You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform在VPC Kubernetes集群中添加自定义安全组?

在IBM VPC Kubernetes Terraform模块中添加自定义安全组

你尝试的security_group_id并非该模块的有效参数,要给Kubernetes集群的worker节点绑定自定义安全组,需使用模块提供的worker_pool_security_groups参数,具体操作如下:

1. (可选)创建自定义安全组

若还没有现成的自定义安全组,可通过ibm_is_security_group资源创建:

resource "ibm_is_security_group" "worker_custom_sg" {
  name               = "worker-custom-sg"
  resource_group_id  = data.ibm_resource_group.rg.id
  vpc_id             = var.vpc_id

  # 按需添加安全组规则,示例包含SSH访问和集群内部通信规则
  rule {
    direction = "inbound"
    protocol  = "tcp"
    port_min  = 22
    port_max  = 22
    remote    = "0.0.0.0/0" # 根据实际场景调整源地址范围
  }

  rule {
    direction = "inbound"
    protocol  = "tcp"
    port_min  = 6443
    port_max  = 6443
    remote    = var.service_subnet # 允许集群服务子网访问API端口
  }
}

2. 在模块调用中绑定自定义安全组

修改你的vpc_kubernetes_cluster模块配置,添加worker_pool_security_groups参数,传入自定义安全组的ID列表:

data "ibm_resource_group" "rg" {
  name = var.resource_group
}

# (若已创建自定义安全组,保留此处资源代码)
# resource "ibm_is_security_group" "worker_custom_sg" { ... }

module "vpc_kubernetes_cluster" {
  source = "../../modules/vpc-kubernetes"
  cluster_name                    = var.cluster_name
  vpc_id                          = var.vpc_id
  worker_pool_flavor              = var.worker_pool_flavor
  worker_zones                    = var.worker_zones
  worker_nodes_per_zone           = var.worker_nodes_per_zone
  resource_group_id               = data.ibm_resource_group.rg.id
  kube_version                    = var.kube_version
  update_all_workers              = var.update_all_workers
  service_subnet                  = var.service_subnet
  pod_subnet                      = var.pod_subnet
  worker_labels                   = var.worker_labels
  wait_till                       = var.wait_till
  disable_public_service_endpoint = var.disable_public_service_endpoint
  tags                            = var.tags
  cos_instance_crn                = var.cos_instance_crn
  force_delete_storage            = var.force_delete_storage
  kms_config                      = var.kms_config
  taints                          = var.taints
  create_timeout                  = var.create_timeout
  update_timeout                  = var.update_timeout
  delete_timeout                  = var.delete_timeout

  # 绑定自定义安全组
  worker_pool_security_groups = [ibm_is_security_group.worker_custom_sg.id]
}

注意事项

  • 若不指定worker_pool_security_groups,模块会自动生成包含集群运行基础规则的默认安全组;
  • 自定义安全组需包含worker节点正常运行所需的全部规则(如节点间通信、Pod网络互通、API服务器访问等),否则集群可能无法正常工作;
  • 支持传入多个安全组ID,格式为[sg-id-1, sg-id-2]。

内容的提问来源于stack exchange,提问作者SemirAdam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 02:10:16