Ports and Privileges
What a running Racora opens on its nodes and in the cluster, and which of its workloads the Kubernetes Pod Security levels forbid. The Open5GS rows apply when the Open5GS core provider runs; an external core runs none of them.
Ports
What listens, and where. Nothing below authenticates on its own; what a host or a NodePort exposes is yours to fence.
| Port | Where | What |
|---|---|---|
| 6443/TCP | control node host | the k3s API server (k3s platform); the join token authorises workers. Between nodes k3s also needs 8472/UDP (flannel VXLAN) and 10250/TCP (kubelet), per k3s's networking requirements |
| 30300/TCP | every node (NodePort) | Grafana, readable by anyone as the anonymous Viewer; the login, what does not persist, and how to keep it private are on Read Logs and Traces |
| 9999/TCP, 27017/TCP | control node host network | the Open5GS WebUI and MongoDB. MongoDB binds 127.0.0.1. The WebUI binds the address the node's hostname resolves to, the loopback alias 127.0.1.1 on a stock Ubuntu host; check with ss -ltnp | grep 9999, and reach it over ssh -L 9999:127.0.1.1:9999 <control node> (Open5GS) |
| 38412/SCTP, 2152/UDP | control node host network | the Open5GS core (NGAP and GTP-U): the provider runs hostNetwork, so its AMF and UPF ports are the host's |
| 38472/SCTP, 38462/SCTP | cluster-internal (ClusterIP) | CU-CP F1-C and E1 |
| 8001/TCP | cluster-internal | the CU-CP metrics and runtime-command WebSocket, unauthenticated |
| 8001/TCP | each DU pod, no Service | the DU's own runtime-command WebSocket, unauthenticated (Runtime Commands) |
| 2152/UDP | the CU-UP pod IP | NG-U (N3) toward the UPF; an external UPF must reach it (Configure the 5G Core) |
| 2153/UDP | the CU-UP pod IP | F1-U from the DUs |
| 2000/TCP | a zmq DU's Service | the transmit side of a virtual radio (How Radios Are Driven) |
| 8815/TCP | cluster-internal | the CU-IP Flight endpoint |
| 4317, 4318/TCP | cluster-internal | the OpenTelemetry collector (OTLP); Tempo and ClickHouse behind it |
Namespaces and Privileges
The chart creates six namespaces: racora-system, centralized-unit, distributed-unit,
5g-core, user-equipment, monitoring. Four of them run workloads the baseline Pod
Security level forbids:
| Namespace | Why |
|---|---|
centralized-unit | CU-CP and CU-UP add the SYS_NICE, IPC_LOCK and PERFMON capabilities |
distributed-unit | every DU adds the same three capabilities; a real-radio DU also claims the USRP device and runs on isolated cores |
5g-core | the Open5GS provider runs hostNetwork and privileged |
racora-system | the USRP device plugin is privileged (it mounts the kubelet's device-plugin socket and /sys/bus/usb) |
On the k3s platform no Pod Security level is enforced by default. On a cluster that
enforces baseline, exempt these four namespaces before installing. Under restricted,
exempt every Racora namespace: no Racora workload sets the non-root user, seccomp profile
and dropped capabilities that level demands.