Skip to content

Commit 87e2f2e

Browse files
authored
fix icmp in cp_ingress_additional_cidrs nsg rule (#572)
Signed-off-by: Omar Aloraini <[email protected]> Signed-off-by: Omar Aloraini <[email protected]>
1 parent 13f845b commit 87e2f2e

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

modules/network/nsgs.tf

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -102,6 +102,20 @@ resource "oci_core_network_security_group_security_rule" "cp_ingress_additional_
102102
}
103103
}
104104

105+
count = length(var.control_plane_allowed_cidrs)
106+
107+
}
108+
109+
resource "oci_core_network_security_group_security_rule" "cp_ingress_additional_cidrs_icmp" {
110+
network_security_group_id = oci_core_network_security_group.cp.id
111+
description = "Allow additional CIDR block access to control plane. Required for kubectl/helm."
112+
direction = "INGRESS"
113+
protocol = local.icmp_protocol
114+
source = element(var.control_plane_allowed_cidrs, count.index)
115+
source_type = "CIDR_BLOCK"
116+
117+
stateless = false
118+
105119
icmp_options {
106120
type = 3
107121
code = 4

0 commit comments

Comments
 (0)