From b1ed1ef3fd36a6d29f364c45608993e23d89781c Mon Sep 17 00:00:00 2001 From: Mark Bishop Date: Thu, 30 Aug 2018 19:53:53 -0700 Subject: [PATCH 1/3] adding new chart --- content/rancher/v2.x/en/installation/references/_index.md | 2 +- src/img/rancher/port-communications.svg | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) create mode 100644 src/img/rancher/port-communications.svg diff --git a/content/rancher/v2.x/en/installation/references/_index.md b/content/rancher/v2.x/en/installation/references/_index.md index 3f2e7facc22..b0537811c38 100644 --- a/content/rancher/v2.x/en/installation/references/_index.md +++ b/content/rancher/v2.x/en/installation/references/_index.md @@ -9,7 +9,7 @@ To operate properly, Rancher requires the following ports to be open on your nod The following diagram displays the basic port requirements for Rancher. If you need more detail, refer to the tables below. -![Basic Port Requirements]({{< baseurl >}}/img/rancher/port-communications.png) +![Basic Port Requirements]({{< baseurl >}}/img/rancher/port-communications.svg) {{< requirements_ports_rancher >}} {{< requirements_ports_rke >}} diff --git a/src/img/rancher/port-communications.svg b/src/img/rancher/port-communications.svg new file mode 100644 index 00000000000..272f1155d7e --- /dev/null +++ b/src/img/rancher/port-communications.svg @@ -0,0 +1,2 @@ + +


Rancher Management Plane
[Not supported by viewer]
Text
Text
Rancher Launched Kubernetes

 Nodes hosted by an IaaS. 
  • Amazon EC2
  • DigitalOcean
  • Azure
  • vSphere
[Not supported by viewer]
Rancher Launched Kubernetes

 
  Cluster with custom nodes.
[Not supported by viewer]
Imported Clusters
  • kops
  • Tectonic
  • RKE CLI
  • non-Rancher provisioned cloud cluster
[Not supported by viewer]
Hosted Kubernetes Provider

 Provisioned by Rancher.
  • Google GKE
  • Amazon EKS
  • Microsoft AKS
[Not supported by viewer]
Rancher Server TLS: 443
<font color="#000000">Rancher Server TLS: 443</font>
Rancher Server TLS: 443
[Not supported by viewer]
▲ Rancher Server TLS: 443
[Not supported by viewer]
▼ SSH: 22
▼ Docker Daemon TLS: 2376
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
 ▼ Kubernetes API: 6443
[Not supported by viewer]
\ No newline at end of file From 0300b96797055633957befeb871cf1b5bf8413d1 Mon Sep 17 00:00:00 2001 From: Mark Bishop Date: Fri, 31 Aug 2018 11:11:36 -0700 Subject: [PATCH 2/3] updating cluster ports diagram --- src/img/rancher/port-communications.svg | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/img/rancher/port-communications.svg b/src/img/rancher/port-communications.svg index 272f1155d7e..222c9159773 100644 --- a/src/img/rancher/port-communications.svg +++ b/src/img/rancher/port-communications.svg @@ -1,2 +1,2 @@ -


Rancher Management Plane
[Not supported by viewer]
Text
Text
Rancher Launched Kubernetes

 Nodes hosted by an IaaS. 
  • Amazon EC2
  • DigitalOcean
  • Azure
  • vSphere
[Not supported by viewer]
Rancher Launched Kubernetes

 
  Cluster with custom nodes.
[Not supported by viewer]
Imported Clusters
  • kops
  • Tectonic
  • RKE CLI
  • non-Rancher provisioned cloud cluster
[Not supported by viewer]
Hosted Kubernetes Provider

 Provisioned by Rancher.
  • Google GKE
  • Amazon EKS
  • Microsoft AKS
[Not supported by viewer]
Rancher Server TLS: 443
<font color="#000000">Rancher Server TLS: 443</font>
Rancher Server TLS: 443
[Not supported by viewer]
▲ Rancher Server TLS: 443
[Not supported by viewer]
▼ SSH: 22
▼ Docker Daemon TLS: 2376
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
 ▼ Kubernetes API: 6443
[Not supported by viewer]
\ No newline at end of file +

