Krumware Rancher Environment
© 2026 Krumware LLC
Rancher
v2.14.3
rancher.internal.krum.io · Prime
Managed clusters ready
5 / 12
7 lab clusters not ready
apps-dev Fleet bundles
14/14
13 GitRepos from one GitOps repo
apps-dev Epinio apps
78
in 14 namespaces
Certificates expiring in 45 days
8
next: tls-ingress-rancher in 34 d
Configuration gaps
4
Rancher backups · Kasten policies · Alert receivers · Log shipping

Read-only snapshot of rancher-internal and apps-dev taken 2026-10-09 23:12:22 UTC. Environment links open Rancher and need a Rancher login.

LOCAL CLUSTER · RANCHER-INTERNAL Amazon EKS v1.34.11 · 3 × t3a.large · us-east-1a / 1b / 1c
DOWNSTREAM · APPS-DEVAmazon EKS v1.35.8 · hosted, created by Rancher · 3 × t3a.large · +10 more clusters
Krumware · Rancher Prime environment
Deployment network
Rancher v2.14.3 on Amazon EKS v1.34.11  ·  rancher.internal.krum.io  ·  11 downstream clusters  ·  featured: apps-dev
Hover or tap any box, arrow or flow label for live details. Click to pin; Esc to close.
Core connection Optional / configured In-cluster traffic healthydegradednot deployednot configured Snapshot 2026-10-09 23:12:22 UTC
CONFIGURED DESTINATIONS
Users / CLI
Rancher UI · kubectl via cluster proxy
Sign-in: GitHub + Local · Rancher AI
Joining nodes
17 Elemental inventories (5 registrations) · RKE2 VMs on Harvester
F7 · dev-machines: anchor ×3 · gpu-worker ×3 · test ×2
4/4
Ingress · Traefik v3.3.2 · AWS NLB
rancher.internal.krum.io:443 · Let’s Encrypt (ACME http-01) · external-dns → Route 53
4/4
Rancher v2.14.3
cattle-system · 2 replicas · Prime
GitHub auth · OIDC provider (/oidc)
Cluster proxy · tunnel server
AI agent + MCP · SCC operator
1/1
Provisioning
v2prov
eks-operator v1.14.6
6 node drivers
5 RKE2 clusters
4/4
Fleet v0.15.4
cattle-fleet-system
13 GitRepos · 1 HelmOp
krumIO/fleet-rancher-
internal-gitops (main)
5/5
Turtles v0.26.3
cattle-turtles-system
CAPI v1.12.7
RKE2 providers v0.21.1 · CAPHV v0.2.9
3/3
Webhook & operators
rancher-webhook v0.10.7
elemental-operator 1.9.1
harvester-config-server
Not deployed
Rancher Backups
rancher-backup operator
Not installed. Rancher state lives only in the EKS-managed etcd.
9/9
AWS
Amazon EKS v1.34.11 · AWS-managed API server + etcd
3 × t3a.large · AL2023 · containerd 2.2.5 · VPC CNI · CoreDNS · EBS CSI
Add-ons: AWS LB controller · external-dns · external-secrets → 1Password
3/3
Rancher agents
cattle-system · cattle-fleet-system
cattle-cluster-agent
2 pods · WSS tunnel to Rancher (F2)
fleet-agent
v0.15.4 · 14/14 bundles ready (F4)
rancher-webhook
v0.10.7 · admission for Rancher RBAC
rancher-system-agent
n/a on EKS · used by 5 RKE2 clusters (F3)
system-upgrade-controller
n/a · EKS upgrades via eks-operator
6/6
AWSEKS v1.35.8
nodegroup workers01 · 3 × t3a.large
zones 1a / 1b / 1c · API endpoint: private only
VPC CNI v1.23.2 · CoreDNS v1.13.2
Traefik v3.6.10 · NLB · EBS CSI
9/9
OBSERVABILITY
rancher-monitoring
Prometheus v3.5.0 · 10d retention · emptyDir
Grafana 12.1.1 · Alertmanager: 0 receivers
Logging
rancher-logging not installed · Everest ships its own VictoriaMetrics operator
17/17
STORAGE & BACKUP
AWSAmazon EBS CSI
v1.66.0 · storage classes ebs, gp2
etcd: AWS-managed (no snapshots to manage)
K10Kasten K10 8.5.7
0 policies · 0 location profiles · not protecting anything yet
7/7
SECURITY & POLICY
cert-manager v1.20.2
letsencrypt-dns01 (Route 53) · 19 certs incl. *.apps-dev wildcard
ESOExternal Secrets v2.5.0
ClusterSecretStore onepassword → 1Password
NeuVector · Kubewarden · Compliance
Not installed
5/12 ready
OTHER MANAGED CLUSTERS
Harvester HCI · 4
gitops-test*, prod, chart-test*, lab*
RKE2 guest clusters on Harvester VMs: 4
dev-machines · Elemental
8 nodes on Proxmox / HP hosts · apps-prod: EKS
* not ready at snapshot
12/12
PLATFORM · APP DELIVERY
Epinio v1.14.2
78 apps in 14 namespaces · 16 catalog services · 5 app charts
Dex v2.45.1 · registry · SeaweedFS S3 · Paketo buildpacks
11/11
PLATFORM · DATABASES
EVOpenEverest 1.15.2
Percona operators: PostgreSQL · MongoDB · MySQL (PXC)
0 database clusters · sign-in via Rancher OIDC
1/1
PLATFORM · TENANCY
k3kSUSE Virtual Clusters
k3k 1.0.2 · K3s-in-pods
0 virtual clusters running
F9
GHGitHub OAuth
Rancher → github.com / api.github.com: HTTPS 443
Browser redirect for sign-in (F9a) · local users as fallback
F8
GHGit & Helm sources
git@github.com:krumIO/fleet-rancher-internal-gitops: SSH 22
7 cluster repos · charts.external-secrets.io (HelmOp) · 443
F6
AWSAWS & Harvester APIs
Amazon EKS API us-east-1 (apps-dev, apps-prod): HTTPS 443
4 Harvester clusters · node drivers: amazonec2, azure, digitalocean…
F11
Image & chart registries
registry.rancher.com (system-default) · registry.suse.com
docker.io · quay.io · ghcr.io · gcr.io (Kasten) · ECR: 443
F13
AWSLERoute 53 & Let’s Encrypt
external-dns → Route 53 API (upsert-only) · 443
cert-manager ACME: http-01 (Rancher) · dns-01 (*.apps-dev)
F15
1P1Password
External Secrets → 1Password SDK · HTTPS 443
ClusterSecretStore onepassword · both clusters
F10
not configured
AWSK10Backup storage
No rancher-backup target · Kasten: 0 location profiles
Recommended: S3 bucket for rancher-backup + K10
F12
not configured
Alert & log destinations
Alertmanager running with 0 receivers
No log shipping (rancher-logging not installed)
F14 DNS: Amazon VPC resolver · NTP: Amazon Time Sync (AL2023 default)    Node-to-node (EKS) kubelet 10250 · VPC CNI pod IPs from the VPC (no overlay) · 30000–32767 NodePort (Epinio registry :30500)
apps-dev needs no inbound connection from Rancher: its agents dial out to rancher.internal.krum.io (F2, F4) and Rancher reaches the private EKS API back through the F2 tunnel. Images come from registry.rancher.com by default. Values from a read-only snapshot; re-run collect.py to refresh.
© 2026 Krumware LLC · krum.io
F1 · 443F2 · F3 · F4443 WSS / HTTPSF7F9a · browser GitHub OAuth redirectHTTP 804439443F9F6F8F11F13F15

Managed clusters

Every cluster registered in Rancher, with Fleet agent status. Explorer links open the cluster in Rancher.

