Skip to content

Firewall rules

Firewall rules control ingress to worker nodes on a Provisioned cluster: protocol, port range (or ICMP type/code), and source IPv4 CIDRs. Use them to allow an office network to an application port, including traffic that arrives on an Elastic IP.

They do not filter the Kubernetes API. API reachability is exposure only.

Who can do this: member can list and get rules. Create and delete require super_admin. The cluster must be Provisioned.

What a rule controls

Every rule is ingress toward the cluster's workers. There is no egress field and no "target pod" field. Traffic that should hit a Service or Elastic IP must be allowed here (or it never reaches the node).

You set Effect
protocol tcp, udp, or icmp
port_min / port_max For tcp/udp: L4 port range. For icmp: type / code
cidrs Source IPv4 CIDRs allowed to that port range
name Optional unique label
description Optional note (max 255 characters)

Direction is always ingress. IPv6 is not supported.

Field table and validation

Create body: FirewallRuleCreateRequest (POST /v1/public/clusters/{id}/firewall-rules). Extra fields → 422. Domain errors after parse → 400.

Field Type Required Validation
protocol tcp | udp | icmp yes Other values → 422 or 400.
port_min integer tcp/udp: yes. icmp: no tcp/udp: 1–65535. icmp: 0–255, default 8 (echo-request). Schema allows 0–65535; domain rejects out-of-range.
port_max integer no tcp/udp: default = port_min (single port). Must be ≥ port_min. icmp: default 0.
cidrs string[] no Default ["0.0.0.0/0"]. At most 16. IPv4 only. Host addresses become /32. Duplicates dropped.
name string no Same DNS label as cluster names, 1–63 chars. Unique among alive rules on the cluster.
description string no Max 255 characters.

GET list/get use PublicFirewallRuleResponse (no cluster_id on the item; the list envelope has cluster_id). POST and DELETE return FirewallRuleResponse, which includes cluster_id. Same protocol/ports/CIDRs either way. Rules have no status / phase field.

Defaults when no rule exists

If you create no rules, Door does not add extra application ports for you. Platform defaults for additional worker ports are empty. Open each port you need (for example TCP 80 and 443).

A new rule is stored immediately and applied in the background (202). Re-GET the list to confirm it is present. The rule is visible in the list as soon as create returns; the dataplane catches up shortly after.

Console

API only

The console Networking tab shows Elastic IPs (Application public IPs) only. There is no firewall editor in the Door console, and Maya has no firewall action. Create and delete rules with the API calls below.

List and get

export DOOR_TOKEN
export CLUSTER_ID=3f9c1a2e-7b4d-4c58-9e21-5d6f8a0b1c2d
export ORG=acme

curl -sS \
  "https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules" \
  -H "Authorization: Bearer $DOOR_TOKEN" \
  -H "X-Door-Organization: ${ORG}"

200 → PublicFirewallRuleListResponse:

{
  "schema_version": "firewall_rule.public.v1",
  "cluster_id": "3f9c1a2e-7b4d-4c58-9e21-5d6f8a0b1c2d",
  "items": [
    {
      "id": "b2c3d4e5-1111-2222-3333-444455556666",
      "name": "office-https",
      "protocol": "tcp",
      "port_min": 443,
      "port_max": 443,
      "cidrs": ["203.0.113.0/24"],
      "description": "Office HTTPS",
      "created_at": "2026-10-01T11:00:00.000000Z",
      "updated_at": "2026-10-01T11:00:00.000000Z",
      "deleted_at": null
    }
  ],
  "total": 1
}

GET /v1/public/clusters/{id}/firewall-rules/{rule_id} → 200 or 404.

Create

POST /v1/public/clusters/{id}/firewall-rules

Success: 202 Accepted.

Example — office CIDR to a public application port (HTTPS)

This is the model the product supports (worker ingress, not the API server):

curl -sS -X POST \
  "https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules" \
  -H "Authorization: Bearer $DOOR_TOKEN" \
  -H "X-Door-Organization: ${ORG}" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "office-https",
    "protocol": "tcp",
    "port_min": 443,
    "cidrs": ["203.0.113.0/24"],
    "description": "Office HTTPS to application Elastic IP"
  }'

port_max defaults to 443. Combine with a public Elastic IP on an internet cluster and a LoadBalancer Service.

Example — ping (ICMP echo)

curl -sS -X POST \
  "https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules" \
  -H "Authorization: Bearer $DOOR_TOKEN" \
  -H "X-Door-Organization: ${ORG}" \
  -H "Content-Type: application/json" \
  -d '{"name":"allow-ping","protocol":"icmp","cidrs":["203.0.113.0/24"]}'

Omitting both ports uses type 8 / code 0.

Example — HTTP from anywhere

{
  "name": "http-public",
  "protocol": "tcp",
  "port_min": 80,
  "cidrs": ["0.0.0.0/0"]
}

Omitting cidrs is the same as 0.0.0.0/0.

Status codes (create)

Status When
202 Accepted. Rule is stored; dataplane follows.
400 Bad protocol, port range, ICMP type/code, CIDR, or too many CIDRs.
401 Missing or invalid token.
403 Not super_admin.
404 Cluster not found.
409 Cluster not Provisioned (or deleting); duplicate name.
422 Schema (missing protocol, extra fields, name pattern).

Delete

DELETE /v1/public/clusters/{id}/firewall-rules/{firewall_rule_id}

202 with the rule (deleted_at set). The dataplane removes the opening shortly after. 404 if the id is unknown. 409 if the cluster is not Provisioned.

curl -sS -X DELETE \
  "https://dks-api.apps.door.cloud/v1/public/clusters/${CLUSTER_ID}/firewall-rules/${RULE_ID}" \
  -H "Authorization: Bearer $DOOR_TOKEN" \
  -H "X-Door-Organization: ${ORG}"

There is no PATCH. To change a rule, delete it and create another.

Limits

  • At most 16 source CIDRs per rule.
  • No maximum number of rules per cluster in code. Contact your Door account team if you need a large set.
  • Names unique among alive rules on the cluster.

Maya

Maya does not ship a firewall tool. Use this API or the console if a networking form is present.