mirror of https://github.com/kubernetes/kops.git
gce: Rename firewall SSH rules for bastion
This commit is contained in:
parent
95340a97f8
commit
53e45886f3
|
|
@ -62,14 +62,14 @@ func (b *ExternalAccessModelBuilder) Build(c *fi.CloudupModelBuilderContext) err
|
||||||
SourceRanges: b.Cluster.Spec.SSHAccess,
|
SourceRanges: b.Cluster.Spec.SSHAccess,
|
||||||
Network: network,
|
Network: network,
|
||||||
})
|
})
|
||||||
b.AddFirewallRulesTasks(c, "bastion-to-master", &gcetasks.FirewallRule{
|
b.AddFirewallRulesTasks(c, "bastion-to-master-ssh", &gcetasks.FirewallRule{
|
||||||
Lifecycle: b.Lifecycle,
|
Lifecycle: b.Lifecycle,
|
||||||
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleControlPlane), b.GCETagForRole("Master")},
|
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleControlPlane), b.GCETagForRole("Master")},
|
||||||
Allowed: []string{"tcp:22"},
|
Allowed: []string{"tcp:22"},
|
||||||
SourceTags: []string{b.GCETagForRole(kops.InstanceGroupRoleBastion)},
|
SourceTags: []string{b.GCETagForRole(kops.InstanceGroupRoleBastion)},
|
||||||
Network: network,
|
Network: network,
|
||||||
})
|
})
|
||||||
b.AddFirewallRulesTasks(c, "bastion-to-node", &gcetasks.FirewallRule{
|
b.AddFirewallRulesTasks(c, "bastion-to-node-ssh", &gcetasks.FirewallRule{
|
||||||
Lifecycle: b.Lifecycle,
|
Lifecycle: b.Lifecycle,
|
||||||
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleNode)},
|
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleNode)},
|
||||||
Allowed: []string{"tcp:22"},
|
Allowed: []string{"tcp:22"},
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue