Read-only snapshot of rancher-internal and apps-dev taken 2026-10-09 23:12:22 UTC. Environment links open Rancher and need a Rancher login.
Every cluster registered in Rancher, with Fleet agent status. Explorer links open the cluster in Rancher.
| CLUSTER | STATUS | TYPE | KUBERNETES | NODES | FLEET BUNDLES | AGENT LAST SEEN | OPEN |
|---|---|---|---|---|---|---|---|
| local Rancher | ●Ready | Rancher local (EKS, imported) | v1.34.11 | 3 | 14/24 | 2026-10-09 | Explorer ↗ |
| apps-dev featured | ●Ready | Hosted EKS (created by Rancher) | v1.35.8 | 3 | 14/14 | 2026-10-09 | Explorer ↗ |
| apps-prod | ●Ready | Hosted EKS (created by Rancher) | v1.35.8 | 3 | 13/13 | 2026-10-09 | Explorer ↗ |
| dev-machines | ●Ready | RKE2 on Elemental hosts | v1.34.7+rke2r1 | 8 | 34/38 | 2026-10-09 | Explorer ↗ |
| harvester-prod | ●Ready | Harvester HCI (imported) | v1.35.7+rke2r1 | 3 | 1/1 | 2026-10-09 | Explorer ↗ Harvester ↗ |
| harvester-chart-test | ▲Not ready | Harvester HCI (imported) | v1.35.6+rke2r1 | 1 | 3/3 | 2026-09-03 | Explorer ↗ Harvester ↗ |
| harvester-gitops-test | ▲Not ready | Harvester HCI (imported) | v1.35.6+rke2r1 | 1 | 1/2 | 2026-09-03 | Explorer ↗ Harvester ↗ |
| harvester-lab | ▲Not ready | Harvester HCI (imported) | v1.35.2+rke2r1 | 3 | 5/6 | 2026-09-11 | Explorer ↗ Harvester ↗ |
| harvester-sles-dev | ▲Not ready | RKE2 on Harvester VMs | v1.34.7+rke2r1 | 2 | 3/3 | 2026-09-03 | Explorer ↗ |
| harvester-ubuntu-dev | ▲Not ready | RKE2 on Harvester VMs | v1.34.7+rke2r1 | 2 | 3/3 | 2026-09-03 | Explorer ↗ |
| platform-services | ▲Not ready | RKE2 on Harvester VMs | v1.34.7+rke2r1 | 3 | 12/13 | 2026-09-11 | Explorer ↗ |
| tailscale-demo | ▲Not ready | RKE2 on Harvester VMs | v1.34.7+rke2r1 | 1 | 10/12 | 2026-09-03 | Explorer ↗ |
Every numbered connection, with what the snapshot observed. Gaps show where a reference flow has no configured destination. Hover a row to trace it on the diagram, or click its flow ID to jump there.
| FLOW | STATUS | SOURCE | DESTINATION | PORT | OBSERVED | PURPOSE |
|---|---|---|---|---|---|---|
| ●Active | Users / CLI | rancher.internal.krum.io (AWS NLB → Traefik) | TCP 443 HTTPS / WSS | Auth: github, local · NLB k8s-traefik-traefik-819e70a6de-97f2ab8efb9a56b1… | UI, API and kubectl through the Rancher cluster proxy; shell and log streams use WSS. | |
| ●Active | cattle-cluster-agent (11 downstream clusters) | rancher.internal.krum.io | TCP 443 WSS | apps-dev: agent v2.14.3 · 2 pods | Long-lived remotedialer tunnel. Rancher proxies API calls to the downstream cluster back through it. | |
| ●Active | rancher-system-agent (RKE2 nodes) | rancher.internal.krum.io | TCP 443 HTTPS | 5 v2prov clusters: dev-machines, harvester-sles-dev, harvester-ubuntu-dev, platform-services, tailscale-demo · not used on EKS | Watches plan secrets: RKE2 install, upgrade, etcd snapshot and restore. | |
| ●Active | fleet-agent | rancher.internal.krum.io (Fleet API) | TCP 443 HTTPS | apps-dev: 14/14 bundles ready · Fleet v0.15.4 | Pull model: reads BundleDeployments for its namespace and writes status. Works behind NAT. | |
| –Not applicable | Users / CLI | apps-dev EKS API endpoint | TCP 443 | Endpoint access: private=True public=False | Authorized Cluster Endpoint applies to RKE2/K3s. apps-dev’s EKS API is private, so kubectl always goes through the Rancher proxy. | |
| ●Active | eks-operator, rancher-machine, CAPI providers | AWS EKS API, Harvester clusters, new VMs | TCP 443 · SSH 22 · 6443 | apps-dev & apps-prod created by Rancher (imported=False) · 4 Harvester clusters | Create and manage EKS clusters, provision RKE2 guest clusters on Harvester VMs, bootstrap node-driver VMs. | |
| ●Active | Elemental hosts, Harvester VMs | rancher.internal.krum.io | TCP 443 HTTPS | 17 MachineInventories · 5 MachineRegistrations | Download the system-agent install script and register; elemental-register enrolls hosts into the inventory. | |