Rancher Management Plane
[Not supported by viewer]
Text
Text
Rancher Launched Kubernetes

 Nodes hosted by an IaaS. 
  • Amazon EC2
  • DigitalOcean
  • Azure
  • vSphere
[Not supported by viewer]
Rancher Launched Kubernetes

 
  Cluster with custom nodes.
[Not supported by viewer]
Imported Clusters
  • kops
  • Tectonic
  • RKE CLI
  • non-Rancher provisioned cloud cluster
[Not supported by viewer]
Hosted Kubernetes Provider

 Provisioned by Rancher.
  • Google GKE
  • Amazon EKS
  • Microsoft AKS
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
▲ Rancher Server TLS: 443
[Not supported by viewer]
▼ SSH: 22
▼ Docker Daemon TLS: 2376
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
 ▼ Kubernetes API: 6443
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
\ No newline at end of file From a571a22c4aa98221455ecdcbb95a1c93386892fc Mon Sep 17 00:00:00 2001 From: Mark Bishop Date: Fri, 31 Aug 2018 15:29:47 -0700 Subject: [PATCH 3/3] updating install visuals --- content/rancher/v2.x/en/installation/ha/_index.md | 1 + .../en/installation/ha/rke-add-on/layer-4-lb/_index.md | 1 + .../en/installation/ha/rke-add-on/layer-7-lb/_index.md | 1 + content/rancher/v2.x/en/installation/references/_index.md | 5 +++-- .../rancher/v2.x/en/installation/requirements/_index.md | 7 +++++-- src/img/rancher/ha/rancher2ha-l7.svg | 2 +- src/img/rancher/ha/rancher2ha.svg | 2 +- src/img/rancher/port-communications.svg | 2 +- 8 files changed, 14 insertions(+), 7 deletions(-) diff --git a/content/rancher/v2.x/en/installation/ha/_index.md b/content/rancher/v2.x/en/installation/ha/_index.md index cfac1fc5f23..7ad2b6b25a3 100644 --- a/content/rancher/v2.x/en/installation/ha/_index.md +++ b/content/rancher/v2.x/en/installation/ha/_index.md @@ -16,6 +16,7 @@ This procedure walks you through setting up a 3-node cluster with RKE and instal * The Ingress controller will redirect http port 80 to https and terminate SSL/TLS on port 443. * The Ingress controller will forward traffic to port 80 on the pod in the Rancher deployment. +HA Rancher install with layer 4 load balancer, depicting SSL termination at ingress controllers ![Rancher HA]({{< baseurl >}}/img/rancher/ha/rancher2ha.svg) ## Required Tools diff --git a/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-4-lb/_index.md b/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-4-lb/_index.md index 4cc31cca769..bb6f251614d 100644 --- a/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-4-lb/_index.md +++ b/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-4-lb/_index.md @@ -11,6 +11,7 @@ This procedure walks you through setting up a 3-node cluster using the Rancher K In a HA setup that uses a layer 4 load balancer, the load balancer accepts Rancher client connections over the TCP/UDP protocols (i.e., the transport level). The load balancer then forwards these connections to individual cluster nodes without reading the request itself. Because the load balancer cannot read the packets it's forwarding, the routing decisions it can make are limited. +HA Rancher install with layer 4 load balancer, depicting SSL termination at ingress controllers ![Rancher HA]({{< baseurl >}}/img/rancher/ha/rancher2ha.svg) ## Installation Outline diff --git a/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-7-lb/_index.md b/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-7-lb/_index.md index 263b7522d54..256a2543e46 100644 --- a/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-7-lb/_index.md +++ b/content/rancher/v2.x/en/installation/ha/rke-add-on/layer-7-lb/_index.md @@ -11,6 +11,7 @@ This procedure walks you through setting up a 3-node cluster using the Rancher K In a HA setup that uses a layer 7 load