You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform创建指定二级Pod IP范围的GKE节点池

解决方案

你之前配置不生效的核心原因是参数位置错误、使用了不存在的参数,同时低版本Provider不支持节点池级网络配置功能,正确配置方式如下:

前置要求

  • GKE集群必须为VPC原生(IP别名)模式,路由模式集群不支持节点池自定义Pod范围
  • 使用的HashiCorp Google Provider版本 >= 4.40.0,该版本才正式支持节点池级别的网络配置参数
  • 若使用共享VPC,需确保当前操作账号对共享VPC的辅助IP范围有使用权限

配置示例

场景1:复用提前创建的辅助IP范围

如果你已经提前在共享VPC子网中创建好了名为pods2的[pod2-subnet]/18辅助IP范围,配置如下:

resource "google_container_node_pool" "node_pool_1" {
  name       = var.pool_name_1
  location   = var.cluster_location
  node_locations = [var.pool_zone]
  cluster    = "app-${var.cluster_name}"
  max_pods_per_node = 10

  autoscaling {
    min_node_count = 1
    max_node_count = 300
  }

  # 节点池自定义网络配置,指定独立Pod范围
  network_config {
    # 填写提前创建的辅助IP范围名称
    pod_range = "pods2"
    # 若节点池与集群使用同一子网,无需额外指定subnetwork参数
    # 若需使用与集群不同的子网,可补充以下配置:
    # subnetwork = "projects/shared-project-1/regions/${var.region}/subnetworks/k8s-subnet"
  }

  node_config {
    preemptible = true
    machine_type = var.machine_pv_e1

    metadata = {
      disable-legacy-endpoints = "true"
      owner = "abc"
      project = "app1"
      team = "spirit"
    }

    labels = {
      app = "prod-${var.app1}"
      pool = "n2"
      pool_type = "pv"
      zone = "d"
      env = "prod"
    }
    service_account = "app-sa@project101.iam.gserviceaccount.com"
    oauth_scopes = [
      "https://www.googleapis.com/auth/monitoring",
      "https://www.googleapis.com/auth/devstorage.read_write"
    ]

    tags = [var.node_tag]
  }
}

场景2:自动创建Pod IP范围

无需提前创建辅助IP段,直接指定CIDR让节点池自动创建对应辅助范围,network_config块调整为:

network_config {
  create_pod_range = true
  pod_ipv4_cidr_block = "[pod2-subnet]/18"
  # 可选:自定义自动创建的辅助IP范围名称
  pod_range_name = "pods2-auto"
}

验证方法

节点池创建完成后执行以下命令,确认配置生效:
gcloud container node-pools describe <节点池名称> --cluster <集群名称> --location <集群区域> --format="value(networkConfig.podRange)"
若输出你指定的Pod范围名称或CIDR,说明配置生效。

内容的提问来源于stack exchange,提问作者xyphan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 08:24:04