diff --git a/modules/gke-cluster-autopilot/README.md b/modules/gke-cluster-autopilot/README.md
index 78e15e6715..39b8d34d9a 100644
--- a/modules/gke-cluster-autopilot/README.md
+++ b/modules/gke-cluster-autopilot/README.md
@@ -206,25 +206,25 @@ module "cluster-1" {
| name | description | type | required | default |
|---|---|:---:|:---:|:---:|
-| [location](variables.tf#L110) | Autopilot clusters are always regional. | string
| ✓ | |
-| [name](variables.tf#L187) | Cluster name. | string
| ✓ | |
-| [project_id](variables.tf#L223) | Cluster project ID. | string
| ✓ | |
-| [vpc_config](variables.tf#L239) | VPC-level configuration. | object({…})
| ✓ | |
+| [location](variables.tf#L111) | Autopilot clusters are always regional. | string
| ✓ | |
+| [name](variables.tf#L188) | Cluster name. | string
| ✓ | |
+| [project_id](variables.tf#L224) | Cluster project ID. | string
| ✓ | |
+| [vpc_config](variables.tf#L240) | VPC-level configuration. | object({…})
| ✓ | |
| [backup_configs](variables.tf#L17) | Configuration for Backup for GKE. | object({…})
| | {}
|
| [deletion_protection](variables.tf#L37) | Whether or not to allow Terraform to destroy the cluster. Unless this field is set to false in Terraform state, a terraform destroy or terraform apply that would delete the cluster will fail. | bool
| | true
|
| [description](variables.tf#L44) | Cluster description. | string
| | null
|
| [enable_addons](variables.tf#L50) | Addons enabled in the cluster (true means enabled). | object({…})
| | {}
|
-| [enable_features](variables.tf#L64) | Enable cluster-level features. Certain features allow configuration. | object({…})
| | {}
|
-| [issue_client_certificate](variables.tf#L98) | Enable issuing client certificate. | bool
| | false
|
-| [labels](variables.tf#L104) | Cluster resource labels. | map(string)
| | null
|
-| [logging_config](variables.tf#L115) | Logging configuration. | object({…})
| | {}
|
-| [maintenance_config](variables.tf#L126) | Maintenance window configuration. | object({…})
| | {…}
|
-| [min_master_version](variables.tf#L149) | Minimum version of the master, defaults to the version of the most recent official release. | string
| | null
|
-| [monitoring_config](variables.tf#L155) | Monitoring configuration. System metrics collection cannot be disabled. Control plane metrics are optional. Kube state metrics are optional. Google Cloud Managed Service for Prometheus is enabled by default. | object({…})
| | {}
|
-| [node_config](variables.tf#L192) | Configuration for nodes and nodepools. | object({…})
| | {}
|
-| [node_locations](variables.tf#L202) | Zones in which the cluster's nodes are located. | list(string)
| | []
|
-| [private_cluster_config](variables.tf#L209) | Private cluster configuration. | object({…})
| | null
|
-| [release_channel](variables.tf#L228) | Release channel for GKE upgrades. Clusters created in the Autopilot mode must use a release channel. Choose between \"RAPID\", \"REGULAR\", and \"STABLE\". | string
| | "REGULAR"
|
+| [enable_features](variables.tf#L64) | Enable cluster-level features. Certain features allow configuration. | object({…})
| | {}
|
+| [issue_client_certificate](variables.tf#L99) | Enable issuing client certificate. | bool
| | false
|
+| [labels](variables.tf#L105) | Cluster resource labels. | map(string)
| | null
|
+| [logging_config](variables.tf#L116) | Logging configuration. | object({…})
| | {}
|
+| [maintenance_config](variables.tf#L127) | Maintenance window configuration. | object({…})
| | {…}
|
+| [min_master_version](variables.tf#L150) | Minimum version of the master, defaults to the version of the most recent official release. | string
| | null
|
