WEBVTT

00:01.150 --> 00:03.490
Hello and welcome to this lecture. In this lecture

00:03.490 --> 00:09.430
We look at the networking configurations required on the master and worker nodes in a kubernetes cluster.

00:09.730 --> 00:15.610
The kubernetes cluster consists of master and worker nodes. Each node must have at least 1 interface

00:15.670 --> 00:17.170
connected to a network.

00:17.170 --> 00:19.750
Each interface must have an address configured.

00:19.750 --> 00:24.620
The hosts must have a unique hostname set. As well as a unique MAC address.

00:24.640 --> 00:29.750
You should note this especially if you created the VMs by cloning from existing ones.

00:29.830 --> 00:32.740
There are some ports that needs to be opened as well.

00:32.770 --> 00:35.550
These are used by the various components in the control plane.

00:35.590 --> 00:39.980
The master should accept connections on 6443 for the API server.

00:40.030 --> 00:45.850
The worker nodes, Kubectl tool, external users, and all other control plane components access the

00:45.850 --> 00:50.500
kube-api server via this port. The kubelets on the master and worker nodes listen on

00:50.500 --> 00:52.170
10250. Yes,

00:52.300 --> 00:57.050
in case we didn’t discuss this, the kubelet’s can be present on the master node as well.

00:57.070 --> 01:03.220
The kube-scheduler requires port 10251 to be open. The kube-controller-manager requires port

01:03.220 --> 01:10.180
10252 to be open. The worker nodes expose services for external access on ports 30000 to

01:10.180 --> 01:11.860
32767.

01:11.950 --> 01:13.270
So these should be open as well.

01:13.330 --> 01:17.260
Finally, the ETCD server listens on port 2379.

01:17.320 --> 01:23.020
If you have multiple master nodes, all of these ports need to be open on those as well. And you also need

01:23.020 --> 01:28.240
an additional port 2380 open so the ETCD clients can communicate with each other.

01:28.270 --> 01:33.430
The list of ports to be opened are also available in the kubernetes documentation page.

01:33.430 --> 01:39.430
So consider these when you setup networking for your nodes, in your firewalls, or ip table rules or network

01:39.430 --> 01:45.370
security group in a cloud environment such as GCP or Azure or AWS. And if things are not working

01:45.430 --> 01:50.530
this is one place to look for while you are investigating. Head over to the practice session and explore

01:50.530 --> 01:53.140
the networking setup in the existing environment.

01:53.140 --> 01:56.020
Keep this commands handy while you look for information.

01:56.050 --> 02:01.000
We will start with simple exercises where you will explore an existing kubernetes cluster and view

02:01.000 --> 02:05.040
information about the interfaces, ips, hostnames, ports etc.

02:05.050 --> 02:09.540
This will help you familiarize with the environment and look for information in the future sections.

02:09.550 --> 02:12.580
Going forward we will get into more challenging exercises.

02:12.640 --> 02:14.200
For now let's start slow.

