# Security: Tunnel between cattle-cluster-agent and cluster controller

**URL:** <https://forums.suse.com/t/security-tunnel-between-cattle-cluster-agent-and-cluster-controller/20074>\
**Category:** SUSE Rancher Prime\
**Created:** [April 16, 2021, 6:36am UTC](https://forums.suse.com/t/security-tunnel-between-cattle-cluster-agent-and-cluster-controller/20074 "2021-04-16T06:36:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dlandtwing](https://avatars.discourse-cdn.com/v4/letter/d/9de053/32.png) [@dlandtwing](https://forums.suse.com/u/dlandtwing)\
**Post date:** [April 16, 2021, 6:36am UTC](https://forums.suse.com/t/security-tunnel-between-cattle-cluster-agent-and-cluster-controller/20074/1 "2021-04-16T06:36:37Z")

</div>

Hello

We are looking to use Rancher primarily for centralized access management in a multi-cloud scenario with imported clusters.

In the architecture overview it says that the cattle-cluster-agent opens a connection/tunnel to the Rancher cluster controller. This is a concern for our security team as they usually only allow outbound connection from our DMZ unless inbound connections are absolutely needed, so they’ve asked me to clarify:

- Is there any way to use imported clusters without requiring inbound connections to the cluster controller?
- Has this tunnel been specifically pentested and/or assessed from a security perspective?
- What was the reasoning behind the decision to establish the connection/tunnel from the cattle-cluster-agent to the cluster controller and not the other way around?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [April 16, 2021, 6:56pm UTC](https://forums.suse.com/t/security-tunnel-between-cattle-cluster-agent-and-cluster-controller/20074/2 "2021-04-16T18:56:47Z")

</div>

- No. How is opening up “n” holes (one for every cluster) instead of a single one for the server an improvement to them?
- It’s a regular WebSocket over TLS; the cluster is identified by the api key it sends.
- The vast majority of users have much bigger problems with requiring every cluster to be reachable from the server rather than the one server be reachable from every cluster.
  - Restricted inbound to a cluster is a naturally-occurring situation in a private network/behind a NAT, with no particularly desirable solutions possible.
  - Restricting outbound communication from a cluster is non-existent by default, has to be specifically setup, and if you’re setting it up you can just add an exception, of which you probably already need many for the cluster to do anything useful like pull images.
  - If you want to be able to talk to the API for anything (including the UI), the server needs to be exposed to all those users anyway.

---

<div class="post-metadata">

**Author:** ![dlandtwing](https://avatars.discourse-cdn.com/v4/letter/d/9de053/32.png) [@dlandtwing](https://forums.suse.com/u/dlandtwing)\
**Post date:** [April 19, 2021, 6:57am UTC](https://forums.suse.com/t/security-tunnel-between-cattle-cluster-agent-and-cluster-controller/20074/3 "2021-04-19T06:57:10Z")

</div>

Thanks vincent, that makes it clearer!

---

<div class="post-metadata">

**Author:** ![sandersbud4](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sandersbud4/32/7463_2.png) [@sandersbud4](https://forums.suse.com/u/sandersbud4)\
**Post date:** [April 21, 2021, 11:01am UTC](https://forums.suse.com/t/security-tunnel-between-cattle-cluster-agent-and-cluster-controller/20074/4 "2021-04-21T11:01:51Z")

</div>

@dlandtwing In near my eyes view there no way to use imported clusters. It is regular WebSocket over TLS the cluster is identified by the api key it sends. 🙂
