Reorder special rule first, copy/paste error, should be tcp, not udp.
This commit is contained in:
parent
c2a1392041
commit
c986e4b37d
17
main.tf
17
main.tf
|
@ -29,21 +29,23 @@ resource "openstack_networking_secgroup_v2" "microk8s" {
|
||||||
}
|
}
|
||||||
|
|
||||||
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule1" {
|
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule1" {
|
||||||
|
#We never know where Richard is, so allow from all of the known internet
|
||||||
direction = "ingress"
|
direction = "ingress"
|
||||||
ethertype = "IPv4"
|
ethertype = "IPv4"
|
||||||
protocol = "tcp"
|
protocol = "tcp"
|
||||||
port_range_min = 16443
|
port_range_min = 16443
|
||||||
port_range_max = 16443
|
port_range_max = 16443
|
||||||
remote_group_id = openstack_networking_secgroup_v2.microk8s.id
|
remote_ip_prefix = "0.0.0.0/0"
|
||||||
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
}
|
}
|
||||||
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule2" {
|
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule2" {
|
||||||
|
#We never know where Richard is, so allow from all of the known internet
|
||||||
direction = "ingress"
|
direction = "ingress"
|
||||||
ethertype = "IPv6"
|
ethertype = "IPv6"
|
||||||
protocol = "tcp"
|
protocol = "tcp"
|
||||||
port_range_min = 16443
|
port_range_min = 16443
|
||||||
port_range_max = 16443
|
port_range_max = 16443
|
||||||
remote_group_id = openstack_networking_secgroup_v2.microk8s.id
|
remote_ip_prefix = "::/0"
|
||||||
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
}
|
}
|
||||||
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule3" {
|
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule3" {
|
||||||
|
@ -192,27 +194,24 @@ resource "openstack_networking_secgroup_rule_v2" "microk8s_rule18" {
|
||||||
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
}
|
}
|
||||||
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule19" {
|
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule19" {
|
||||||
#We never know where Richard is, so allow from all of the known internet
|
|
||||||
direction = "ingress"
|
direction = "ingress"
|
||||||
ethertype = "IPv4"
|
ethertype = "IPv4"
|
||||||
protocol = "udp"
|
protocol = "tcp"
|
||||||
port_range_min = 16443
|
port_range_min = 16443
|
||||||
port_range_max = 16443
|
port_range_max = 16443
|
||||||
remote_ip_prefix = "0.0.0.0/0"
|
remote_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
}
|
}
|
||||||
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule20" {
|
resource "openstack_networking_secgroup_rule_v2" "microk8s_rule20" {
|
||||||
#We never know where Richard is, so allow from all of the known internet
|
|
||||||
direction = "ingress"
|
direction = "ingress"
|
||||||
ethertype = "IPv6"
|
ethertype = "IPv6"
|
||||||
protocol = "udp"
|
protocol = "tcp"
|
||||||
port_range_min = 16443
|
port_range_min = 16443
|
||||||
port_range_max = 16443
|
port_range_max = 16443
|
||||||
remote_ip_prefix = "::/0"
|
remote_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
security_group_id = openstack_networking_secgroup_v2.microk8s.id
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
resource "openstack_compute_instance_v2" "controller-nodes" {
|
resource "openstack_compute_instance_v2" "controller-nodes" {
|
||||||
count = var.controller_instance_count
|
count = var.controller_instance_count
|
||||||
name = "${var.controller_name}-${count.index}.${var.dns_suffix}"
|
name = "${var.controller_name}-${count.index}.${var.dns_suffix}"
|
||||||
|
|
Loading…
Reference in a new issue