Remove GCP firewall rule allowing Nginx Ingress health

* Nginx Ingress addon no longer uses hostNework so Prometheus may
scrape port 10254 via the CNI network, rather than via the host
address
This commit is contained in:
Dalton Hubble
2018-08-21 21:06:03 -07:00
parent bceec9fdf5
commit da5d2c5321
3 changed files with 5 additions and 28 deletions

View File

@ -124,20 +124,6 @@ resource "google_compute_firewall" "internal-kubelet" {
target_tags = ["${var.cluster_name}-controller", "${var.cluster_name}-worker"]
}
# Allow Prometheus to scrape ingress-controller
resource "google_compute_firewall" "ingress-health" {
name = "${var.cluster_name}-ingress-health"
network = "${google_compute_network.network.name}"
allow {
protocol = "tcp"
ports = [10254]
}
source_tags = ["${var.cluster_name}-worker"]
target_tags = ["${var.cluster_name}-worker"]
}
# Allow heapster / metrics-server to scrape kubelet read-only
resource "google_compute_firewall" "internal-kubelet-readonly" {
name = "${var.cluster_name}-internal-kubelet-readonly"