First boot switches the VM's own firewall on: ufw is enabled with the rules K3s documents for a node that keeps ufw on — 22, 80 and 443 allowed, the pod (10.42.0.0/16) and service (10.43.0.0/16) networks allowed, and 6443 deliberately not allowed — and first boot re-proves the cluster through it (node Ready, CoreDNS running, the ingress answering on :80) before it reports done. The current image (2026.1001.1516, K3s v1.36.5+k3s1) keeps this; its image-verify run found ufw active with 6443 not allowed.
If you deployed this VM before 2026-09-17, it came from the older image and is not changed by the new publication — redeploy from the current Marketplace version, or apply the one-time repair below:
sudo sed -i 's/^DEFAULT_FORWARD_POLICY=.*/DEFAULT_FORWARD_POLICY="ACCEPT"/' /etc/default/ufw
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow from 10.42.0.0/16 to any
sudo ufw allow from 10.43.0.0/16 to any
sudo ufw --force enableImage change: see the pull request.
Source: the Marketplace live version set for this offer, read from Partner Center on 2026-09-17. New deployments take the newest version by default.
| Application ports | 80 and 443 (the bundled Traefik ingress) are open in the VM's own firewall — open them in the Network Security Group and your Ingress routes are reachable. 6443 (Kubernetes API) is deliberately NOT opened: the kubeconfig is full cluster-admin, so the API stays on the node |
|---|---|
| Service(s) | k3s |
| Configuration | /etc/rancher/k3s/k3s.yaml (kubeconfig, root-only, full cluster-admin) |
| Logs | journalctl -u k3s -f |
| Version | K3s v1.36.5+k3s1 (Kubernetes 1.36; bundled Traefik 3.7.13 ingress, CoreDNS 1.14.7) |
| Platform | Ubuntu 24.04 LTS |
Email support@dcassociatesgroup.com (response within 1 business day) or send a
message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.