Sitelet https://github.com/kubernetes/kops/commit/d03a6c00c40b6b0cda516ff4f0357772c49d1689
Skip to content

Commit d03a6c0

Browse files
committed
gce: allow Calico VXLAN UDP port and TCP metrics ports in GCE firewall
1 parent 3d2208a commit d03a6c0

2 files changed

Lines changed: 8 additions & 0 deletions

File tree

‎pkg/model/gcemodel/firewall.go‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -149,6 +149,11 @@ func (b *FirewallModelBuilder) Build(c *fi.CloudupModelBuilderContext) error {
149149
if b.NetworkingIsCalico() {
150150
t.Allowed = append(t.Allowed, "ipip")
151151
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.BGP))
152+
t.Allowed = append(t.Allowed, fmt.Sprintf("udp:%d", wellknownports.CalicoVxlanUDP))
153+
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeControllerManagerMetricsPort))
154+
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeSchedulerMetricsPort))
155+
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeProxyMetricsPort))
156+
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.EtcdMetricsPort))
152157
}
153158
if b.NetworkingIsCilium() {
154159
t.Allowed = append(t.Allowed, fmt.Sprintf("udp:%d", wellknownports.VxlanUDP))

‎pkg/wellknownports/wellknownports.go‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,9 @@ const (
104104
// VxlanUDP is the port used by VXLAN tunneling over UDP
105105
VxlanUDP = 8472
106106

107+
// CalicoVxlanUDP is the port used by Calico VXLAN tunneling over UDP
108+
CalicoVxlanUDP = 4789
109+
107110
// AWSLBCMetricsPort is reserved for the AWS Load Balancer Controller's metrics.
108111
AWSLBCMetricsPort = 9442
109112

0 commit comments

Comments
 (0)