This topic describes the default ports for the control plane of MyBase .
Protocol | Visitor | Target Machine | Service listener port | Purpose | Notes |
TCP | Outside the cluster | Any | 22 | SSH service | None |
TCP | Outside the cluster | Control plane | 9000 | Internal CI/CD tool for accessing DTS interfaces | None |
TCP | Outside the cluster | Data plane | 30000:32768 | Database host port (random) | None |
TCP | Inside the cluster | Control plane | 2379 | etcd metadata service | None |
TCP | Inside the cluster | Control plane | 2380 | etcd metadata service | None |
TCP | Inside the cluster | Control plane | 3306 | Metadatabase | None |
TCP | Inside the cluster | Control plane, data plane | 3308 | Database disaster recovery service | None |
TCP | Inside the cluster | Control plane | 3600:3900 | Metadatabase | None |
TCP | Inside the cluster | Any | 4010:4012 | Image distribution service | None |
TCP | Inside the cluster | Any | 4243 | Container daemon service | None |
TCP | Inside the cluster | Control plane | 5000:5001 | Container image repository | None |
TCP | Inside the cluster | Control plane | 6443 | Kubernetes apiserver | None |
TCP | Inside the cluster | Control plane | 6666 | OS maintenance service (mock_iclone) | None |
TCP | Inside the cluster | Any | 6999 | OS host service, used for the OS service daemon | None |
TCP | Inside the cluster | Control plane | 8080 | coredns | None |
TCP | Inside the cluster | Control plane | 8081 | Image service | None |
TCP | Inside the cluster | Control plane | 8082:8083 | Configuration service | None |
TCP | Inside the cluster | Control plane | 8085 | API server | None |
TCP | Inside the cluster | Any | 8110 | Data disaster recovery | None |
TCP | Inside the cluster | Control plane | 8180 | Internal ib master for scheduling jobs and tasks | None |
TCP | Inside the cluster | Control plane | 8280 | Internal ib worker for downloading apps | None |
TCP | Inside the cluster | Control plane | 8889:8999 | Distribution service | None |
TCP | Inside the cluster | Any | 9100 | Node performance monitoring and collection | None |
TCP | Inside the cluster | Control plane | 9153 | coredns management | None |
TCP | Inside the cluster | Control plane, data plane | 9998 | DTS management service | None |
TCP | Inside the cluster | Control plane | 10240:10245 | Apsara Nuwa service (ensures data synchronization between nodes) | None |
TCP | Inside the cluster | Any | 10249 | kube-proxy | None |
TCP | Inside the cluster | Any | 10250 | kubelet | None |
TCP | Inside the cluster | Any | 10255 | kubelet | None |
TCP | Inside the cluster | Any | 10256 | kube-proxy | None |
TCP | Inside the cluster | Control plane | 10257 | kube-scheduler | None |
TCP | Inside the cluster | Control plane | 10259 | kube-controller-manager | None |
TCP | Inside the cluster | Any | 10800:10802 | Database performance collection service | None |
TCP | Inside the cluster | Control plane | 10927:10930 | webhook service | None |
TCP | Inside the cluster | Any | 11023 | Network security protection | None |
TCP | Inside the cluster | Control plane | 11111 | Internal certificate service | None |
TCP | Inside the cluster | Data plane (DAS) | 11211 | Internal log service | None |
TCP | Inside the cluster | Control plane | 11444:11446 | Capacity management service | None |
TCP | Inside the cluster | Control plane | 11600:11900 | xdb instance | None |
TCP | Inside the cluster | Control plane | 12060 | Permission isolation service | None |
TCP | Inside the cluster | Control plane | 12344 | Proxy SSL service | None |
TCP | Inside the cluster | Any | 12345:12351 | Internal network plug-in | None |
TCP | Inside the cluster | Any | 12399 | Internal network plug-in | None |
TCP | Inside the cluster | Any | 13579 | Log service | None |
TCP | Inside the cluster | Control plane | 15678 | xdb management | None |
TCP | Inside the cluster | Any | 15757 | Monitoring client | None |
TCP | Inside the cluster | Control plane | 17390 | API server | None |
TCP | Inside the cluster | Control plane, data plane (DTS) | 17000:18000 | DTS data service | None |
TCP | Inside the cluster | Any | 18080:18090 | Data monitoring service | None |
TCP | Inside the cluster | Any | 18097 | Data synchronization service | None |
TCP | Inside the cluster | Any | 18100:18299 | Data monitoring service | None |
TCP | Inside the cluster | Control plane | 18765:18766 | xdb management | None |
TCP | Inside the cluster | Control plane | 19334 | Image service | None |
TCP | Inside the cluster | Control plane | 22019 | Internal web service | None |
TCP | Inside the cluster | Control plane | 22377 | etcd management | None |
TCP | Inside the cluster | Any | 24242 | Tianji client | None |
TCP | Inside the cluster | Any | 26443 | kube-api reverse proxy | None |
TCP | Inside the cluster | Control plane, data plane | 28080 | Disaster recovery service | None |
TCP | Inside the cluster | Any | 30000:32768 | Kubernetes random port service | None |
TCP | Inside the cluster | Control plane | 33060 | xdb instance | None |
TCP | Inside the cluster | Control plane | 45661:45669 | Data synchronization service | 1125: The Tianji service is abnormal. To resolve this, add port 45661. |
TCP | Inside the cluster | Control plane | 45678 | Tianji Host Service | None |
TCP | Inside the cluster | Any | 59060 | Database monitoring and collection service | None |
TCP | Inside the cluster | Any | 32768:61000 | Linux random port, for services that start on a random port | This entry is necessary because iptables rejects all ports in the current test plan. Alternatively, run the following command: iptables -A ICBC_Whitelist -m state --state RELATED,ESTABLISHED -m comment --comment SRS_SET_UP_FLG__RELATED -j ACCEPT. You do not need to open this port range if you confirm that the internal cloud firewall does not cause this issue. |
TCP | Inside the cluster | Data plane (PolarDB-X) | 3000:4000 |
| None |
TCP | Inside the cluster | Data plane (PolarDB-X) | 11000:12000 | Access between the three replicas of a PolarDB-X data node, including the global meta service (GMS) | None |
TCP | Inside the cluster | Data plane (PolarDB-X) | 28000:29000 | Proprietary protocol (RPC) connections between PolarDB-X compute nodes and storage nodes | None |
TCP | Inside the cluster | Data plane (PolarDB-X) | 4000:5000 | NC port, used for binary logging (binlog) transmission during cross-machine reconstruction tasks when an instance node fails | None |
UDP | Inside the cluster | Control plane | 53 | Internal DNS service | None |
UDP | Inside the cluster | Any | 67:68 | DHCP service | None |
UDP | Inside the cluster | Any | 111 | RPC listener service | None |
UDP | Inside the cluster | Control plane | 123 | Internal NTP service | None |
UDP | Inside the cluster | Any | 323 | Internal NTP service | None |
UDP | Inside the cluster | Any | 800:1000 | RPC service random port | None |
UDP | Inside the cluster | Any | 1123 | Internal NTP service | None |
UDP | Inside the cluster | Any | 8472 | Nimitz VXLAN communication | None |
UDP | Inside the cluster | Any | 12351 | Nimitz VXLAN communication | None |