Review public IP assignment to Tencent Cloud TKE nodes

Keep nodes on private networks when direct internet access is unnecessary.

Description

A public IP on a TKE node can create a path for internet access. Actual reachability also depends on security groups and network configuration.

Potential impact

Services or management ports on incorrectly restricted nodes may be exposed externally.

Remediation

Set public_ip_assigned to false for nodes that do not need it and use restricted private paths for administration. Review the API server’s public endpoint settings separately.

Examples

These network excerpts use an independent cluster with explicitly configured control-plane and worker nodes. Instance types, VPC settings, and authentication are omitted; establish private administrative access before disabling public access.

Before

hcl
resource "tencentcloud_kubernetes_cluster" "example" {
  cluster_name        = "tf_example_cluster"
  cluster_internet    = true
  cluster_deploy_type = "INDEPENDENT_CLUSTER"

  master_config {
    public_ip_assigned = true
  }

  worker_config {
    public_ip_assigned = true
  }
}

After

hcl
resource "tencentcloud_kubernetes_cluster" "example" {
  cluster_name        = "tf_example_cluster"
  cluster_internet    = false
  cluster_deploy_type = "INDEPENDENT_CLUSTER"

  master_config {
    public_ip_assigned = false
  }

  worker_config {
    public_ip_assigned = false
  }
}

References