Comments (6)
If the .ssh/config file could be created yo jump through the NT server it would be awesome, that will simplify as yuo don't have to go to the NAT(Bastion) first and then connect to the server on the private NW.
from terraform-kubernetes-installer.
ISV reported this as a critical need, so would be good to support this scenario.
from terraform-kubernetes-installer.
Is there any ETA for this issue being resolved in near future?
Private instances/subnets/lbr are must-have according to our Threat-Model.
from terraform-kubernetes-installer.
I'm working on this now and hope to have something soon.
The change was a bit involved than just prohibiting public IPs on the instances and load-balancers since instances need access to the internet during the bootstrap phase. But here is our approach:
If the tbd_cluster_visibility
input variable is set toprivate
(vs. public):
- The etcd, master, and worker subnets, instances, and load-balancers, will be private - meaning they will not have public IP addresses.
- We'll provision a NAT instance in the VCN that is on a public subnet and connected to the Internet.
- While the etcd, master, and worker instances instances are initializing they will access the internet to download software through the NAT instance.
from terraform-kubernetes-installer.
Thanks for the update! I'm glad to try it out once the NAT instance is implemented.
from terraform-kubernetes-installer.
If the .ssh/config file could be created yo jump through the NT server it would be awesome, that will simplify as yuo don't have to go to the NAT(Bastion) first and then connect to the server on the private NW.
Yeah, that was what we were thinking.
from terraform-kubernetes-installer.
Related Issues (20)
- Allow creation of clusters with existing subnets, routes and security lists. HOT 1
- Enable (and configure) advanced auditing by default
- Question about updating existing cluster vs creating new one in new vcn HOT 8
- CI tests are failing with index out of range error when tests set master_oci_lb_enabled=false
- load balancers go into critical state when the instances are rebooted
- oci_core_images OCID lookup failing HOT 4
- Metadata size limit of 32000 bytes being hit. HOT 5
- Update the CCM version to latest
- pod cluster network does not work when number of worker nodes > 1
- Naming consistency. Map references to BMCS to OCI
- Document current limitations of the OCI Terraform installer
- module.instances-etcd-ad2.data.template_file.etcd-bootstrap: 1 error
- Kubernetes nodes(master and worker) NotReady HOT 2
- k8s worker freeze when launching several pods
- oci_load_balancer_listener reports invalid parameter HOT 3
- Error using master branch and oci provider 3.5 HOT 2
- Cluster does not provision successfully on Oracle-Linux-7.5-2018.10.16-0 HOT 5
- Error in creating vm
- centos HOT 1
- Deprecation warnings and fixes
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from terraform-kubernetes-installer.