Sitelet https://github.com/kubernetes/kops/pull/18545
Skip to content

gce: allow TCP metrics ports in GCE firewall - #18545

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
Qqkyu:gce-calico-vxlan-firewall
Jul 14, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
Qqkyu:gce-calico-vxlan-firewall

Conversation

@Qqkyu

@Qqkyu Qqkyu commented Jul 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR opens the GCE ingress firewall ports required for Prometheus metrics collection in Calico-based clusters.

Why is this change needed?

When the Prometheus server is enabled in a kOps cluster on GCE, it attempts to scrape metrics from control plane components (Kubelet, Kube-Controller-Manager, Kube-Scheduler, Kube-Proxy, Etcd) on TCP ports 10249, 10257, 10259, and 2382.

Historically, kOps only opened these metrics ports for GCE IP Alias / Kindnet networks. However, this created a gap for Calico-based clusters, where these ports remained blocked, causing Prometheus scraping to fail with connection timeouts.

@kubernetes-prow

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@kubernetes-prow kubernetes-prow Bot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 7, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from olemarkus and zetaab July 7, 2026 14:50
@kubernetes-prow kubernetes-prow Bot added area/provider/gcp Issues or PRs related to gcp provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jul 7, 2026
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch from 2aa9c38 to 867adae Compare July 9, 2026 09:38
@kubernetes-prow kubernetes-prow Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 9, 2026
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch 6 times, most recently from 9207ae4 to d03a6c0 Compare July 10, 2026 09:50
@kubernetes-prow kubernetes-prow Bot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jul 10, 2026
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch 4 times, most recently from d8d83ed to cb2d063 Compare July 10, 2026 11:15
@kubernetes-prow kubernetes-prow Bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 10, 2026
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch 3 times, most recently from 83605d7 to cc40fc8 Compare July 10, 2026 12:33
@kubernetes-prow kubernetes-prow Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jul 10, 2026
@Qqkyu Qqkyu changed the title gce: allow UDP port 4789 in GCE firewall for Calico VXLAN mode gce: allow TCP metrics ports in GCE firewall Jul 13, 2026
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch from f29761c to 66eb511 Compare July 13, 2026 07:53
@Qqkyu
Qqkyu marked this pull request as ready for review July 13, 2026 07:54
@kubernetes-prow kubernetes-prow Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 13, 2026
@kubernetes-prow
kubernetes-prow Bot requested a review from hakman July 13, 2026 07:54

@hakman hakman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @Qqkyu, it seems like a good idea. I would argue that it's best to allow for all CNIs. WDYT?

Allowed: []string{
fmt.Sprintf("tcp:%d", wellknownports.KubeAPIServer),
fmt.Sprintf("tcp:%d", wellknownports.KubeletAPI),
fmt.Sprintf("tcp:%d", wellknownports.KopsControllerPort),

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably best to keep open for any CNI.

Suggested change
fmt.Sprintf("tcp:%d", wellknownports.KopsControllerPort),
// Metrics ports for control plane components, so they can be scraped from nodes.
fmt.Sprintf("tcp:%d", wellknownports.KubeControllerManagerMetricsPort),
fmt.Sprintf("tcp:%d", wellknownports.KubeSchedulerMetricsPort),
fmt.Sprintf("tcp:%d", wellknownports.KubeProxyMetricsPort),
fmt.Sprintf("tcp:%d", wellknownports.EtcdMetricsPort),

Comment thread pkg/model/gcemodel/firewall.go Outdated
Comment on lines +152 to +155
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeControllerManagerMetricsPort))
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeSchedulerMetricsPort))
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeProxyMetricsPort))
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.EtcdMetricsPort))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeControllerManagerMetricsPort))
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeSchedulerMetricsPort))
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.KubeProxyMetricsPort))
t.Allowed = append(t.Allowed, fmt.Sprintf("tcp:%d", wellknownports.EtcdMetricsPort))

Comment thread pkg/model/gcemodel/firewall.go Outdated
Comment on lines 163 to 168

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change

@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch from 66eb511 to 7bb3452 Compare July 14, 2026 09:12
@kubernetes-prow kubernetes-prow Bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 14, 2026
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch from 7bb3452 to 31cdf6b Compare July 14, 2026 09:26
@Qqkyu
Qqkyu force-pushed the gce-calico-vxlan-firewall branch from 31cdf6b to a22a194 Compare July 14, 2026 10:22
@kubernetes-prow kubernetes-prow Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 14, 2026

@hakman hakman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @Qqkyu! 🙂

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 14, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 14, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 572dbe4 into kubernetes:master Jul 14, 2026
28 of 29 checks passed
@Qqkyu
Qqkyu deleted the gce-calico-vxlan-firewall branch July 30, 2026 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/provider/gcp Issues or PRs related to gcp provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants