Closed ncapps closed 1 year ago
I will work on a fix for this issue.
@ncapps @rileykarson Can I get some clarification on this PR ? Are you trying to create a GKE cluster with private nodes which operates with PSC instead of VPC Peering? Is that possible today? My understanding was that its only supported for public GKE clusters and GKE cluster with private nodes was not supported yet
Hi @sanmaym, Yes - we are creating GKE clusters with private nodes that use PSC. We have been using this configuration for over a year now. We needed to provision and manage the clusters using gcloud
until this change was applied to the Google Terraform provider.
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.
Community Note
Description
Creating a VPC network peering connection between the cluster VPC and the control plane VPC is not allowed in some enterprise uses cases. An alternative solution is connect the cluster VPC and control plane VPC using a Private Service Connect (PSC) endpoint.
The Terraform resource,
google_container_cluster
, should allow creating a private cluster without specifying themaster_ipv4_cidr_block
. This use case is supported with thegcloud container clusters create
command.Using Terraraform, we currently cannot create a private cluster without providing a value for
master_ipv4_cidr_block
.This configuration results in a Terraform build phase error.
Error message:
New or Affected Resource(s)
Potential Terraform Configuration
References