Only bind localhost for healthz and default server

This commit is contained in:
danielqsj 2017-08-23 14:40:09 +08:00
parent 85dbc93e4b
commit 7bf0e2f507

View file

@ -361,18 +361,8 @@ http {
# Use the port 18080 (random value just to avoid known ports) as default port for nginx. # Use the port 18080 (random value just to avoid known ports) as default port for nginx.
# Changing this value requires a change in: # Changing this value requires a change in:
# https://github.com/kubernetes/ingress/blob/master/controllers/nginx/pkg/cmd/controller/nginx.go # https://github.com/kubernetes/ingress/blob/master/controllers/nginx/pkg/cmd/controller/nginx.go
{{ range $address := $all.Cfg.BindAddressIpv4 }} listen 127.0.0.1:18080 default_server reuseport backlog={{ $all.BacklogSize }};
listen {{ $address }}:18080 default_server reuseport backlog={{ $all.BacklogSize }}; {{ if $IsIPV6Enabled }}listen [::1]:18080 default_server reuseport backlog={{ .BacklogSize }};{{ end }}
{{ else }}
listen 18080 default_server reuseport backlog={{ $all.BacklogSize }};
{{ end }}
{{ if $IsIPV6Enabled }}
{{ range $address := $all.Cfg.BindAddressIpv6 }}
listen {{ $address }}:18080 default_server reuseport backlog={{ $all.BacklogSize }};
{{ else }}
listen [::]:18080 default_server reuseport backlog={{ $all.BacklogSize }};
{{ end }}
{{ end }}
set $proxy_upstream_name "-"; set $proxy_upstream_name "-";
location {{ $healthzURI }} { location {{ $healthzURI }} {
@ -415,11 +405,7 @@ http {
# default server for services without endpoints # default server for services without endpoints
server { server {
{{ range $address := $all.Cfg.BindAddressIpv4 }} listen 127.0.0.1:8181;
listen {{ $address }}:8181;
{{ else }}
listen 8181;
{{ end }}
set $proxy_upstream_name "-"; set $proxy_upstream_name "-";
location / { location / {