diff --git a/CHANGELOG.md b/CHANGELOG.md index 259c420..d69197f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,12 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](http://keepachangelog.com/) and this project adheres to [Semantic Versioning](http://semver.org/). +## [[v1.0.1](https://github.com/terraform-aws-modules/terraform-aws-eks/compare/v1.0.0...v1.0.1)] - 2018-06-23] + +### Added + +- new variable `worker_sg_ingress_from_port` allows to change the minimum port number from which pods will accept communication + ## [[v1.0.0](https://github.com/terraform-aws-modules/terraform-aws-eks/compare/v0.2.0...v1.0.0)] - 2018-06-11] ### Added diff --git a/README.md b/README.md index 1c6d1dd..2b293dd 100644 --- a/README.md +++ b/README.md @@ -104,6 +104,7 @@ MIT Licensed. See [LICENSE](https://github.com/terraform-aws-modules/terraform-a | vpc_id | VPC where the cluster and workers will be deployed. | string | - | yes | | worker_groups | A list of maps defining worker group configurations. See workers_group_defaults for valid keys. | list | `` | no | | worker_security_group_id | If provided, all workers will be attached to this security group. If not given, a security group will be created with necessary ingres/egress to work with the EKS cluster. | string | `` | no | +| worker_sg_ingress_from_port | Minimum port number from which pods will accept communication. Must be changed to a lower value if some pods in your cluster will expose a port lower than 1025 (e.g. 22, 80, or 443). | string | `1025` | no | | workers_group_defaults | Default values for target groups as defined by the list of maps. | map | `` | no | ## Outputs diff --git a/variables.tf b/variables.tf index 442f487..245211d 100644 --- a/variables.tf +++ b/variables.tf @@ -67,3 +67,8 @@ variable "worker_security_group_id" { description = "If provided, all workers will be attached to this security group. If not given, a security group will be created with necessary ingres/egress to work with the EKS cluster." default = "" } + +variable "worker_sg_ingress_from_port" { + description = "Minimum port number from which pods will accept communication. Must be changed to a lower value if some pods in your cluster will expose a port lower than 1025 (e.g. 22, 80, or 443)." + default = "1025" +} diff --git a/version b/version index 0ec25f7..b18d465 100644 --- a/version +++ b/version @@ -1 +1 @@ -v1.0.0 +v1.0.1 diff --git a/workers.tf b/workers.tf index 800dc08..ed3f0d8 100644 --- a/workers.tf +++ b/workers.tf @@ -73,7 +73,7 @@ resource "aws_security_group_rule" "workers_ingress_cluster" { protocol = "tcp" security_group_id = "${aws_security_group.workers.id}" source_security_group_id = "${local.cluster_security_group_id}" - from_port = 1025 + from_port = "${var.worker_sg_ingress_from_port}" to_port = 65535 type = "ingress" count = "${var.worker_security_group_id == "" ? 1 : 0}"