|
|
|
@ -90,6 +90,78 @@ module "nlb" {
|
|
|
|
|
# tftest modules=1 resources=4
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Mutiple forwarding rules
|
|
|
|
|
|
|
|
|
|
You can add more forwarding rules to your load balancer and override some forwarding rules defaults, including the global access policy, the IP protocol, the IP version and ports.
|
|
|
|
|
|
|
|
|
|
The example adds two forwarding rules:
|
|
|
|
|
|
|
|
|
|
- the first one, called `nlb-test-vip-one` exposes an IPv4 address, it listens on all ports, and allows connections from any region.
|
|
|
|
|
- the second one, called `nlb-test-vip-two` exposes an IPv4 address, it listens on port 80 and allows connections from the same region only.
|
|
|
|
|
|
|
|
|
|
```hcl
|
|
|
|
|
module "nlb" {
|
|
|
|
|
source = "./fabric/modules/net-lb-ext"
|
|
|
|
|
project_id = var.project_id
|
|
|
|
|
region = "europe-west1"
|
|
|
|
|
name = "nlb-test"
|
|
|
|
|
backends = [{
|
|
|
|
|
group = module.nlb.groups.my-group.self_link
|
|
|
|
|
}]
|
|
|
|
|
forwarding_rules_config = {
|
|
|
|
|
vip-one = {}
|
|
|
|
|
vip-two = {
|
|
|
|
|
ports = [80]
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
group_configs = {
|
|
|
|
|
my-group = {
|
|
|
|
|
zone = "europe-west1-b"
|
|
|
|
|
instances = [
|
|
|
|
|
"instance-1-self-link",
|
|
|
|
|
"instance-2-self-link"
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
# tftest modules=1 resources=5
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Dual stack (IPv4 and IPv6)
|
|
|
|
|
|
|
|
|
|
Your load balancer can use a combination of either or both IPv4 and IPv6 forwarding rules.
|
|
|
|
|
In this example we set the load balancer to work as dual stack, meaning it exposes both an IPv4 and an IPv6 address.
|
|
|
|
|
|
|
|
|
|
```hcl
|
|
|
|
|
module "nlb" {
|
|
|
|
|
source = "./fabric/modules/net-lb-ext"
|
|
|
|
|
project_id = var.project_id
|
|
|
|
|
region = "europe-west1"
|
|
|
|
|
name = "nlb-test"
|
|
|
|
|
backends = [{
|
|
|
|
|
group = module.nlb.groups.my-group.self_link
|
|
|
|
|
}]
|
|
|
|
|
forwarding_rules_config = {
|
|
|
|
|
ipv4 = {
|
|
|
|
|
version = "IPV4"
|
|
|
|
|
}
|
|
|
|
|
ipv6 = {
|
|
|
|
|
version = "IPV6"
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
group_configs = {
|
|
|
|
|
my-group = {
|
|
|
|
|
zone = "europe-west1-b"
|
|
|
|
|
instances = [
|
|
|
|
|
"instance-1-self-link",
|
|
|
|
|
"instance-2-self-link"
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
# tftest modules=1 resources=5
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### End to end example
|
|
|
|
|
|
|
|
|
|
This example spins up a simple HTTP server and combines four modules:
|
|
|
|
@ -136,12 +208,16 @@ module "nlb" {
|
|
|
|
|
project_id = var.project_id
|
|
|
|
|
region = "europe-west1"
|
|
|
|
|
name = "nlb-test"
|
|
|
|
|
ports = [80]
|
|
|
|
|
backends = [
|
|
|
|
|
for z, mod in module.instance-group : {
|
|
|
|
|
group = mod.group.self_link
|
|
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
forwarding_rules_config = {
|
|
|
|
|
"" = {
|
|
|
|
|
ports = [80]
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
health_check_config = {
|
|
|
|
|
http = {
|
|
|
|
|
port = 80
|
|
|
|
@ -155,19 +231,18 @@ module "nlb" {
|
|
|
|
|
|
|
|
|
|
| name | description | type | required | default |
|
|
|
|
|
|---|---|:---:|:---:|:---:|
|
|
|
|
|
| [name](variables.tf#L189) | Name used for all resources. | <code>string</code> | ✓ | |
|
|
|
|
|
| [project_id](variables.tf#L200) | Project id where resources will be created. | <code>string</code> | ✓ | |
|
|
|
|
|
| [region](variables.tf#L216) | GCP region. | <code>string</code> | ✓ | |
|
|
|
|
|
| [address](variables.tf#L17) | Optional IP address used for the forwarding rule. | <code>string</code> | | <code>null</code> |
|
|
|
|
|
| [backend_service_config](variables.tf#L23) | Backend service level configuration. | <code title="object({ connection_draining_timeout_sec = optional(number) connection_tracking = optional(object({ idle_timeout_sec = optional(number) persist_conn_on_unhealthy = optional(string) track_per_session = optional(bool) })) failover_config = optional(object({ disable_conn_drain = optional(bool) drop_traffic_if_unhealthy = optional(bool) ratio = optional(number) })) locality_lb_policy = optional(string) log_sample_rate = optional(number) port_name = optional(string) protocol = optional(string, "UNSPECIFIED") session_affinity = optional(string) timeout_sec = optional(number) })">object({…})</code> | | <code>{}</code> |
