Network and egress IPs: allow them on the AKS and service firewalls
Every connection from Kubepier Web to your clusters and services leaves from fixed IPs. If an endpoint only accepts some IPs, such as AKS authorized IP ranges, allow these on the firewall. In the app, the same list is under the Network and security menu.
Kubepier Web egress IPs
The IP list shows up here and in the app, under the Network and security menu.
The same IPs apply to every Kubepier Web customer. Allow every IP on the list.
Where to allow
| Service | Where to allow |
|---|---|
| AKS | API server authorized IP ranges: in the portal, under the cluster networking, or with az aks update --api-server-authorized-ip-ranges. |
| EKS | Public access CIDRs of the public endpoint: in the console, under the cluster networking, or with aws eks update-cluster-config. |
| GKE | Master authorized networks (control plane authorized networks): in the console or with gcloud container clusters update. |
| Other clusters and on-premises | The firewall or security group in front of the Kubernetes API (usually port 6443 or 443). |
| MongoDB Atlas | In the portal: Network Access → IP Access List → Add IP Address. |
| Azure Service Bus | In the portal: the namespace → Networking → Selected networks, then add the IPs to the firewall. Check that the namespace tier supports IP rules. |
| RabbitMQ | The server firewall or security group, for the management API port (the URL saved on the client). For managed RabbitMQ, the provider’s IP list, in the portal. |
| Redis | The server firewall or security group, or the managed service’s IP list, in the portal (Azure Cache for Redis: Firewall; ElastiCache: security group). |
| SQL and Kafka | Kubepier Web does not connect to them today: the Dependencies panel is desktop-only and only reads the pod variables and the ConfigMaps they reference. If the web starts querying these services, the connection will leave from the same IPs. |
Authorized IP ranges: commands for AKS, EKS and GKE
# AKS
az aks update -g <resource-group> -n <cluster> \
--api-server-authorized-ip-ranges <ip-1>/32,<ip-2>/32,<already-allowed-ips>
# EKS
aws eks update-cluster-config --name <cluster> \
--resources-vpc-config endpointPublicAccess=true,publicAccessCidrs="<ip-1>/32,<ip-2>/32,<already-allowed-ips>"
# GKE
gcloud container clusters update <cluster> --enable-master-authorized-networks \
--master-authorized-networks <ip-1>/32,<ip-2>/32,<already-allowed-ips> These commands replace the current list: include the IPs that are already allowed.
How the list is published
- The list comes from app.kubepier.com.br/api/rede/ips-saida and only shows here once it is configured in production.
- When the list changes, it changes here and in the app within minutes (the answer is cached for 5 minutes).
Before you allow them
- The IPs are the same for every Kubepier Web customer: a network layer on top of credentials, never a replacement.
- Fully private services cannot be reached by the Direct route: use the Through the cluster route in the service form, or Kubepier Desktop over your VPN. The API of a fully private cluster can only be reached from the desktop.