mirror of
https://github.com/puppetmaster/typhoon.git
synced 2024-12-25 17:39:33 +01:00
af5c413abf
* ELB distributing load across controllers is no longer the mechanism used to SSH to instances to distribute secrets * Focus the ELB on load balancing across apiserver and edit the HTTP health check to an SSL:443 check
44 lines
1.1 KiB
HCL
44 lines
1.1 KiB
HCL
# kube-apiserver Network Load Balancer DNS Record
|
|
resource "aws_route53_record" "apiserver" {
|
|
zone_id = "${var.dns_zone_id}"
|
|
|
|
name = "${format("%s.%s.", var.cluster_name, var.dns_zone)}"
|
|
type = "A"
|
|
|
|
# AWS recommends their special "alias" records for ELBs
|
|
alias {
|
|
name = "${aws_elb.apiserver.dns_name}"
|
|
zone_id = "${aws_elb.apiserver.zone_id}"
|
|
evaluate_target_health = true
|
|
}
|
|
}
|
|
|
|
# Controller Network Load Balancer
|
|
resource "aws_elb" "apiserver" {
|
|
name = "${var.cluster_name}-apiserver"
|
|
subnets = ["${aws_subnet.public.*.id}"]
|
|
security_groups = ["${aws_security_group.controller.id}"]
|
|
|
|
listener {
|
|
lb_port = 443
|
|
lb_protocol = "tcp"
|
|
instance_port = 443
|
|
instance_protocol = "tcp"
|
|
}
|
|
|
|
instances = ["${aws_instance.controllers.*.id}"]
|
|
|
|
# Kubelet HTTP health check
|
|
health_check {
|
|
target = "SSL:443"
|
|
healthy_threshold = 2
|
|
unhealthy_threshold = 4
|
|
timeout = 5
|
|
interval = 6
|
|
}
|
|
|
|
idle_timeout = 3600
|
|
connection_draining = true
|
|
connection_draining_timeout = 300
|
|
}
|