Thank you for opening an issue. Please note that we try to keep the Terraform issue tracker reserved for bug reports and feature requests. For general usage questions, please see: https://www.terraform.io/community.html.
Terraform Version
Run terraform -v to show the version. If you are not running the latest version of Terraform, please upgrade because your issue may have already been fixed.
Affected Resource(s)
Please list the resources as a list, for example:
kubernetes_cluster
kubernetes_node_pool
firewall
If this issue appears to affect multiple resources, it may be an issue with Terraform's core, so please mention this.
If Terraform produced a panic, please provide a link to a GitHub Gist containing the output of the crash.log.
Expected Behavior
What should have happened?
The VPC is created, the load balancer is created, the kubernetes cluster with the default node pool is created and the firewall is created. Nodes are only accessible via the load balancer. When trying to use a public port of the nodes, there's no response.
Actual Behavior
What actually happened?
The resources are created, but DO always creates a default firewall for the cluster. This cannot be prevented, it seems, because it also happens when creating the resources in the UI. The DO firewalls are whitelists. Anything that is whitelisted in any of the DO firewalls is permitted. Hence, I cannot make the firewall any stricter than what the default firewall allows.
As a workaround, I can go into the UI and manually delete the auto-created firewall, but that's not ideal.
Steps to Reproduce
Please list the steps required to reproduce the issue, for example:
terraform apply
Important Factoids
Are there anything atypical about your accounts that we should know? For example: Running in EC2 Classic? Custom version of OpenStack? Tight ACLs?
References
Are there any other GitHub issues (open or closed) or Pull Requests that should be linked here? For example:
Hi there,
Thank you for opening an issue. Please note that we try to keep the Terraform issue tracker reserved for bug reports and feature requests. For general usage questions, please see: https://www.terraform.io/community.html.
Terraform Version
Run
terraform -v
to show the version. If you are not running the latest version of Terraform, please upgrade because your issue may have already been fixed.Affected Resource(s)
Please list the resources as a list, for example:
If this issue appears to affect multiple resources, it may be an issue with Terraform's core, so please mention this.
Terraform Configuration Files
Debug Output
Please provider a link to a GitHub Gist containing the complete debug output: https://www.terraform.io/docs/internals/debugging.html. Please do NOT paste the debug output in the issue; just paste a link to the Gist.
Panic Output
If Terraform produced a panic, please provide a link to a GitHub Gist containing the output of the
crash.log
.Expected Behavior
What should have happened?
The VPC is created, the load balancer is created, the kubernetes cluster with the default node pool is created and the firewall is created. Nodes are only accessible via the load balancer. When trying to use a public port of the nodes, there's no response.
Actual Behavior
What actually happened?
The resources are created, but DO always creates a default firewall for the cluster. This cannot be prevented, it seems, because it also happens when creating the resources in the UI. The DO firewalls are whitelists. Anything that is whitelisted in any of the DO firewalls is permitted. Hence, I cannot make the firewall any stricter than what the default firewall allows.
As a workaround, I can go into the UI and manually delete the auto-created firewall, but that's not ideal.
Steps to Reproduce
Please list the steps required to reproduce the issue, for example:
terraform apply
Important Factoids
Are there anything atypical about your accounts that we should know? For example: Running in EC2 Classic? Custom version of OpenStack? Tight ACLs?
References
Are there any other GitHub issues (open or closed) or Pull Requests that should be linked here? For example: