mirror of https://github.com/kubernetes/kops.git
Merge pull request #15331 from justinsb/gce_address_family_ipalias
gce: set ip address family on all FirewallRule tasks
This commit is contained in:
commit
2ef477f190
|
|
@ -107,6 +107,7 @@ func createPublicLB(b *APILoadBalancerBuilder, c *fi.CloudupModelBuilderContext)
|
|||
Name: s(b.NameForFirewallRule("pod-cidrs-to-https-api")),
|
||||
Lifecycle: b.Lifecycle,
|
||||
Network: network,
|
||||
Family: gcetasks.AddressFamilyIPv4, // ip alias is always ipv4
|
||||
SourceRanges: []string{b.Cluster.Spec.Networking.PodCIDR},
|
||||
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleControlPlane)},
|
||||
Allowed: []string{"tcp:" + strconv.Itoa(wellknownports.KubeAPIServer)},
|
||||
|
|
|
|||
|
|
@ -121,6 +121,7 @@ func (b *ExternalAccessModelBuilder) Build(c *fi.CloudupModelBuilderContext) err
|
|||
Name: s(b.NameForFirewallRule("pod-cidrs-to-https-api")),
|
||||
Lifecycle: b.Lifecycle,
|
||||
Network: network,
|
||||
Family: gcetasks.AddressFamilyIPv4, // ip alias is always ipv4
|
||||
SourceRanges: []string{b.Cluster.Spec.Networking.PodCIDR},
|
||||
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleControlPlane)},
|
||||
Allowed: []string{"tcp:" + strconv.Itoa(wellknownports.KubeAPIServer)},
|
||||
|
|
|
|||
Loading…
Reference in New Issue