+| [monitoring_config](variables.tf#L156) | Monitoring configuration. System metrics collection cannot be disabled. Control plane metrics are optional. Kube state metrics are optional. Google Cloud Managed Service for Prometheus is enabled by default. | object({…})
| | {}
|
+| [node_config](variables.tf#L193) | Configuration for nodes and nodepools. | object({…})
| | {}
|
+| [node_locations](variables.tf#L203) | Zones in which the cluster's nodes are located. | list(string)
| | []
|
+| [private_cluster_config](variables.tf#L210) | Private cluster configuration. | object({…})
| | null
|
+| [release_channel](variables.tf#L229) | Release channel for GKE upgrades. Clusters created in the Autopilot mode must use a release channel. Choose between \"RAPID\", \"REGULAR\", and \"STABLE\". | string
| | "REGULAR"
|
## Outputs
diff --git a/modules/gke-cluster-autopilot/main.tf b/modules/gke-cluster-autopilot/main.tf
index 4abd4ef491..865177618b 100644
--- a/modules/gke-cluster-autopilot/main.tf
+++ b/modules/gke-cluster-autopilot/main.tf
@@ -58,6 +58,13 @@ resource "google_container_cluster" "cluster" {
}
}
+ dynamic "service_external_ips_config" {
+ for_each = !var.enable_features.service_external_ips ? [""] : []
+ content {
+ enabled = var.enable_features.service_external_ips
+ }
+ }
+
dynamic "authenticator_groups_config" {
for_each = var.enable_features.groups_for_rbac != null ? [""] : []
content {
diff --git a/modules/gke-cluster-autopilot/variables.tf b/modules/gke-cluster-autopilot/variables.tf
index fed9bd1ff2..97c8348b73 100644
--- a/modules/gke-cluster-autopilot/variables.tf
+++ b/modules/gke-cluster-autopilot/variables.tf
@@ -86,7 +86,8 @@ variable "enable_features" {
enable_network_egress_metering = optional(bool)
enable_resource_consumption_metering = optional(bool)
}))
- tpu = optional(bool, false)
+ service_external_ips = optional(bool, true)
+ tpu = optional(bool, false)
upgrade_notifications = optional(object({
topic_id = optional(string)
}))
diff --git a/modules/gke-cluster-standard/README.md b/modules/gke-cluster-standard/README.md
index 0cd7727f69..ceff50a87a 100644
--- a/modules/gke-cluster-standard/README.md
+++ b/modules/gke-cluster-standard/README.md
@@ -310,27 +310,27 @@ module "cluster-1" {
| name | description | type | required | default |
|---|---|:---:|:---:|:---:|
-| [location](variables.tf#L211) | Cluster zone or region. | string
| ✓ | |
-| [name](variables.tf#L322) | Cluster name. | string
| ✓ | |
-| [project_id](variables.tf#L358) | Cluster project id. | string
| ✓ | |
-| [vpc_config](variables.tf#L369) | VPC-level configuration. | object({…})
| ✓ | |
+| [location](variables.tf#L212) | Cluster zone or region. | string
| ✓ | |
+| [name](variables.tf#L323) | Cluster name. | string
| ✓ | |
+| [project_id](variables.tf#L359) | Cluster project id. | string
| ✓ | |
+| [vpc_config](variables.tf#L370) | VPC-level configuration. | object({…})
| ✓ | |
| [backup_configs](variables.tf#L17) | Configuration for Backup for GKE. | object({…})
| | {}
|
| [cluster_autoscaling](variables.tf#L38) | Enable and configure limits for Node Auto-Provisioning with Cluster Autoscaler. | object({…})
| | null
|
| [deletion_protection](variables.tf#L115) | Whether or not to allow Terraform to destroy the cluster. Unless this field is set to false in Terraform state, a terraform destroy or terraform apply that would delete the cluster will fail. | bool
| | true
|
| [description](variables.tf#L122) | Cluster description. | string
| | null
|
| [enable_addons](variables.tf#L128) | Addons enabled in the cluster (true means enabled). | object({…})
| | {…}
|
-| [enable_features](variables.tf#L152) | Enable cluster-level features. Certain features allow configuration. | object({…})
| | {…}
|
-| [issue_client_certificate](variables.tf#L199) | Enable issuing client certificate. | bool
