Description
A public IP on a TKE node can create a path for internet access. Actual reachability also depends on security groups and network configuration.
Potential impact
Services or management ports on incorrectly restricted nodes may be exposed externally.
Remediation
Set public_ip_assigned to false for nodes that do not need it and use restricted private paths for administration. Review the API server’s public endpoint settings separately.
Examples
These network excerpts use an independent cluster with explicitly configured control-plane and worker nodes. Instance types, VPC settings, and authentication are omitted; establish private administrative access before disabling public access.
Before
hcl
resource "tencentcloud_kubernetes_cluster" "example" {
cluster_name = "tf_example_cluster"
cluster_internet = true
cluster_deploy_type = "INDEPENDENT_CLUSTER"
master_config {
public_ip_assigned = true
}
worker_config {
public_ip_assigned = true
}
}
After
hcl
resource "tencentcloud_kubernetes_cluster" "example" {
cluster_name = "tf_example_cluster"
cluster_internet = false
cluster_deploy_type = "INDEPENDENT_CLUSTER"
master_config {
public_ip_assigned = false
}
worker_config {
public_ip_assigned = false
}
}