balancer, the load balancer accepts Rancher client connections over the HTTP protocol (i.e., the application level). This application-level access allows the load balancer to read client requests and then redirect to them to cluster nodes using logic that optimally distributes load. +HA Rancher install with layer 7 load balancer, depicting SSL termination at load balancer ![Rancher HA]({{< baseurl >}}/img/rancher/ha/rancher2ha-l7.svg) ## Installation Outline diff --git a/content/rancher/v2.x/en/installation/references/_index.md b/content/rancher/v2.x/en/installation/references/_index.md index b0537811c38..d83a2fd7ba3 100644 --- a/content/rancher/v2.x/en/installation/references/_index.md +++ b/content/rancher/v2.x/en/installation/references/_index.md @@ -5,10 +5,11 @@ aliases: - /rancher/v2.x/en/hosts/amazon/#required-ports-for-rancher-to-work/ --- -To operate properly, Rancher requires the following ports to be open on your nodes. During creation of clusters using a cloud service (like Amazon EC2 or DigitalOcean), Rancher opens these ports for you. +To operate properly, Rancher requires certain ports to be open on your nodes. During creation of clusters using a cloud service (like Amazon EC2 or DigitalOcean), Rancher opens these ports for you. -The following diagram displays the basic port requirements for Rancher. If you need more detail, refer to the tables below. +The ports that Rancher opens change according to the type of machines hosting your cluster nodes. The following diagram depicts the ports that are opened for each [cluster type]({{< baseurl >}}/rancher/v2.x/en/cluster-provisioning). +Cluster Type Port Requirements ![Basic Port Requirements]({{< baseurl >}}/img/rancher/port-communications.svg) {{< requirements_ports_rancher >}} diff --git a/content/rancher/v2.x/en/installation/requirements/_index.md b/content/rancher/v2.x/en/installation/requirements/_index.md index 4e795eebf59..930f75ce31a 100644 --- a/content/rancher/v2.x/en/installation/requirements/_index.md +++ b/content/rancher/v2.x/en/installation/requirements/_index.md @@ -61,9 +61,12 @@ Supported Versions: [Docker Documentation: Installation Instructions](https://docs.docker.com/) {{% /tab %}} {{% tab "Ports" %}} -The following diagram depicts the basic port requirements for Rancher. -![Basic Port Requirements]({{< baseurl >}}/img/rancher/port-communications.png) +When deploying Rancher in an HA cluster, certain ports on your nodes must be open to allow communication with Rancher. The ports that must be open change according to the type of machines hosting your cluster nodes. For example, if your are deploying Rancher on nodes hosted by an IaaS, port `22` must be open for SSH. The following diagram depicts the ports that are opened for each [cluster type]({{< baseurl >}}/rancher/v2.x/en/cluster-provisioning). + +Cluster Type Port Requirements +![Basic Port Requirements]({{< baseurl >}}/img/rancher/port-communications.svg) + {{< requirements_ports_rancher >}} {{< requirements_ports_rke >}} diff --git a/src/img/rancher/ha/rancher2ha-l7.svg b/src/img/rancher/ha/rancher2ha-l7.svg index 87041de905e..725da754024 100644 --- a/src/img/rancher/ha/rancher2ha-l7.svg +++ b/src/img/rancher/ha/rancher2ha-l7.svg @@ -1,2 +1,2 @@ -
Rancher
Rancher
Node 1
Node 1
Node 2
Node 2
Node 3
Node 3
rancher.yourdomain.com
rancher.yourdomain.com<br>
NGINX Ingress controller
(HTTP)
NGINX Ingress controller<br>(HTTP)<br>
NGINX Ingress controller
(HTTP)
NGINX Ingress controller<br>(HTTP)<br>
NGINX Ingress controller
(HTTP)
NGINX Ingress controller<br>(HTTP)<br>
Rancher
Rancher
Layer 7 Load Balancer
(HTTPS)
Layer 7 Load Balancer<br>(HTTPS)<br>
\ No newline at end of file +
Rancher Cluster


