Comments (4)
This feature would be helpful for enterprise adoption
from pulumi-eks.
Something to consider when implementing this: it would be great if the library accounted for ensuring that the machine that itβs running on has access to the cluster API, probably via an additional extra security group rule or assertion. (See https://docs.aws.amazon.com/eks/latest/userguide/sec-group-reqs.html)
from pulumi-eks.
Something to consider when implementing this: it would be great if the library accounted for ensuring that the machine that itβs running on has access to the cluster API, probably via an additional extra security group rule or assertion. (See https://docs.aws.amazon.com/eks/latest/userguide/sec-group-reqs.html)
This is a great point. If public=false,private=true then the @pulumi/kuberentes
API calls we make will not succeed by default. The two options I can think of are:
- Automatically add a SG ingress rule targetting the IP of the current machine (potentially NATed?)
- Ensure that users can provide a custom Cluster security group so that they can configure ingress with the CIDR blocks, IPs or other SGs they want to have access (and document that deployments will only be possible if done from an IP within one of these).
(2) would require some slightly non-trivial manual configuration - but should otherwise be reliable.
(1) is "automatic" but doesn't feel reliable - for one its subtly defeating security best-practices by default. But then also if deployments happen from different IPs (even different IPs within a single CI system), there will be unexpected churn in the deployment.
I think I'll solve for (2) for now, and we could explore (1) or some variant of it as an ease-of-use addon in the future if really needed (though I suspect that ease-of-use will not be aligned with private-only endpoint access :-)).
Thoughts?
from pulumi-eks.
I agree that option 2 is the best path forward.
I've added some comments in #154 (comment).
from pulumi-eks.
Related Issues (20)
- ManagedNodeGroup should be able to specify an AMI ID override
- Workflow failure: cron HOT 1
- Workflow failure: master HOT 1
- Unable to specify `nodeRootVolumeIops` and `nodeRootVolumeThroughput` in node group resources
- Upgrade tests are broken after release v2.5.0
- Keep pulumi-aws reference up-to-date with automation
- `instanceRole` still created when `skipDefaultNodeGroup` is enabled. HOT 1
- eks.ManagedNodeGroup with amiType: 'AL2023_ARM_64_STANDARD' breaks when kubeletExtraArgs specified HOT 5
- Upgrade tests fails whenever there is a new recommended AMI ID
- Generate Node SDK using the standard codegen tooling HOT 3
- Enforce linting rules in CI
- Workflow failure: master
- Workflow failure: master
- VPC CNI creation does not respect the `proxy` config or `HTTP_PROXY` environment variable HOT 1
- eks.ManagedNodeGroup: launchTemplate is ignored HOT 2
- clusterSecurityGroupTags applied to Additional security group. Must assign to Acutal cluster security group. HOT 3
- Support AL2023 & Bottlerocket for managed node groups
- Cannot create `ManagedNodeGroup` for cluster with `API` authentication mode
- Allow users to set KMS key when encrypting node block devices HOT 2
- Workflow failure: cron HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
π Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. πππ
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google β€οΈ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from pulumi-eks.