-
Notifications
You must be signed in to change notification settings - Fork 70
Open
Description
Hello,
I deployed a cluster in AWS EKS with version 1.7.12 years ago with the values copied below. There are a few issues I'd like to address for deploying a new Graylog cluster (with the latest version). Could you help?
- Three classic load balancers were created for the old cluster. How can one ALB or NLB be used for service, master, and input (all accesses, including the service, are private)
- The service load balancer deployed is set to TCP, not HTTPS or SSL as I expected.
- How to restrict the inbound/outbound access to
10.0.0.0/8
Thank you,
...
service:
type: LoadBalancer
port: 443
annotations:
service.beta.kubernetes.io/aws-load-balancer-internal: 0.0.0.0/0
service.beta.kubernetes.io/aws-load-balancer-ssl-cert: arn:aws:acm:us-east-1:123456789012:certificate/753cd66c-e8c2-4092-97e9-2a9603033723
service.beta.kubernetes.io/aws-load-balancer-ssl-ports: https
master:
annotations:
service.beta.kubernetes.io/aws-load-balancer-internal: 0.0.0.0/0
port: 9000
input:
tcp:
service:
annotations:
service.beta.kubernetes.io/aws-load-balancer-internal: 0.0.0.0/0
type: LoadBalancer
loadBalancerIP:
ports:
- name: gelf
port: 12201
- name: syslog
port: 12202
externalUri:....
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
graylog ClusterIP None <none> 9000/TCP 2y51d
graylog-master LoadBalancer 172.20.101.245 internal-a7767d80ac73c49aeb2cedef3c567bb0-1132647746.us-east-1.elb.amazonaws.com 9000:30155/TCP 2y51d
graylog-tcp LoadBalancer 172.20.224.75 internal-ade74e0a8cd3441ddbbb6b8291b262fc-1583953693.us-east-1.elb.amazonaws.com 12201:30667/TCP,12202:31423/TCP 2y51d
graylog-web LoadBalancer 172.20.93.132 internal-a617e2764ffd04ac598c0e26bf160db3-2060849374.us-east-1.elb.amazonaws.com 443:32415/TCP 2y51d
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels