# K3s overrides firewalld rules

**URL:** <https://forums.suse.com/t/k3s-overrides-firewalld-rules/45212>\
**Category:** k3s, k3OS, and k3d\
**Created:** [February 23, 2025, 6:05pm UTC](https://forums.suse.com/t/k3s-overrides-firewalld-rules/45212 "2025-02-23T18:05:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![polpmpn1](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@polpmpn1](https://forums.suse.com/u/polpmpn1)\
**Post date:** [February 23, 2025, 6:05pm UTC](https://forums.suse.com/t/k3s-overrides-firewalld-rules/45212/1 "2025-02-23T18:05:21Z")

</div>

We have firewalld configured (via salt, of course) to open all ports _only_ to trusted networks (a mix of public IPs and private nets). A few ports like 80 and 443 are open to all IPs.

When k3s starts, traefik inserts a ton of KUBE\* rules that are processed first which causes 8443 and 8080 to be open to all IPs. We don’t want that.

This seems to be a bug and there is no actual fix, any ideas would be appreciated. I have another posting with someone having a similar issue.

[Installing k3s disables firewall port range unexpectedly - Help - NixOS Discourse](https://discourse.nixos.org/t/installing-k3s-disables-firewall-port-range-unexpectedly/46396/5)

---

<div class="post-metadata">

**Author:** ![polpmpn1](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@polpmpn1](https://forums.suse.com/u/polpmpn1)\
**Post date:** [March 4, 2025, 3:08pm UTC](https://forums.suse.com/t/k3s-overrides-firewalld-rules/45212/2 "2025-03-04T15:08:22Z")

</div>

[K3s overrides salt config of firewalld, kube injects rules that overrides · k3s-io/k3s · Discussion #11873](https://github.com/k3s-io/k3s/discussions/11873) We have even started this thread to no avail.

Anyone else have any ideas? Much appreciated