| | false
|
-| [labels](variables.tf#L205) | Cluster resource labels. | map(string)
| | null
|
-| [logging_config](variables.tf#L216) | Logging configuration. | object({…})
| | {}
|
-| [maintenance_config](variables.tf#L237) | Maintenance window configuration. | object({…})
| | {…}
|
-| [max_pods_per_node](variables.tf#L260) | Maximum number of pods per node in this cluster. | number
| | 110
|
-| [min_master_version](variables.tf#L266) | Minimum version of the master, defaults to the version of the most recent official release. | string
| | null
|
-| [monitoring_config](variables.tf#L272) | Monitoring configuration. Google Cloud Managed Service for Prometheus is enabled by default. | object({…})
| | {}
|
-| [node_config](variables.tf#L327) | Node-level configuration. | object({…})
| | {}
|
-| [node_locations](variables.tf#L337) | Zones in which the cluster's nodes are located. | list(string)
| | []
|
-| [private_cluster_config](variables.tf#L344) | Private cluster configuration. | object({…})
| | null
|
-| [release_channel](variables.tf#L363) | Release channel for GKE upgrades. | string
| | null
|
+| [enable_features](variables.tf#L152) | Enable cluster-level features. Certain features allow configuration. | object({…})
| | {…}
|
+| [issue_client_certificate](variables.tf#L200) | Enable issuing client certificate. | bool
| | false
|
+| [labels](variables.tf#L206) | Cluster resource labels. | map(string)
| | null
|
+| [logging_config](variables.tf#L217) | Logging configuration. | object({…})
| | {}
|
+| [maintenance_config](variables.tf#L238) | Maintenance window configuration. | object({…})
| | {…}
|
+| [max_pods_per_node](variables.tf#L261) | Maximum number of pods per node in this cluster. | number
| | 110
|
+| [min_master_version](variables.tf#L267) | Minimum version of the master, defaults to the version of the most recent official release. | string
| | null
|
+| [monitoring_config](variables.tf#L273) | Monitoring configuration. Google Cloud Managed Service for Prometheus is enabled by default. | object({…})
| | {}
|
+| [node_config](variables.tf#L328) | Node-level configuration. | object({…})
| | {}
|
+| [node_locations](variables.tf#L338) | Zones in which the cluster's nodes are located. | list(string)
| | []
|
+| [private_cluster_config](variables.tf#L345) | Private cluster configuration. | object({…})
| | null
|
+| [release_channel](variables.tf#L364) | Release channel for GKE upgrades. | string
| | null
|
## Outputs
diff --git a/modules/gke-cluster-standard/main.tf b/modules/gke-cluster-standard/main.tf
index 71d5eee2a1..069f6d242e 100644
--- a/modules/gke-cluster-standard/main.tf
+++ b/modules/gke-cluster-standard/main.tf
@@ -110,6 +110,12 @@ resource "google_container_cluster" "cluster" {
enabled = var.backup_configs.enable_backup_agent
}
}
+ dynamic "service_external_ips_config" {
+ for_each = !var.enable_features.service_external_ips ? [""] : []
+ content {
+ enabled = var.enable_features.service_external_ips
+ }
+ }
dynamic "authenticator_groups_config" {
for_each = var.enable_features.groups_for_rbac != null ? [""] : []
content {
diff --git a/modules/gke-cluster-standard/variables.tf b/modules/gke-cluster-standard/variables.tf
index 840dd5aeaa..1f95c0c897 100644
--- a/modules/gke-cluster-standard/variables.tf
+++ b/modules/gke-cluster-standard/variables.tf
@@ -177,8 +177,9 @@ variable "enable_features" {
enable_network_egress_metering = optional(bool)
enable_resource_consumption_metering = optional(bool)
}))
- shielded_nodes = optional(bool, false)
- tpu = optional(bool, false)
+ service_external_ips = optional(bool, true)
+ shielded_nodes = optional(bool, false)
+ tpu = optional(bool, false)
upgrade_notifications = optional(object({
topic_id = optional(string)
}))