|
|
|
|
|
| [backends](variables.tf#L72) | Load balancer backends. | <code title="list(object({ group = string description = optional(string, "Terraform managed.") failover = optional(bool, false) }))">list(object({…}))</code> | | <code>[]</code> |
|
|
|
|
|
| [description](variables.tf#L83) | Optional description used for resources. | <code>string</code> | | <code>"Terraform managed."</code> |
|
|
|
|
|
| [group_configs](variables.tf#L89) | Optional unmanaged groups to create. Can be referenced in backends via outputs. | <code title="map(object({ zone = string instances = optional(list(string)) named_ports = optional(map(number), {}) }))">map(object({…}))</code> | | <code>{}</code> |
|
|
|
|
|
| [health_check](variables.tf#L100) | Name of existing health check to use, disables auto-created health check. | <code>string</code> | | <code>null</code> |
|
|
|
|
|
| [health_check_config](variables.tf#L106) | Optional auto-created health check configuration, use the output self-link to set it in the auto healing policy. Refer to examples for usage. | <code title="object({ check_interval_sec = optional(number) description = optional(string, "Terraform managed.") enable_logging = optional(bool, false) healthy_threshold = optional(number) timeout_sec = optional(number) unhealthy_threshold = optional(number) grpc = optional(object({ port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT service_name = optional(string) })) http = optional(object({ host = optional(string) port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request_path = optional(string) response = optional(string) })) http2 = optional(object({ host = optional(string) port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request_path = optional(string) response = optional(string) })) https = optional(object({ host = optional(string) port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request_path = optional(string) response = optional(string) })) tcp = optional(object({ port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request = optional(string) response = optional(string) })) ssl = optional(object({ port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request = optional(string) response = optional(string) })) })">object({…})</code> | | <code title="{ tcp = { port_specification = "USE_SERVING_PORT" } }">{…}</code> |
|
|
|
|
|
| [labels](variables.tf#L183) | Labels set on resources. | <code>map(string)</code> | | <code>{}</code> |
|
|
|
|
|
| [ports](variables.tf#L194) | Comma-separated ports, leave null to use all ports. | <code>list(string)</code> | | <code>null</code> |
|
|
|
|
|
| [protocol](variables.tf#L205) | IP protocol used, defaults to TCP. UDP or L3_DEFAULT can also be used. | <code>string</code> | | <code>"TCP"</code> |
|
|
|
|
|
| [name](variables.tf#L197) | Name used for all resources. | <code>string</code> | ✓ | |
|
|
|
|
|
| [project_id](variables.tf#L202) | Project id where resources will be created. | <code>string</code> | ✓ | |
|
|
|
|
|
| [region](variables.tf#L218) | GCP region. | <code>string</code> | ✓ | |
|
|
|
|
|
| [backend_service_config](variables.tf#L17) | Backend service level configuration. | <code title="object({ connection_draining_timeout_sec = optional(number) connection_tracking = optional(object({ idle_timeout_sec = optional(number) persist_conn_on_unhealthy = optional(string) track_per_session = optional(bool) })) failover_config = optional(object({ disable_conn_drain = optional(bool) drop_traffic_if_unhealthy = optional(bool) ratio = optional(number) })) locality_lb_policy = optional(string) log_sample_rate = optional(number) port_name = optional(string) protocol = optional(string, "UNSPECIFIED") session_affinity = optional(string) timeout_sec = optional(number) })">object({…})</code> | | <code>{}</code> |
|
|
|
|
|
| [backends](variables.tf#L66) | Load balancer backends. | <code title="list(object({ group = string description = optional(string, "Terraform managed.") failover = optional(bool, false) }))">list(object({…}))</code> | | <code>[]</code> |
|
|
|
|
|
| [description](variables.tf#L77) | Optional description used for resources. | <code>string</code> | | <code>"Terraform managed."</code> |
|
|
|
|
|
