gce: Rename firewall SSH rules for bastion

This commit is contained in:
Ciprian Hacman 2023-07-10 07:06:07 +03:00
parent 95340a97f8
commit 53e45886f3
1 changed files with 2 additions and 2 deletions

View File

@ -62,14 +62,14 @@ func (b *ExternalAccessModelBuilder) Build(c *fi.CloudupModelBuilderContext) err
SourceRanges: b.Cluster.Spec.SSHAccess,
Network: network,
})
b.AddFirewallRulesTasks(c, "bastion-to-master", &gcetasks.FirewallRule{
b.AddFirewallRulesTasks(c, "bastion-to-master-ssh", &gcetasks.FirewallRule{
Lifecycle: b.Lifecycle,
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleControlPlane), b.GCETagForRole("Master")},
Allowed: []string{"tcp:22"},
SourceTags: []string{b.GCETagForRole(kops.InstanceGroupRoleBastion)},
Network: network,
})
b.AddFirewallRulesTasks(c, "bastion-to-node", &gcetasks.FirewallRule{
b.AddFirewallRulesTasks(c, "bastion-to-node-ssh", &gcetasks.FirewallRule{
Lifecycle: b.Lifecycle,
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleNode)},
Allowed: []string{"tcp:22"},