Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
With the introduction of multi-nodegroup support, we have missed the fact that node ports below 1025 are not open (accept for 22 being controller by
--ssh-access
, and 443 being open only to the EKS control plane). We might need to widen internal port access in the future (see #419), but for now we have to open DNS port, as it cripples the functionality of a multi-nodegroup cluster.Fixes #414.
For discussion of full stricter isolation, see #417.
Checklist
make build
)make test
)