| [forwarding_rules_config](variables.tf#L83) | The optional forwarding rules configuration. | <code title="map(object({ address = optional(string) description = optional(string) ip_version = optional(string) ports = optional(list(string), null) protocol = optional(string, "TCP") }))">map(object({…}))</code> | | <code title="{ "" = {} }">{…}</code> |
|
|
|
|
|
| [group_configs](variables.tf#L97) | Optional unmanaged groups to create. Can be referenced in backends via outputs. | <code title="map(object({ zone = string instances = optional(list(string)) named_ports = optional(map(number), {}) }))">map(object({…}))</code> | | <code>{}</code> |
|
|
|
|
|
| [health_check](variables.tf#L108) | Name of existing health check to use, disables auto-created health check. | <code>string</code> | | <code>null</code> |
|
|
|
|
|
| [health_check_config](variables.tf#L114) | Optional auto-created health check configuration, use the output self-link to set it in the auto healing policy. Refer to examples for usage. | <code title="object({ check_interval_sec = optional(number) description = optional(string, "Terraform managed.") enable_logging = optional(bool, false) healthy_threshold = optional(number) timeout_sec = optional(number) unhealthy_threshold = optional(number) grpc = optional(object({ port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT service_name = optional(string) })) http = optional(object({ host = optional(string) port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request_path = optional(string) response = optional(string) })) http2 = optional(object({ host = optional(string) port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request_path = optional(string) response = optional(string) })) https = optional(object({ host = optional(string) port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request_path = optional(string) response = optional(string) })) tcp = optional(object({ port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request = optional(string) response = optional(string) })) ssl = optional(object({ port = optional(number) port_name = optional(string) port_specification = optional(string) # USE_FIXED_PORT USE_NAMED_PORT USE_SERVING_PORT proxy_header = optional(string) request = optional(string) response = optional(string) })) })">object({…})</code> | | <code title="{ tcp = { port_specification = "USE_SERVING_PORT" } }">{…}</code> |
|
|
|
|
|
| [labels](variables.tf#L191) | Labels set on resources. | <code>map(string)</code> | | <code>{}</code> |
|
|
|
|
|
| [protocol](variables.tf#L207) | IP protocol used, defaults to TCP. UDP or L3_DEFAULT can also be used. | <code>string</code> | | <code>"TCP"</code> |
|
|
|
|
|
|
|
|
|
|
## Outputs
|
|
|
|
|
|
|
|
|
@ -176,13 +251,13 @@ module "nlb" {
|
|
|
|
|
| [backend_service](outputs.tf#L17) | Backend resource. | |
|
|
|
|
|
| [backend_service_id](outputs.tf#L22) | Backend id. | |
|
|
|
|
|
| [backend_service_self_link](outputs.tf#L27) | Backend self link. | |
|
|
|
|
|
| [forwarding_rule](outputs.tf#L32) | Forwarding rule resource. | |
|
|
|
|
|
| [forwarding_rule_address](outputs.tf#L37) | Forwarding rule address. | |
|
|
|
|
|
| [forwarding_rule_self_link](outputs.tf#L42) | Forwarding rule self link. | |
|
|
|
|
|
| [group_self_links](outputs.tf#L47) | Optional unmanaged instance group self links. | |
|
|
|
|
|
| [groups](outputs.tf#L54) | Optional unmanaged instance group resources. | |
|
|
|
|
|
| [health_check](outputs.tf#L59) | Auto-created health-check resource. | |
|
|
|
|
|
| [health_check_self_id](outputs.tf#L64) | Auto-created health-check self id. | |
|
|
|
|
|
| [health_check_self_link](outputs.tf#L69) | Auto-created health-check self link. | |
|
|
|
|
|
| [id](outputs.tf#L74) | Fully qualified forwarding rule id. | |
|
|
|
|
|
| [forwarding_rule_addresses](outputs.tf#L32) | Forwarding rule addresses. | |
|
|
|
|
|
| [forwarding_rule_self_links](outputs.tf#L40) | Forwarding rule self links. | |
|
|
|
|
|
| [forwarding_rules](outputs.tf#L48) | Forwarding rule resources. | |
|
|
|
|
|
| [group_self_links](outputs.tf#L53) | Optional unmanaged instance group self links. | |
|
|
|
|
|
| [groups](outputs.tf#L60) | Optional unmanaged instance group resources. | |
|
|
|
|
|
| [health_check](outputs.tf#L65) | Auto-created health-check resource. | |
|
|
|
|
|
| [health_check_self_id](outputs.tf#L70) | Auto-created health-check self id. | |
|
|
|
|
|
| [health_check_self_link](outputs.tf#L75) | Auto-created health-check self link. | |
|
|
|
|
|
| [id](outputs.tf#L80) | Fully qualified forwarding rule ids. | |
|
|
|
|
|
<!-- END TFDOC -->
|
|
|
|
|