Every numbered arrow on the sheet. The arrow points from the side that opens the connection; replies use the same session. Hover a row to trace it on the diagram, or click its flow ID to jump there.
| FLOW | SOURCE | DESTINATION | PORT / PROTOCOL | NEEDED | PURPOSE |
|---|---|---|---|---|---|
| Users / CLI | Rancher ingress | TCP 443 HTTPS / WSS | Required | UI, API and kubectl through the Rancher cluster proxy; shell and log streams use WSS. Port 80 only redirects. | |
| cattle-cluster-agent | Rancher ingress | TCP 443 WSS | Required | Long-lived remotedialer tunnel. Rancher proxies API calls to the downstream cluster back through it. | |
| rancher-system-agent (each node) | Rancher ingress | TCP 443 HTTPS | Provisioned clusters | Watches plan secrets: RKE2 / K3s install, upgrade, etcd snapshot and restore. | |
| fleet-agent | Rancher ingress (Fleet API) | TCP 443 HTTPS | Required | Pull model: reads BundleDeployments for its namespace and writes status. Works behind NAT. | |
| Users / CLI | Downstream kube-apiserver | TCP 6443 | Optional | Authorized Cluster Endpoint. kube-api-auth validates Rancher tokens on the cluster, so kubectl keeps working if Rancher is down. | |
| Provisioning (rancher-machine, CAPI providers, hosted operators) | Infrastructure & cloud APIs, new VMs | TCP 443 · SSH 22 · 6443 | Per provider | Create and delete VMs, bootstrap node-driver VMs over SSH, manage EKS / AKS / GKE, reach imported cluster APIs at registration. | |
| New nodes / Elemental hosts | Rancher ingress | TCP 443 HTTPS | Custom, node-driver, Elemental | Download the system-agent install script and register; elemental-register enrolls SUSE Linux Micro hosts. | |
| Fleet gitjob / helmops, Rancher catalogs, Kubewarden | Git, Helm and OCI sources | TCP 443 · SSH 22 | If GitOps or custom catalogs | Clone Git repos into bundles, fetch Helm charts and OCI artifacts, pull policy modules. | |
| Rancher server | Identity provider | TCP 389 / 636 · 443 | If external auth | LDAP / AD bind and search, OIDC token exchange. F9a is the browser redirect for SAML and OIDC sign-in. | |
| rancher-backup, RKE2 / K3s etcd snapshots, Longhorn | Backup storage | TCP 443 (S3) · 2049 (NFS) | If configured | Rancher backups, scheduled etcd snapshots and Longhorn volume backups. Encryption is set per target. | |
| containerd on every node, Rancher catalogs | Image & chart repositories | TCP 443 | Required | Image pulls (registry.rancher.com for Prime) and chart fetches. Point system-default-registry at a mirror for air-gap. | |
| Alertmanager, Fluentd outputs | Alert & log destinations | TCP 443 · 587 | If configured | Alert notifications and log shipping to the configured receivers and outputs. | |
| SUSE Observability agents | SUSE Observability | TCP 443 | Optional | Topology, metrics, traces and logs. Flows are in the SUSE Observability deployment network reference. | |
| All nodes | DNS, NTP | UDP/TCP 53 · UDP 123 | Required | Name resolution for the Rancher hostname and destinations; time sync for TLS and etcd. |
In-cluster traffic (green): Traefik → Rancher service HTTP 80 with TLS ending at the ingress; Rancher, Fleet, Turtles and operators → kube-apiserver 6443; kube-apiserver → rancher-webhook 9443. Node-to-node ports are listed in the sheet footer.
What ships with or around Rancher 2.15, split by who maintains it. Each card opens the project’s public documentation.
Sources: Rancher v2.15.0 release notes, Rancher port requirements, RKE2 networking services, Fleet architecture, Rancher Cluster API overview. Logos are the projects’ own artwork, shown to identify each component.