|
|
|
@ -43,7 +43,7 @@ resource "google_kms_key_ring" "gke_db" {
|
|
|
|
|
location = var.region
|
|
|
|
|
|
|
|
|
|
lifecycle {
|
|
|
|
|
prevent_destroy = true
|
|
|
|
|
#prevent_destroy = true
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
depends_on = [
|
|
|
|
@ -65,7 +65,7 @@ resource "google_kms_crypto_key" "gke_db" {
|
|
|
|
|
key_ring = google_kms_key_ring.gke_db.id
|
|
|
|
|
|
|
|
|
|
lifecycle {
|
|
|
|
|
prevent_destroy = true
|
|
|
|
|
#prevent_destroy = true
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
depends_on = [
|
|
|
|
@ -114,24 +114,6 @@ resource "google_storage_bucket_iam_member" "gke_gcr" {
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_compute_global_address" "gke_cluster_range" {
|
|
|
|
|
project = var.project
|
|
|
|
|
name = "gke-cluster-range"
|
|
|
|
|
purpose = "VPC_PEERING"
|
|
|
|
|
address_type = "INTERNAL"
|
|
|
|
|
prefix_length = 16
|
|
|
|
|
network = var.private_network_id
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_compute_global_address" "gke_services_range" {
|
|
|
|
|
project = var.project
|
|
|
|
|
name = "gke-services-range"
|
|
|
|
|
purpose = "VPC_PEERING"
|
|
|
|
|
address_type = "INTERNAL"
|
|
|
|
|
prefix_length = 20
|
|
|
|
|
network = var.private_network_id
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_container_cluster" "primary" {
|
|
|
|
|
project = var.project
|
|
|
|
|
name = "gke-cluster"
|
|
|
|
@ -169,12 +151,12 @@ resource "google_container_cluster" "primary" {
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
ip_allocation_policy {
|
|
|
|
|
cluster_secondary_range_name = google_compute_global_address.gke_cluster_range.name
|
|
|
|
|
services_secondary_range_name = google_compute_global_address.gke_services_range.name
|
|
|
|
|
cluster_ipv4_cidr_block = "/16"
|
|
|
|
|
services_ipv4_cidr_block = "/20"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
lifecycle {
|
|
|
|
|
prevent_destroy = true
|
|
|
|
|
#prevent_destroy = true
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
depends_on = [
|
|
|
|
|