From d630d418ce65c001f979384a2ef30893f3f46b1c Mon Sep 17 00:00:00 2001 From: Jakub Novak Date: Sun, 11 May 2025 19:35:31 +0200 Subject: [PATCH 1/2] Enable firewall logs for ingress --- packages/cluster/network/main.tf | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/packages/cluster/network/main.tf b/packages/cluster/network/main.tf index de76ad28e..9607f1425 100644 --- a/packages/cluster/network/main.tf +++ b/packages/cluster/network/main.tf @@ -582,6 +582,12 @@ resource "google_compute_firewall" "remote_connection_firewall_ingress" { } + dynamic "log_config" { + for_each = var.environment != "dev" ? [1] : [] + content { + metadata = "EXCLUDE_ALL_METADATA" + } + } priority = 1000 From ca2921ac1083b314230049518b544632cfeba6d2 Mon Sep 17 00:00:00 2001 From: Jakub Novak Date: Sun, 11 May 2025 19:38:51 +0200 Subject: [PATCH 2/2] Add comment --- packages/cluster/network/main.tf | 1 + 1 file changed, 1 insertion(+) diff --git a/packages/cluster/network/main.tf b/packages/cluster/network/main.tf index 9607f1425..5a35dd827 100644 --- a/packages/cluster/network/main.tf +++ b/packages/cluster/network/main.tf @@ -582,6 +582,7 @@ resource "google_compute_firewall" "remote_connection_firewall_ingress" { } + # Metadata fields can be found here: https://cloud.google.com/firewall/docs/firewall-rules-logging#log-format dynamic "log_config" { for_each = var.environment != "dev" ? [1] : [] content {