| ●Active | Fleet gitjob / helmops, Rancher catalogs | github.com, chart repositories | TCP 22 (Git SSH) · 443 | 13 GitRepos · 1 HelmOp · 7 cluster repos | Clone the GitOps repo into bundles and fetch Helm charts. | |
| ●Active | Rancher server | GitHub OAuth | TCP 443 | authconfig github enabled (+ local) | OAuth token exchange and org/team lookups. F9a is the browser redirect to github.com for sign-in. | |
| !Not configured | rancher-backup, Kasten K10 | Object storage (S3) | TCP 443 | rancher-backup CRD present: False · K10 profiles: 0 · policies: 0 | Nothing backs up Rancher or apps-dev workloads today. EKS etcd is AWS-managed, but Rancher objects and app data are not exported. | |
| ●Active | containerd on every node, Rancher catalogs | registry.rancher.com, registry.suse.com, public registries | TCP 443 | system-default-registry=registry.rancher.com | Image pulls and chart fetches. | |
| !Not configured | Alertmanager, log shipping | Alert & log receivers | TCP 443 | AlertmanagerConfigs: 0 · rancher-logging: not installed | Alerts fire into Alertmanager but are not routed anywhere; no logs leave the cluster. | |
| ●Active | external-dns, cert-manager (both clusters) | AWS Route 53, Let’s Encrypt ACME | TCP 443 | external-dns provider=aws upsert-only · ACME http-01 (Rancher) / dns-01 (apps-dev) | Publish ingress hostnames to Route 53 and obtain TLS certificates. | |
| ●Active | All nodes | Amazon VPC DNS, Amazon Time Sync | UDP/TCP 53 · UDP 123 | AWS-provided defaults | Name resolution for the Rancher hostname and destinations; time sync for TLS. | |
| ●Active | External Secrets Operator (both clusters) | 1Password | TCP 443 | ClusterSecretStore onepassword ready · 1 ExternalSecret on apps-dev | Sync secrets from 1Password vaults into Kubernetes Secrets. | |
| ●Active | Epinio (Dex), OpenEverest, browsers | Rancher OIDC provider (rancher.internal.krum.io/oidc) | TCP 443 | OIDC clients: epinio, everest-apps-dev, everest-apps-prod | Platform UIs sign users in with their Rancher identity; the Rancher Epinio extension calls the Epinio API directly (CORS allows the Rancher origin). |
In-cluster traffic (green): NLB → Traefik → Rancher service HTTP 80; Rancher, Fleet, Turtles and operators → EKS API 443; EKS API → rancher-webhook 9443; agents → apps-dev EKS API.
Ingress and platform certificates on both clusters, soonest expiry first. cert-manager renews them automatically about 30 days before expiry.
| CLUSTER | CERTIFICATE | DNS NAMES | ISSUER | EXPIRES | REMAINING |
|---|---|---|---|---|---|
| rancher-internal | cattle-system/tls-ingress-rancher | rancher.internal.krum.io | rancher | 2026-11-13 | ●34 days |
| apps-dev | traefik/wildcard-tls | apps-dev.internal.krum.io, *.apps-dev.internal.krum.io | letsencrypt-dns01 | 2026-11-14 | ●35 days |
| apps-dev | epinio/dex-tls | auth.apps-dev.internal.krum.io | letsencrypt-dns01 | 2026-11-17 | ●38 days |
| apps-dev | epinio/epinio | epinio.apps-dev.internal.krum.io | letsencrypt-dns01 | 2026-11-17 | ●38 days |
| apps-dev | cert-manager/epinio-ca | - | selfsigned-issuer | 2026-11-17 | ●38 days |
| apps-dev | epinio/epinio-registry | registry.epinio.svc.cluster.local | epinio-ca | 2026-11-17 | ●38 days |
| apps-dev | everest-system/everest-tls | everest.apps-dev.internal.krum.io | letsencrypt-dns01 | 2026-11-30 | ●51 days |
What runs in this environment, with live status. Filled buttons open the component in this environment; Docs opens its public documentation.
Data: read-only kubectl snapshot of rancher-internal and apps-dev (collect.py). Logos are the projects’ own artwork, shown to identify each component; lettered tiles stand in where none was available.