Skip to content

Commit 11f922b

Browse files
committed
temporary ssh patch
1 parent 4add0d9 commit 11f922b

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

pkg/model/gcemodel/external_access.go

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,14 @@ func (b *ExternalAccessModelBuilder) Build(c *fi.CloudupModelBuilderContext) err
5555
if err != nil {
5656
return err
5757
}
58+
b.AddFirewallRulesTasks(c, "ssh-external-to-master", &gcetasks.FirewallRule{
59+
Lifecycle: b.Lifecycle,
60+
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleControlPlane), b.GCETagForRole("Master")},
61+
Allowed: []string{"tcp:22"},
62+
SourceRanges: b.Cluster.Spec.SSHAccess,
63+
Network: network,
64+
})
65+
5866
b.AddFirewallRulesTasks(c, "ssh-external-to-bastion", &gcetasks.FirewallRule{
5967
Lifecycle: b.Lifecycle,
6068
TargetTags: []string{b.GCETagForRole(kops.InstanceGroupRoleBastion)},

0 commit comments

Comments
 (0)