mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-23 19:56:01 +00:00
Prepend the metadata firewall in gce, so it isn't superceded.
This commit is contained in:
parent
289de0ee14
commit
b886897f9d
@ -91,7 +91,7 @@ function config-ip-firewall {
|
|||||||
echo "Configuring IP firewall rules"
|
echo "Configuring IP firewall rules"
|
||||||
|
|
||||||
iptables -N KUBE-METADATA-SERVER
|
iptables -N KUBE-METADATA-SERVER
|
||||||
iptables -A FORWARD -p tcp -d 169.254.169.254 --dport 80 -j KUBE-METADATA-SERVER
|
iptables -I FORWARD -p tcp -d 169.254.169.254 --dport 80 -j KUBE-METADATA-SERVER
|
||||||
|
|
||||||
if [[ -n "${KUBE_FIREWALL_METADATA_SERVER:-}" ]]; then
|
if [[ -n "${KUBE_FIREWALL_METADATA_SERVER:-}" ]]; then
|
||||||
iptables -A KUBE-METADATA-SERVER -j DROP
|
iptables -A KUBE-METADATA-SERVER -j DROP
|
||||||
|
@ -99,7 +99,7 @@ function config-ip-firewall {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
iptables -N KUBE-METADATA-SERVER
|
iptables -N KUBE-METADATA-SERVER
|
||||||
iptables -A FORWARD -p tcp -d 169.254.169.254 --dport 80 -j KUBE-METADATA-SERVER
|
iptables -I FORWARD -p tcp -d 169.254.169.254 --dport 80 -j KUBE-METADATA-SERVER
|
||||||
|
|
||||||
if [[ -n "${KUBE_FIREWALL_METADATA_SERVER:-}" ]]; then
|
if [[ -n "${KUBE_FIREWALL_METADATA_SERVER:-}" ]]; then
|
||||||
iptables -A KUBE-METADATA-SERVER -j DROP
|
iptables -A KUBE-METADATA-SERVER -j DROP
|
||||||
|
Loading…
Reference in New Issue
Block a user