CLUSTERSTATUSTYPEKUBERNETESNODESFLEET BUNDLESAGENT LAST SEENOPEN
local RancherReadyRancher local (EKS, imported)v1.34.11314/242026-10-09Explorer ↗
apps-dev featuredReadyHosted EKS (created by Rancher)v1.35.8314/142026-10-09Explorer ↗
apps-prodReadyHosted EKS (created by Rancher)v1.35.8313/132026-10-09Explorer ↗
dev-machinesReadyRKE2 on Elemental hostsv1.34.7+rke2r1834/382026-10-09Explorer ↗
harvester-prodReadyHarvester HCI (imported)v1.35.7+rke2r131/12026-10-09Explorer ↗ Harvester ↗
harvester-chart-testNot readyHarvester HCI (imported)v1.35.6+rke2r113/32026-09-03Explorer ↗ Harvester ↗
harvester-gitops-testNot readyHarvester HCI (imported)v1.35.6+rke2r111/22026-09-03Explorer ↗ Harvester ↗
harvester-labNot readyHarvester HCI (imported)v1.35.2+rke2r135/62026-09-11Explorer ↗ Harvester ↗
harvester-sles-devNot readyRKE2 on Harvester VMsv1.34.7+rke2r123/32026-09-03Explorer ↗
harvester-ubuntu-devNot readyRKE2 on Harvester VMsv1.34.7+rke2r123/32026-09-03Explorer ↗
platform-servicesNot readyRKE2 on Harvester VMsv1.34.7+rke2r1312/132026-09-11Explorer ↗
tailscale-demoNot readyRKE2 on Harvester VMsv1.34.7+rke2r1110/122026-09-03Explorer ↗

Flow register

Every numbered connection, with what the snapshot observed. Gaps show where a reference flow has no configured destination. Hover a row to trace it on the diagram, or click its flow ID to jump there.

