-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
google_container_cluster tries to recreate cluster when node_config is set #11022
Comments
So you're saying that the only way to set network tags on the cluster's node pool is through |
Looking at the docs it seems like you should be able to set |
Hey @slevenick thanks for your time! I tried that, but the default nodes alwas have to be deployed and afterwards removed from what i read. Since the default nodes will never succeed without reaching the internet for google apis the cluster won't come online. As a workaround I'm currently using the default node pool even though thats not recommended. |
Got the same issue, we have firewall rules blocking default egress one and allowing only service accounts. Once you specify node_config in google_container_cluster, it tries to recreate the cluster each time. |
[upstream:62869102395e9659ae75cbfdd9ee3879d5e761b5] Signed-off-by: Modular Magician <magic-modules@google.com>
Community Note
modular-magician
user, it is either in the process of being autogenerated, or is planned to be autogenerated soon. If an issue is assigned to a user, that user is claiming responsibility for the issue. If an issue is assigned tohashibot
, a community member has claimed the issue already.Terraform Version
Terraform v0.12.31
Affected Resource(s)
Terraform Configuration Files
Output
Expected Behavior
Being able to re-run
terraform apply
for a kubernetes cluster with custom network tags.Actual Behavior
Setting routing rules in
node_config
on the cluster forces recreation of the cluster. This also has been discussed in #2115, but was closed without mentioning this use case.Important Factoids
Not being able to set network tags limits firewall and routing rules by quite a lot. Seems to me like it should be supported?
References
Thank you!
The text was updated successfully, but these errors were encountered: