You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中为GKE节点创建网络标签并关联自定义防火墙规则

Got it, let's walk through how to set up custom network tags for your GKE nodes and use them in your firewall rule—so you don't have to rely on GCP's auto-generated tags that might change format down the line. Here's the step-by-step solution:

Step 1: Add Custom Network Tags to Your GKE Node Pools

First, you'll need to enable and configure the node_pools_tags block in your GKE module. This lets you assign static, predictable tags to all your GKE nodes (or specific node pools if you want granular control).

Update your GKE module configuration like this:

module "gke" {
  source = "terraform-google-modules/kubernetes-engine/google//modules/beta-private-cluster"
  project_id = var.project_id
  name = "${var.project_name}-gke-${var.env_name}-cluster"
  regional = true
  region = var.region
  zones = ["${var.region}-a", "${var.region}-b", "${var.region}-c"]
  network = module.vpc.network_name
  subnetwork = module.vpc.subnets_names[0]
  ip_range_pods = "${var.project_name}-gke-pod-ip-range"
  ip_range_services = "${var.project_name}-gke-service-ip-range"
  http_load_balancing = false
  network_policy = false
  horizontal_pod_autoscaling = true
  filestore_csi_driver = false
  enable_private_endpoint = false
  enable_private_nodes = true
  master_ipv4_cidr_block = "${var.control_plane_cidr}"
  istio = false
  cloudrun = false
  dns_cache = false
  node_pools = [
    {
      name = "${var.project_name}-gke-node-pool"
      machine_type = "${var.machine_type}"
      node_locations = "${var.region}-a,${var.region}-b,${var.region}-c"
      min_count = "${var.node_pools_min_count}"
      max_count = "${var.node_pools_max_count}"
      disk_size_gb = "${var.node_pools_disk_size_gb}"
      auto_repair = true
      auto_upgrade = true
      preemptible = false
    }
  ]
  # Enable and configure custom node tags here
  node_pools_tags = {
    # Apply this tag to ALL node pools in the cluster
    all = ["gke-${var.project_name}-${var.env_name}-node"]
    # Alternatively, target only your specific node pool if needed:
    # "${var.project_name}-gke-node-pool" = ["gke-${var.project_name}-${var.env_name}-node"]
  }
}

I used a tag like gke-${var.project_name}-${var.env_name}-node to make it unique across projects and environments—adjust the format to fit your naming conventions, just make sure it's something static you control.

Step 2: Update Your Firewall Rule to Target the Custom Tag

Next, modify your firewall module to use this custom tag as the target_tags value. This ensures the rule only applies to your GKE nodes, no matter what auto-generated tags GCP assigns.

Update your firewall module configuration:

module "firewall_rules" {
  source = "terraform-google-modules/network/google//modules/firewall-rules"
  project_id = var.project_id
  network_name = module.vpc.network_name
  rules = [{
    name = "allow-istio-ingress"
    description = "Allow Istio ingress traffic to GKE nodes from control plane CIDR"
    direction = "INGRESS"
    priority = null
    ranges = ["${var.control_plane_cidr}"]
    source_tags = null
    source_service_accounts = null
    target_tags = ["gke-${var.project_name}-${var.env_name}-node"] # Match the custom tag from GKE
    target_service_accounts = null
    allow = [{
      protocol = "tcp"
      ports = ["15017"]
    }]
    deny = []
    log_config = {
      metadata = "INCLUDE_ALL_METADATA"
    }
  }]
  depends_on = [module.gke]
}

Make sure the target_tags array here uses the exact same tag string as you defined in the GKE module—consistency is key here.

Why This Works

By using your own custom network tags, you avoid any dependency on GCP's auto-generated tag formats (which include dynamic hashes that can change when you update or re-create your GKE cluster). This makes your Terraform configuration more robust and future-proof.

After applying these changes, you can verify in the GCP Console:

  • Check your GKE node instances to confirm they have the custom tag attached
  • Verify the firewall rule's target tags match your custom tag

内容的提问来源于stack exchange,提问作者Nitin G

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 23:42:41