Skip to content
This repository has been archived by the owner on Apr 30, 2021. It is now read-only.

Commit

Permalink
Merge pull request #603 from alphagov/magic-security-group-rules
Browse files Browse the repository at this point in the history
Revert "Remove unneeded security group rules"
  • Loading branch information
philandstuff authored Oct 4, 2019
2 parents cdb1f32 + b516b9e commit 108c164
Showing 1 changed file with 22 additions and 0 deletions.
22 changes: 22 additions & 0 deletions modules/k8s-cluster/security.tf
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,28 @@ resource "aws_security_group_rule" "nodes-from-vpc" {
cidr_blocks = ["${data.aws_vpc.private.cidr_block}"]
}

resource "aws_security_group_rule" "nodes-from-controller" {
security_group_id = "${aws_security_group.node.id}"

type = "ingress"
protocol = "tcp"
from_port = 1025
to_port = 65535

source_security_group_id = "${aws_security_group.controller.id}"
}

resource "aws_security_group_rule" "controller-to-nodes" {
security_group_id = "${aws_security_group.controller.id}"

type = "egress"
protocol = "tcp"
from_port = 1025
to_port = 65535

source_security_group_id = "${aws_security_group.node.id}"
}

resource "aws_security_group_rule" "controller-from-nodes" {
security_group_id = "${aws_security_group.controller.id}"

Expand Down

0 comments on commit 108c164

Please sign in to comment.