Skip to content

Commit 1d866fe

Browse files
committed
aws: Open controller-manager and scheduler ports for metrics
1 parent cad1f25 commit 1d866fe

File tree

1 file changed

+40
-0
lines changed

1 file changed

+40
-0
lines changed

data/data/aws/vpc/sg-master.tf

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -138,6 +138,46 @@ resource "aws_security_group_rule" "master_ingress_internal_from_worker" {
138138
to_port = 9990
139139
}
140140

141+
resource "aws_security_group_rule" "master_ingress_kube_scheduler" {
142+
type = "ingress"
143+
security_group_id = "${aws_security_group.master.id}"
144+
145+
protocol = "tcp"
146+
from_port = 10251
147+
to_port = 10251
148+
self = true
149+
}
150+
151+
resource "aws_security_group_rule" "master_ingress_kube_scheduler_from_worker" {
152+
type = "ingress"
153+
security_group_id = "${aws_security_group.master.id}"
154+
source_security_group_id = "${aws_security_group.worker.id}"
155+
156+
protocol = "tcp"
157+
from_port = 10251
158+
to_port = 10251
159+
}
160+
161+
resource "aws_security_group_rule" "master_ingress_kube_controller_manager" {
162+
type = "ingress"
163+
security_group_id = "${aws_security_group.master.id}"
164+
165+
protocol = "tcp"
166+
from_port = 10252
167+
to_port = 10252
168+
self = true
169+
}
170+
171+
resource "aws_security_group_rule" "master_ingress_kube_controller_manager_from_worker" {
172+
type = "ingress"
173+
security_group_id = "${aws_security_group.master.id}"
174+
source_security_group_id = "${aws_security_group.worker.id}"
175+
176+
protocol = "tcp"
177+
from_port = 10252
178+
to_port = 10252
179+
}
180+
141181
resource "aws_security_group_rule" "master_ingress_kubelet_insecure" {
142182
type = "ingress"
143183
security_group_id = "${aws_security_group.master.id}"

0 commit comments

Comments
 (0)