[Not supported by viewer]
Rancher
[Not supported by viewer]
Node 3
[Not supported by viewer]
Ingress Controller
Node 2
[Not supported by viewer]
Ingress Controller
Node 1
[Not supported by viewer]
Ingress Controller
Layer 7
Load Balancer
(HTTPS)

[Not supported by viewer]
Rancher URL Request
Rancher URL Request
\ No newline at end of file diff --git a/src/img/rancher/ha/rancher2ha.svg b/src/img/rancher/ha/rancher2ha.svg index 6fcd6eda6c0..8981f454cbd 100644 --- a/src/img/rancher/ha/rancher2ha.svg +++ b/src/img/rancher/ha/rancher2ha.svg @@ -1,2 +1,2 @@ -
Rancher
Rancher
Node 1
Node 1
Node 2
Node 2
Node 3
Node 3
rancher.yourdomain.com
rancher.yourdomain.com<br>
NGINX Ingress controller
(HTTPS)
NGINX Ingress controller<br>(HTTPS)<br>
NGINX Ingress controller
(HTTPS)
NGINX Ingress controller<br>(HTTPS)<br>
NGINX Ingress controller
(HTTPS)
NGINX Ingress controller<br>(HTTPS)<br>
Rancher
Rancher
Layer 4 Load Balancer
(TCP)
Layer 4 Load Balancer<br>(TCP)<br>
\ No newline at end of file +
Rancher Cluster


[Not supported by viewer]
Rancher
[Not supported by viewer]
Node 3
[Not supported by viewer]
Ingress Controller(HTTPS)
Node 2
[Not supported by viewer]
Ingress Controller(HTTPS)
Node 1
[Not supported by viewer]
Ingress Controller(HTTPS)
Layer 4
Load Balancer
(TCP)

[Not supported by viewer]
Rancher URL Request
Rancher URL Request
\ No newline at end of file diff --git a/src/img/rancher/port-communications.svg b/src/img/rancher/port-communications.svg index 222c9159773..7953709f117 100644 --- a/src/img/rancher/port-communications.svg +++ b/src/img/rancher/port-communications.svg @@ -1,2 +1,2 @@ -

Rancher Management Plane
[Not supported by viewer]
Text
Text
Rancher Launched Kubernetes

 Nodes hosted by an IaaS. 
  • Amazon EC2
  • DigitalOcean
  • Azure
  • vSphere
[Not supported by viewer]
Rancher Launched Kubernetes

 
  Cluster with custom nodes.
[Not supported by viewer]
Imported Clusters
  • kops
  • Tectonic
  • RKE CLI
  • non-Rancher provisioned cloud cluster
[Not supported by viewer]
Hosted Kubernetes Provider

 Provisioned by Rancher.
  • Google GKE
  • Amazon EKS
  • Microsoft AKS
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
▲ Rancher Server TLS: 443
[Not supported by viewer]
▼ SSH: 22
▼ Docker Daemon TLS: 2376
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
 ▼ Kubernetes API: 6443
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
\ No newline at end of file +

Rancher Management Plane
[Not supported by viewer]
Text
Text
Rancher Launched Kubernetes

 Nodes hosted by an IaaS. 
  • Amazon EC2
  • DigitalOcean
  • Azure
  • vSphere
[Not supported by viewer]
Rancher Launched Kubernetes

 
  Cluster with custom nodes.
[Not supported by viewer]
Imported Clusters
  • kops
  • Tectonic
  • RKE CLI
  • non-Rancher provisioned cloud cluster
[Not supported by viewer]
Hosted Kubernetes Provider

 Provisioned by Rancher.
  • Google GKE
  • Amazon EKS
  • Microsoft AKS
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
▲ Rancher Server TLS: 443
[Not supported by viewer]
▼ SSH: 22
▼ Docker Daemon TLS: 2376
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
 ▼ Kubernetes API: 6443
[Not supported by viewer]
 ▲ Rancher Server TLS: 443
[Not supported by viewer]
\ No newline at end of file