Skip to content

Commit

Permalink
Merge pull request #1238 from danwinship/security-groups
Browse files Browse the repository at this point in the history
drop unused security group, fix naming of VXLAN rules
  • Loading branch information
openshift-merge-robot authored Feb 13, 2019
2 parents d99dea5 + aa5a529 commit 17c0fa8
Show file tree
Hide file tree
Showing 4 changed files with 4 additions and 155 deletions.
4 changes: 0 additions & 4 deletions data/data/aws/vpc/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ output "master_subnet_ids" {
value = "${local.master_subnet_ids}"
}

output "etcd_sg_id" {
value = "${aws_security_group.etcd.id}"
}

output "master_sg_id" {
value = "${aws_security_group.master.id}"
}
Expand Down
107 changes: 0 additions & 107 deletions data/data/aws/vpc/sg-etcd.tf

This file was deleted.

24 changes: 2 additions & 22 deletions data/data/aws/vpc/sg-master.tf
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ resource "aws_security_group_rule" "master_ingress_heapster_from_worker" {
to_port = 4194
}

resource "aws_security_group_rule" "master_ingress_flannel" {
resource "aws_security_group_rule" "master_ingress_vxlan" {
type = "ingress"
security_group_id = "${aws_security_group.master.id}"

Expand All @@ -96,17 +96,7 @@ resource "aws_security_group_rule" "master_ingress_flannel" {
self = true
}

resource "aws_security_group_rule" "master_ingress_flannel_from_etcd" {
type = "ingress"
security_group_id = "${aws_security_group.master.id}"
source_security_group_id = "${aws_security_group.etcd.id}"

protocol = "udp"
from_port = 4789
to_port = 4789
}

resource "aws_security_group_rule" "master_ingress_flannel_from_worker" {
resource "aws_security_group_rule" "master_ingress_vxlan_from_worker" {
type = "ingress"
security_group_id = "${aws_security_group.master.id}"
source_security_group_id = "${aws_security_group.worker.id}"
Expand Down Expand Up @@ -255,13 +245,3 @@ resource "aws_security_group_rule" "master_ingress_services_from_console" {
from_port = 30000
to_port = 32767
}

resource "aws_security_group_rule" "master_ingress_from_etcd" {
type = "ingress"
security_group_id = "${aws_security_group.master.id}"
source_security_group_id = "${aws_security_group.etcd.id}"

protocol = "tcp"
from_port = 0
to_port = 65535
}
24 changes: 2 additions & 22 deletions data/data/aws/vpc/sg-worker.tf
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ resource "aws_security_group_rule" "worker_ingress_heapster_from_master" {
to_port = 4194
}

resource "aws_security_group_rule" "worker_ingress_flannel" {
resource "aws_security_group_rule" "worker_ingress_vxlan" {
type = "ingress"
security_group_id = "${aws_security_group.worker.id}"

Expand All @@ -86,17 +86,7 @@ resource "aws_security_group_rule" "worker_ingress_flannel" {
self = true
}

resource "aws_security_group_rule" "worker_ingress_flannel_from_etcd" {
type = "ingress"
security_group_id = "${aws_security_group.worker.id}"
source_security_group_id = "${aws_security_group.etcd.id}"

protocol = "udp"
from_port = 4789
to_port = 4789
}

resource "aws_security_group_rule" "worker_ingress_flannel_from_master" {
resource "aws_security_group_rule" "worker_ingress_vxlan_from_master" {
type = "ingress"
security_group_id = "${aws_security_group.worker.id}"
source_security_group_id = "${aws_security_group.master.id}"
Expand Down Expand Up @@ -185,13 +175,3 @@ resource "aws_security_group_rule" "worker_ingress_services_from_console" {
from_port = 30000
to_port = 32767
}

resource "aws_security_group_rule" "etcd_ingress_from_etcd" {
type = "ingress"
security_group_id = "${aws_security_group.etcd.id}"
source_security_group_id = "${aws_security_group.etcd.id}"

protocol = "tcp"
from_port = 0
to_port = 65535
}

0 comments on commit 17c0fa8

Please sign in to comment.