IP addresses and DNS

Record these addresses and names before opening the installation wizard. Use Firewall requirements for the connections to allow.

Address plan

Input Requirement

Management hostname and host address

A DNS name resolving to the host address reachable by operator workstations. The Management hostname is fixed for initialized Management state.

Management internal address

A private RFC1918 address, default 10.41.0.1, that does not overlap the Management bridge, Kubernetes networks or networks Management needs to reach. This is separate from the host’s LAN address and is fixed for initialized Management state.

Cluster and nodes

A lowercase cluster name and node names; one static IPv4 address per appliance node. Separate node DNS names are not installation inputs.

Shared appliance subnet

All appliance nodes and their gateway on one subnet. The installation wizard accepts a subnet prefix from 1 to 29.

Application endpoint

A free load-balancer IPv4 address in the node subnet and an application hostname resolving to that address.

The application endpoint serves ERS and the optional customer metrics interface. Administrative connections use individual appliance node IPs; no separate Kubernetes API DNS record or load-balancer address is needed.

DNS and time services

Provide one to four DNS server IPv4 addresses and one to four NTP server addresses or hostnames for appliance nodes. Management host setup uses its own network configuration and one NTP source.

Operator workstations must resolve the Management hostname. Application clients must resolve the application hostname to its load-balancer address.

For an air-gapped installation, provide DNS and NTP services inside the deployment network. Configure your own DNS records instead of depending on the wizard’s public sslip.io fallback names.

Proxies and integration endpoints

Record HTTP/HTTPS proxy addresses, authentication if required and the NO_PROXY destinations for the appliance network.

Record the addresses of any HSM, application integration, customer monitoring, Syslog receiver or external backup services you will use.

Next step

Configure the firewall rules for the planned addresses.