Skip to content

Commit 2312731

Browse files
author
瑶喜
committed
修改 0.0.0.0/0为交换机的网段
1 parent 515d6f5 commit 2312731

File tree

1 file changed

+9
-3
lines changed
  • solution/tech-solution/ecs-deploy-deepsite-application

1 file changed

+9
-3
lines changed

solution/tech-solution/ecs-deploy-deepsite-application/main.tf

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,9 @@ resource "alicloud_security_group_rule" "allow_tcp_8080" {
3939
port_range = "8080/8080"
4040
priority = 1
4141
security_group_id = alicloud_security_group.security_group.id
42-
cidr_ip = "0.0.0.0/0"
42+
cidr_ip = "192.168.0.0/24"
43+
# 如需允许从公网访问ECS,请将cidr_ip修改为0.0.0.0/0
44+
# cidr_ip = "0.0.0.0/0"
4345
}
4446

4547
# 安全组入站规则(允许 TCP 80 端口 - 可选,用于 Nginx 部署生成的网页)
@@ -51,7 +53,9 @@ resource "alicloud_security_group_rule" "allow_tcp_80" {
5153
port_range = "80/80"
5254
priority = 1
5355
security_group_id = alicloud_security_group.security_group.id
54-
cidr_ip = "0.0.0.0/0"
56+
cidr_ip = "192.168.0.0/24"
57+
# 如需允许从公网访问ECS,请将cidr_ip修改为0.0.0.0/0
58+
# cidr_ip = "0.0.0.0/0"
5559
}
5660

5761
# 安全组入站规则(允许 TCP 443 端口 - 可选,用于 HTTPS 访问)
@@ -63,7 +67,9 @@ resource "alicloud_security_group_rule" "allow_tcp_443" {
6367
port_range = "443/443"
6468
priority = 1
6569
security_group_id = alicloud_security_group.security_group.id
66-
cidr_ip = "0.0.0.0/0"
70+
cidr_ip = "192.168.0.0/24"
71+
# 如需允许从公网访问ECS,请将cidr_ip修改为0.0.0.0/0
72+
# cidr_ip = "0.0.0.0/0"
6773
}
6874

6975
# ECS实例资源

0 commit comments

Comments
 (0)