Sitelet https://github.com/kubernetes/kops/commit/20efe0b164dc056a86297bd39bf6e23c25e3a2c5
Skip to content

Commit 20efe0b

Browse files
Merge pull request #18685 from Jefftree/gce-firewall-etcd-events-metrics
gce: open the etcd events metrics port in the node-to-master firewall
2 parents 1f17295 + eb2907c commit 20efe0b

14 files changed

Lines changed: 49 additions & 0 deletions

File tree

‎docs/contributing/ports.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ See also pkg/wellknownports/wellknownports.go
1313
| 2380 | etcd main peering |
1414
| 2381 | etcd events peering |
1515
| 2382 | etcd cilium peering |
16+
| 2384 | etcd events metrics |
1617
| 3988 | kops controller serving port |
1718
| 3989 | node local dns health check |
1819
| 3990 | Kube API health check |

‎pkg/model/gcemodel/firewall.go‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -143,6 +143,7 @@ func (b *FirewallModelBuilder) Build(c *fi.CloudupModelBuilderContext) error {
143143
fmt.Sprintf("tcp:%d", wellknownports.KubeSchedulerMetricsPort),
144144
fmt.Sprintf("tcp:%d", wellknownports.KubeProxyMetricsPort),
145145
fmt.Sprintf("tcp:%d", wellknownports.EtcdMetricsPort),
146+
fmt.Sprintf("tcp:%d", wellknownports.EtcdEventsMetricsPort),
146147
fmt.Sprintf("tcp:%d", wellknownports.NodeExporterMetricsPort),
147148
},
148149
}

‎pkg/wellknownports/wellknownports.go‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,9 @@ const (
2626
// EtcdMetricsPort is used to serve etcd metrics
2727
EtcdMetricsPort = 2382
2828

29+
// EtcdEventsMetricsPort is used to serve etcd metrics for the events etcd
30+
EtcdEventsMetricsPort = 2384
31+
2932
// KopsChannelsHealthCheck is the loopback port the kops-channels static pod serves /readyz on.
3033
KopsChannelsHealthCheck = 3986
3134

‎tests/integration/update_cluster/ha_gce/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -411,6 +411,10 @@ resource "google_compute_firewall" "node-to-master-ha-gce-example-com" {
411411
ports = ["2382"]
412412
protocol = "tcp"
413413
}
414+
allow {
415+
ports = ["2384"]
416+
protocol = "tcp"
417+
}
414418
allow {
415419
ports = ["9100"]
416420
protocol = "tcp"

‎tests/integration/update_cluster/many-addons-gce/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -331,6 +331,10 @@ resource "google_compute_firewall" "node-to-master-minimal-example-com" {
331331
ports = ["2382"]
332332
protocol = "tcp"
333333
}
334+
allow {
335+
ports = ["2384"]
336+
protocol = "tcp"
337+
}
334338
allow {
335339
ports = ["9100"]
336340
protocol = "tcp"

‎tests/integration/update_cluster/minimal_gce/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -299,6 +299,10 @@ resource "google_compute_firewall" "node-to-master-minimal-gce-example-com" {
299299
ports = ["2382"]
300300
protocol = "tcp"
301301
}
302+
allow {
303+
ports = ["2384"]
304+
protocol = "tcp"
305+
}
302306
allow {
303307
ports = ["9100"]
304308
protocol = "tcp"

‎tests/integration/update_cluster/minimal_gce_dns-none/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -349,6 +349,10 @@ resource "google_compute_firewall" "node-to-master-minimal-gce-example-com" {
349349
ports = ["2382"]
350350
protocol = "tcp"
351351
}
352+
allow {
353+
ports = ["2384"]
354+
protocol = "tcp"
355+
}
352356
allow {
353357
ports = ["9100"]
354358
protocol = "tcp"

‎tests/integration/update_cluster/minimal_gce_ilb/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -325,6 +325,10 @@ resource "google_compute_firewall" "node-to-master-minimal-gce-ilb-example-com"
325325
ports = ["2382"]
326326
protocol = "tcp"
327327
}
328+
allow {
329+
ports = ["2384"]
330+
protocol = "tcp"
331+
}
328332
allow {
329333
ports = ["9100"]
330334
protocol = "tcp"

‎tests/integration/update_cluster/minimal_gce_ilb_cilium_etcd/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -385,6 +385,10 @@ resource "google_compute_firewall" "node-to-master-minimal-gce-ilb-cilium-etcd-e
385385
ports = ["2382"]
386386
protocol = "tcp"
387387
}
388+
allow {
389+
ports = ["2384"]
390+
protocol = "tcp"
391+
}
388392
allow {
389393
ports = ["9100"]
390394
protocol = "tcp"

‎tests/integration/update_cluster/minimal_gce_ilb_longclustername/kubernetes.tf‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -325,6 +325,10 @@ resource "google_compute_firewall" "node-to-master-minimal-gce-with-a-very-very-
325325
ports = ["2382"]
326326
protocol = "tcp"
327327
}
328+
allow {
329+
ports = ["2384"]
330+
protocol = "tcp"
331+
}
328332
allow {
329333
ports = ["9100"]
330334
protocol = "tcp"

0 commit comments

Comments
 (0)