From / To Rancher Nodes Hosted / Imported Cluster External Rancher Load Balancer Internet
Rancher Nodes (1) Kubernetes API
Endpoint Port (2)
git.rancher.io
8443 TCP
9443 TCP
Hosted / Imported Cluster 443 TCP (4)(5) 443 TCP (5)
Kubernetes API Clients Cluster / Provider Specific (6)
Workload Client Cluster / Provider Specific (7)
Notes:

1. Nodes running standalone server or Rancher HA deployment.
2. Only for hosted clusters.
3. Required to fetch Rancher chart library.
4. Only without external load balancer.
5. From worker nodes.
6. For direct access to the Kubernetes API without Rancher.
7. Usually Ingress backed by infrastructure load balancer and/or nodeport.