The solution was writing to /etc/rancher/k3s/config.yaml:
kubelet-arg: - allowed-unsafe-sysctls=net.ipv4.ip_forward - allowed-unsafe-sysctls=net.ipv4.conf.all.src_valid_mark - allowed-unsafe-sysctls=net.ipv6.conf.all.disable_ipv6