection from Rancher: agents dial out (F2–F4) and Rancher reaches each downstream API back through the F2 tunnel. Rancher pulls from registry.rancher.com (Prime) or a mirror. * Default or example ports; confirm per environment.
© 2026 Krumware LLC · krum.io
F1 · 443F2 · F3 · F4443 WSS / HTTPSF7F5 · 6443 · authorized cluster endpointF9a · browser SAML / OIDC redirectHTTP 8064439443F9F6F8F10F11F11F10F12F13

Flow register

Every numbered arrow on the sheet. The arrow points from the side that opens the connection; replies use the same session. Hover a row to trace it on the diagram, or click its flow ID to jump there.

FLOWSOURCEDESTINATIONPORT / PROTOCOLNEEDEDPURPOSE
Users / CLIRancher ingressTCP 443 HTTPS / WSSRequiredUI, API and kubectl through the Rancher cluster proxy; shell and log streams use WSS. Port 80 only redirects.
cattle-cluster-agentRancher ingressTCP 443 WSSRequiredLong-lived remotedialer tunnel. Rancher proxies API calls to the downstream cluster back through it.
rancher-system-agent (each node)Rancher ingressTCP 443 HTTPSProvisioned clustersWatches plan secrets: RKE2 / K3s install, upgrade, etcd snapshot and restore.
fleet-agentRancher ingress (Fleet API)TCP 443 HTTPSRequiredPull model: reads BundleDeployments for its namespace and writes status. Works behind NAT.
Users / CLIDownstream kube-apiserverTCP 6443OptionalAuthorized Cluster Endpoint. kube-api-auth validates Rancher tokens on the cluster, so kubectl keeps working if Rancher is down.
Provisioning (rancher-machine, CAPI providers, hosted operators)Infrastructure & cloud APIs, new VMsTCP 443 · SSH 22 · 6443Per providerCreate and delete VMs, bootstrap node-driver VMs over SSH, manage EKS / AKS / GKE, reach imported cluster APIs at registration.
New nodes / Elemental hostsRancher ingressTCP 443 HTTPSCustom, node-driver, ElementalDownload the system-agent install script and register; elemental-register enrolls SUSE Linux Micro hosts.
Fleet gitjob / helmops, Rancher catalogs, KubewardenGit, Helm and OCI sourcesTCP 443 · SSH 22If GitOps or custom catalogsClone Git repos into bundles, fetch Helm charts and OCI artifacts, pull policy modules.
Rancher serverIdentity providerTCP 389 / 636 · 443If external authLDAP / AD bind and search, OIDC token exchange. F9a is the browser redirect for SAML and OIDC sign-in.
rancher-backup, RKE2 / K3s etcd snapshots, LonghornBackup storageTCP 443 (S3) · 2049 (NFS)If configuredRancher backups, scheduled etcd snapshots and Longhorn volume backups. Encryption is set per target.
containerd on every node, Rancher catalogsImage & chart repositoriesTCP 443RequiredImage pulls (registry.rancher.com for Prime) and chart fetches. Point system-default-registry at a mirror for air-gap.
Alertmanager, Fluentd outputsAlert & log destinationsTCP 443 · 587If configuredAlert notifications and log shipping to the configured receivers and outputs.
SUSE Observability agentsSUSE ObservabilityTCP 443OptionalTopology, metrics, traces and logs. Flows are in the SUSE Observability deployment network reference.
All nodesDNS, NTPUDP/TCP 53 · UDP 123RequiredName resolution for the Rancher hostname and destinations; time sync for TLS and etcd.

In-cluster traffic (green): Traefik → Rancher service HTTP 80 with TLS ending at the ingress; Rancher, Fleet, Turtles and operators → kube-apiserver 6443; kube-apiserver → rancher-webhook 9443. Node-to-node ports are listed in the sheet footer.

Component index

What ships with or around Rancher 2.15, split by who maintains it. Each card opens the project’s public documentation.

Sources: Rancher v2.15.0 release notes, Rancher port requirements, RKE2 networking services, Fleet architecture, Rancher Cluster API overview. Logos are the projects’ own artwork, shown to identify each component.