Skip to content

Commit ff0cb57

Browse files
committed
feat: update getSecurityGroupIngressRules to support EKS additional SG
1 parent bd772dc commit ff0cb57

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

pkg/cloud/services/securitygroup/securitygroups.go

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -648,12 +648,12 @@ func (s *Service) getSecurityGroupIngressRules(role infrav1.SecurityGroupRole) (
648648
}
649649
return append(cniRules, rules...), nil
650650
case infrav1.SecurityGroupEKSNodeAdditional:
651+
rules := infrav1.IngressRules{}
651652
if s.scope.Bastion().Enabled {
652-
return infrav1.IngressRules{
653-
s.defaultSSHIngressRule(s.scope.SecurityGroups()[infrav1.SecurityGroupBastion].ID),
654-
}, nil
653+
rules = append(rules, s.defaultSSHIngressRule(s.scope.SecurityGroups()[infrav1.SecurityGroupBastion].ID))
655654
}
656-
return infrav1.IngressRules{}, nil
655+
ingressRules := s.scope.AdditionalControlPlaneIngressRules()
656+
return append(rules, ingressRules...), nil
657657
case infrav1.SecurityGroupAPIServerLB:
658658
kubeletRules := s.getIngressRulesToAllowKubeletToAccessTheControlPlaneLB()
659659
customIngressRules := s.getControlPlaneLBIngressRules()

0 commit comments

Comments
 (0)