Firewall rules¶
Firewall rules control ingress to worker nodes on a Provisioned cluster: protocol, port range (or ICMP type/code), and source IPv4 CIDRs. Use them to allow an office network to an application port, including traffic that arrives on an Elastic IP.
They do not filter the Kubernetes API. API reachability is exposure only.
Who can do this: member can list and get rules. Create and delete require super_admin. The cluster must be Provisioned.
What a rule controls¶
Every rule is ingress toward the cluster's workers. There is no egress field and no "target pod" field. Traffic that should hit a Service or Elastic IP must be allowed here (or it never reaches the node).
| You set | Effect |
|---|---|
protocol | tcp, udp, or icmp |
port_min / port_max | For tcp/udp: L4 port range. For icmp: type / code |
cidrs | Source IPv4 CIDRs allowed to that port range |
name | Optional unique label |
description | Optional note (max 255 characters) |
Direction is always ingress. IPv6 is not supported.
Field table and validation¶
Create body: FirewallRuleCreateRequest (POST /v1/public/clusters/{id}/firewall-rules). Extra fields → 422. Domain errors after parse → 400.
| Field | Type | Required | Validation |
|---|---|---|---|
protocol | tcp | udp | icmp | yes | Other values → 422 or 400. |
port_min | integer | tcp/udp: yes. icmp: no | tcp/udp: 1–65535. icmp: 0–255, default 8 (echo-request). Schema allows 0–65535; domain rejects out-of-range. |
port_max | integer | no | tcp/udp: default = port_min (single port). Must be ≥ port_min. icmp: default 0. |
cidrs | string[] | no | Default ["0.0.0.0/0"]. At most 16. IPv4 only. Host addresses become /32. Duplicates dropped. |
name | string | no | Same DNS label as cluster names, 1–63 chars. Unique among alive rules on the cluster. |
description | string | no | Max 255 characters. |
GET list/get use PublicFirewallRuleResponse (no cluster_id on the item; the list envelope has cluster_id). POST and DELETE return FirewallRuleResponse, which includes cluster_id. Same protocol/ports/CIDRs either way. Rules have no status / phase field.
Defaults when no rule exists¶
If you create no rules, Door does not add extra application ports for you. Platform defaults for additional worker ports are empty. Open each port you need (for example TCP 80 and 443).
A new rule is stored immediately and applied in the background (202). Re-GET the list to confirm it is present. The rule is visible in the list as soon as create returns; the dataplane catches up shortly after.
Console¶
API only
The console Networking tab shows Elastic IPs (Application public IPs) only. There is no firewall editor in the Door console, and Maya has no firewall action. Create and delete rules with the API calls below.
List and get¶
export DOOR_TOKEN
export CLUSTER_ID=3f9c1a2e-7b4d-4c58-9e21-5d6f8a0b1c2d
export ORG=acme
curl -sS \
"https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules" \
-H "Authorization: Bearer $DOOR_TOKEN" \
-H "X-Door-Organization: ${ORG}"
200 → PublicFirewallRuleListResponse:
{
"schema_version": "firewall_rule.public.v1",
"cluster_id": "3f9c1a2e-7b4d-4c58-9e21-5d6f8a0b1c2d",
"items": [
{
"id": "b2c3d4e5-1111-2222-3333-444455556666",
"name": "office-https",
"protocol": "tcp",
"port_min": 443,
"port_max": 443,
"cidrs": ["203.0.113.0/24"],
"description": "Office HTTPS",
"created_at": "2026-10-01T11:00:00.000000Z",
"updated_at": "2026-10-01T11:00:00.000000Z",
"deleted_at": null
}
],
"total": 1
}
GET /v1/public/clusters/{id}/firewall-rules/{rule_id} → 200 or 404.
Create¶
Success: 202 Accepted.
Example — office CIDR to a public application port (HTTPS)¶
This is the model the product supports (worker ingress, not the API server):
curl -sS -X POST \
"https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules" \
-H "Authorization: Bearer $DOOR_TOKEN" \
-H "X-Door-Organization: ${ORG}" \
-H "Content-Type: application/json" \
-d '{
"name": "office-https",
"protocol": "tcp",
"port_min": 443,
"cidrs": ["203.0.113.0/24"],
"description": "Office HTTPS to application Elastic IP"
}'
port_max defaults to 443. Combine with a public Elastic IP on an internet cluster and a LoadBalancer Service.
Example — ping (ICMP echo)¶
curl -sS -X POST \
"https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules" \
-H "Authorization: Bearer $DOOR_TOKEN" \
-H "X-Door-Organization: ${ORG}" \
-H "Content-Type: application/json" \
-d '{"name":"allow-ping","protocol":"icmp","cidrs":["203.0.113.0/24"]}'
Omitting both ports uses type 8 / code 0.
Example — HTTP from anywhere¶
Omitting cidrs is the same as 0.0.0.0/0.
Status codes (create)¶
| Status | When |
|---|---|
202 | Accepted. Rule is stored; dataplane follows. |
400 | Bad protocol, port range, ICMP type/code, CIDR, or too many CIDRs. |
401 | Missing or invalid token. |
403 | Not super_admin. |
404 | Cluster not found. |
409 | Cluster not Provisioned (or deleting); duplicate name. |
422 | Schema (missing protocol, extra fields, name pattern). |
Delete¶
202 with the rule (deleted_at set). The dataplane removes the opening shortly after. 404 if the id is unknown. 409 if the cluster is not Provisioned.
curl -sS -X DELETE \
"https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules/${RULE_ID}" \
-H "Authorization: Bearer $DOOR_TOKEN" \
-H "X-Door-Organization: ${ORG}"
There is no PATCH. To change a rule, delete it and create another.
Limits¶
- At most 16 source CIDRs per rule.
- No maximum number of rules per cluster in code. Contact your Door account team if you need a large set.
- Names unique among alive rules on the cluster.
Maya¶
Maya does not ship a firewall tool. Use this API or the console if a networking form is present.