Skip to content

Commit c99bd40

Browse files
committed
kube
1 parent d096ad9 commit c99bd40

File tree

3 files changed

+8
-20
lines changed

3 files changed

+8
-20
lines changed

tests/tofu/config.tf

+2-2
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ locals {
1111
name = google_container_cluster.primary.name
1212
context = {
1313
cluster = google_container_cluster.primary.name
14-
user = var.gke_nodes_service_account
14+
user = google_container_cluster.primary.name
1515
}
1616
}
1717
]
@@ -26,7 +26,7 @@ locals {
2626
]
2727
users = [
2828
{
29-
name = var.gke_nodes_service_account
29+
name = google_container_cluster.primary.name
3030
user = {
3131
exec = {
3232
apiVersion = "client.authentication.k8s.io/v1beta1"

tests/tofu/main.tf

+4-4
Original file line numberDiff line numberDiff line change
@@ -48,10 +48,10 @@ resource "google_container_cluster" "primary" {
4848
display_name = "local-ip"
4949
}
5050

51-
cidr_blocks {
52-
cidr_block = google_compute_subnetwork.subnet.ip_cidr_range
53-
display_name = "vpc"
54-
}
51+
# cidr_blocks {
52+
# cidr_block = google_compute_subnetwork.subnet.ip_cidr_range
53+
# display_name = "vpc"
54+
# }
5555
}
5656

5757
private_cluster_config {

tests/tofu/network.tf

+2-14
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ resource "google_compute_router_nat" "nat" {
2727
}
2828
}
2929

30-
resource "google_compute_firewall" "firewall" {
31-
name = "${var.gke_cluster_name}-firewall"
30+
resource "google_compute_firewall" "ssh" {
31+
name = "${var.gke_cluster_name}-ssh"
3232
network = google_compute_network.vpc.self_link
3333
allow {
3434
protocol = "tcp"
@@ -37,18 +37,6 @@ resource "google_compute_firewall" "firewall" {
3737
source_ranges = ["${chomp(data.http.myip.response_body)}/32"]
3838
}
3939

40-
resource "google_compute_firewall" "deny_exkubelet" {
41-
name = "${var.gke_cluster_name}-deny-exkubelet"
42-
network = google_compute_network.vpc.self_link
43-
direction = "INGRESS"
44-
deny {
45-
protocol = "tcp"
46-
ports = ["10255"]
47-
}
48-
source_ranges = ["0.0.0.0/0"]
49-
50-
}
51-
5240
resource "google_compute_address" "vpc-ip" {
5341
name = "${var.gke_cluster_name}-vpc-ip"
5442
address_type = "EXTERNAL"

0 commit comments

Comments
 (0)