fix: allow optional non-tailnet CIDRs alongside tailnet restrictions
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
locals {
|
locals {
|
||||||
ssh_source_ips = var.restrict_api_ssh_to_tailnet ? [var.tailnet_cidr] : var.allowed_ssh_ips
|
ssh_source_ips = var.restrict_api_ssh_to_tailnet ? concat([var.tailnet_cidr], var.allowed_ssh_ips) : var.allowed_ssh_ips
|
||||||
api_source_ips = var.restrict_api_ssh_to_tailnet ? [var.tailnet_cidr] : var.allowed_api_ips
|
api_source_ips = var.restrict_api_ssh_to_tailnet ? concat([var.tailnet_cidr], var.allowed_api_ips) : var.allowed_api_ips
|
||||||
}
|
}
|
||||||
|
|
||||||
resource "hcloud_firewall" "cluster" {
|
resource "hcloud_firewall" "cluster" {
|
||||||
|
|||||||
Reference in New Issue
Block a user