如何在Terraform中为GKE节点创建网络标签并关联自定义防火墙规则
Got it, let's walk through how to set up custom network tags for your GKE nodes and use them in your firewall rule—so you don't have to rely on GCP's auto-generated tags that might change format down the line. Here's the step-by-step solution:
Step 1: Add Custom Network Tags to Your GKE Node Pools
First, you'll need to enable and configure the node_pools_tags block in your GKE module. This lets you assign static, predictable tags to all your GKE nodes (or specific node pools if you want granular control).
Update your GKE module configuration like this:
module "gke" { source = "terraform-google-modules/kubernetes-engine/google//modules/beta-private-cluster" project_id = var.project_id name = "${var.project_name}-gke-${var.env_name}-cluster" regional = true region = var.region zones = ["${var.region}-a", "${var.region}-b", "${var.region}-c"] network = module.vpc.network_name subnetwork = module.vpc.subnets_names[0] ip_range_pods = "${var.project_name}-gke-pod-ip-range" ip_range_services = "${var.project_name}-gke-service-ip-range" http_load_balancing = false network_policy = false horizontal_pod_autoscaling = true filestore_csi_driver = false enable_private_endpoint = false enable_private_nodes = true master_ipv4_cidr_block = "${var.control_plane_cidr}" istio = false cloudrun = false dns_cache = false node_pools = [ { name = "${var.project_name}-gke-node-pool" machine_type = "${var.machine_type}" node_locations = "${var.region}-a,${var.region}-b,${var.region}-c" min_count = "${var.node_pools_min_count}" max_count = "${var.node_pools_max_count}" disk_size_gb = "${var.node_pools_disk_size_gb}" auto_repair = true auto_upgrade = true preemptible = false } ] # Enable and configure custom node tags here node_pools_tags = { # Apply this tag to ALL node pools in the cluster all = ["gke-${var.project_name}-${var.env_name}-node"] # Alternatively, target only your specific node pool if needed: # "${var.project_name}-gke-node-pool" = ["gke-${var.project_name}-${var.env_name}-node"] } }
I used a tag like gke-${var.project_name}-${var.env_name}-node to make it unique across projects and environments—adjust the format to fit your naming conventions, just make sure it's something static you control.
Step 2: Update Your Firewall Rule to Target the Custom Tag
Next, modify your firewall module to use this custom tag as the target_tags value. This ensures the rule only applies to your GKE nodes, no matter what auto-generated tags GCP assigns.
Update your firewall module configuration:
module "firewall_rules" { source = "terraform-google-modules/network/google//modules/firewall-rules" project_id = var.project_id network_name = module.vpc.network_name rules = [{ name = "allow-istio-ingress" description = "Allow Istio ingress traffic to GKE nodes from control plane CIDR" direction = "INGRESS" priority = null ranges = ["${var.control_plane_cidr}"] source_tags = null source_service_accounts = null target_tags = ["gke-${var.project_name}-${var.env_name}-node"] # Match the custom tag from GKE target_service_accounts = null allow = [{ protocol = "tcp" ports = ["15017"] }] deny = [] log_config = { metadata = "INCLUDE_ALL_METADATA" } }] depends_on = [module.gke] }
Make sure the target_tags array here uses the exact same tag string as you defined in the GKE module—consistency is key here.
Why This Works
By using your own custom network tags, you avoid any dependency on GCP's auto-generated tag formats (which include dynamic hashes that can change when you update or re-create your GKE cluster). This makes your Terraform configuration more robust and future-proof.
After applying these changes, you can verify in the GCP Console:
- Check your GKE node instances to confirm they have the custom tag attached
- Verify the firewall rule's target tags match your custom tag
内容的提问来源于stack exchange,提问作者Nitin G

