How can I attach security group to a loadbalancer in EKS cluster?

Viewed 2627

We have an EKS 1.17 Kubernetes cluster in AWS and I am trying to create a load balancer with the attached security group which would allow traffic policy control.

According to this link there should be annotation service.beta.kubernetes.io/aws-load-balancer-extra-security-groups which should allow exactly that when specified in service of type LoadBalancer. When I apply the service template the load balancer is created, but without security groups attached. (see the template and result below)

I have studied a little bit of source code and in some legacy files there was this possibility, however it seems that this code is missing in later versions. What is the status of this functionality? Is there any other automated solution that would allow me to create a load balancer with security group attached?

Template:

apiVersion: v1
kind: Service
metadata:
  annotations:
    service.beta.kubernetes.io/aws-load-balancer-extra-security-groups: sg-0fed8ca44df49ad59
    service.beta.kubernetes.io/aws-load-balancer-type: nlb
  creationTimestamp: null
  finalizers:
  - service.kubernetes.io/load-balancer-cleanup
  labels:
    app: nginx-ingress
    chart: nginx-ingress-1.40.3
    component: controller
    heritage: Helm
    release: nginx-internal
  name: nginx-internal-nginx-ingress-controller
  selfLink: /api/v1/namespaces/ingress/services/nginx-internal-nginx-ingress-controller
spec:
  externalTrafficPolicy: Cluster
  ports:
  - name: http
    nodePort: 32283
    port: 80
    protocol: TCP
    targetPort: http
  - name: https
    nodePort: 30485
    port: 443
    protocol: TCP
    targetPort: https
  selector:
    app: nginx-ingress
    app.kubernetes.io/component: controller
    release: nginx-internal
  sessionAffinity: None
  type: LoadBalancer

Results:

$> aws elbv2 describe-load-balancers --profile cwp-test-admin --names ab45172b455c8471aafce3bb590963a0
{
    "LoadBalancers": [
        {
            "LoadBalancerArn": "arn:aws:elasticloadbalancing:eu-central-1:291004035372:loadbalancer/net/ab45172b455c8471aafce3bb590963a0/e3865ad5129b8c6f",
            "DNSName": "ab45172b455c8471aafce3bb590963a0-e3865ad5129b8c6f.elb.eu-central-1.amazonaws.com",
            "CanonicalHostedZoneId": "Z3F0SRJ5LGBH90",
            "CreatedTime": "2020-08-18T11:19:22.129Z",
            "LoadBalancerName": "ab45172b455c8471aafce3bb590963a0",
            "Scheme": "internet-facing",
            "VpcId": "vpc-0ab00d7cc01d6f870",
            "State": {
                "Code": "active"
            },
            "Type": "network",
            "AvailabilityZones": [
                {
                    "ZoneName": "eu-central-1b",
                    "SubnetId": "subnet-0aa1554d7ba6d766a",
                    "LoadBalancerAddresses": []
                },
                {
                    "ZoneName": "eu-central-1a",
                    "SubnetId": "subnet-0eabf8d5fabfac6be",
                    "LoadBalancerAddresses": []
                }
            ],
            "IpAddressType": "ipv4"
        }
    ]
}
0 Answers
Related