FLOWSTATUSSOURCEDESTINATIONPORTOBSERVEDPURPOSE
ActiveUsers / CLIrancher.internal.krum.io (AWS NLB → Traefik)TCP 443 HTTPS / WSSAuth: github, local · NLB k8s-traefik-traefik-819e70a6de-97f2ab8efb9a56b1…UI, API and kubectl through the Rancher cluster proxy; shell and log streams use WSS.
Activecattle-cluster-agent (11 downstream clusters)rancher.internal.krum.ioTCP 443 WSSapps-dev: agent v2.14.3 · 2 podsLong-lived remotedialer tunnel. Rancher proxies API calls to the downstream cluster back through it.
Activerancher-system-agent (RKE2 nodes)rancher.internal.krum.ioTCP 443 HTTPS5 v2prov clusters: dev-machines, harvester-sles-dev, harvester-ubuntu-dev, platform-services, tailscale-demo · not used on EKSWatches plan secrets: RKE2 install, upgrade, etcd snapshot and restore.
Activefleet-agentrancher.internal.krum.io (Fleet API)TCP 443 HTTPSapps-dev: 14/14 bundles ready · Fleet v0.15.4Pull model: reads BundleDeployments for its namespace and writes status. Works behind NAT.
Not applicableUsers / CLIapps-dev EKS API endpointTCP 443Endpoint access: private=True public=FalseAuthorized Cluster Endpoint applies to RKE2/K3s. apps-dev’s EKS API is private, so kubectl always goes through the Rancher proxy.
Activeeks-operator, rancher-machine, CAPI providersAWS EKS API, Harvester clusters, new VMsTCP 443 · SSH 22 · 6443apps-dev & apps-prod created by Rancher (imported=False) · 4 Harvester clustersCreate and manage EKS clusters, provision RKE2 guest clusters on Harvester VMs, bootstrap node-driver VMs.
ActiveElemental hosts, Harvester VMsrancher.internal.krum.ioTCP 443 HTTPS17 MachineInventories · 5 MachineRegistrationsDownload the system-agent install script and register; elemental-register enrolls hosts into the inventory.
ActiveFleet gitjob / helmops, Rancher catalogsgithub.com, chart repositoriesTCP 22 (Git SSH) · 44313 GitRepos · 1 HelmOp · 7 cluster reposClone the GitOps repo into bundles and fetch Helm charts.
ActiveRancher serverGitHub OAuthTCP 443authconfig github enabled (+ local)OAuth token exchange and org/team lookups. F9a is the browser redirect to github.com for sign-in.
Not configuredrancher-backup, Kasten K10Object storage (S3)TCP 443rancher-backup CRD present: False · K10 profiles: 0 · policies: 0Nothing backs up Rancher or apps-dev workloads today. EKS etcd is AWS-managed, but Rancher objects and app data are not exported.
Activecontainerd on every node, Rancher catalogsregistry.rancher.com, registry.suse.com, public registriesTCP 443system-default-registry=registry.rancher.comImage pulls and chart fetches.
Not configuredAlertmanager, log shippingAlert & log receiversTCP 443AlertmanagerConfigs: 0 · rancher-logging: not installedAlerts fire into Alertmanager but are not routed anywhere; no logs leave the cluster.
Activeexternal-dns, cert-manager (both clusters)AWS Route 53, Let’s Encrypt ACMETCP 443external-dns provider=aws upsert-only · ACME http-01 (Rancher) / dns-01 (apps-dev)Publish ingress hostnames to Route 53 and obtain TLS certificates.
ActiveAll nodesAmazon VPC DNS, Amazon Time SyncUDP/TCP 53 · UDP 123AWS-provided defaultsName resolution for the Rancher hostname and destinations; time sync for TLS.
ActiveExternal Secrets Operator (both clusters)1PasswordTCP 443ClusterSecretStore onepassword ready · 1 ExternalSecret on apps-devSync secrets from 1Password vaults into Kubernetes Secrets.
ActiveEpinio (Dex), OpenEverest, browsersRancher OIDC provider (rancher.internal.krum.io/oidc)TCP 443OIDC clients: epinio, everest-apps-dev, everest-apps-prodPlatform UIs sign users in with their Rancher identity; the Rancher Epinio extension calls the Epinio API directly (CORS allows the Rancher origin).

In-cluster traffic (green): NLB → Traefik → Rancher service HTTP 80; Rancher, Fleet, Turtles and operators → EKS API 443; EKS API → rancher-webhook 9443; agents → apps-dev EKS API.

Platform certificates

Ingress and platform certificates on both clusters, soonest expiry first. cert-manager renews them automatically about 30 days before expiry.

CLUSTERCERTIFICATEDNS NAMESISSUEREXPIRESREMAINING
rancher-internalcattle-system/tls-ingress-rancherrancher.internal.krum.iorancher2026-11-1334 days
apps-devtraefik/wildcard-tlsapps-dev.internal.krum.io, *.apps-dev.internal.krum.ioletsencrypt-dns012026-11-1435 days
apps-devepinio/dex-tlsauth.apps-dev.internal.krum.ioletsencrypt-dns012026-11-1738 days
apps-devepinio/epinioepinio.apps-dev.internal.krum.ioletsencrypt-dns012026-11-1738 days
apps-devcert-manager/epinio-ca-selfsigned-issuer2026-11-1738 days
apps-devepinio/epinio-registryregistry.epinio.svc.cluster.localepinio-ca2026-11-1738 days
apps-deveverest-system/everest-tlseverest.apps-dev.internal.krum.ioletsencrypt-dns012026-11-3051 days

Component index

What runs in this environment, with live status. Filled buttons open the component in this environment; Docs opens its public documentation.

SUSE & RANCHER

KUBERNETES & AWS

PLATFORM SERVICES (APPS-DEV)

Data: read-only kubectl snapshot of rancher-internal and apps-dev (collect.py). Logos are the projects’ own artwork, shown to identify each component; lettered tiles stand in where none was available.