Skip to main content
Attach network security groups to Managed Kubernetes node groups to control traffic to and from your cluster’s nodes.

Prerequisites

Before attaching security groups to a node group, you need to create them. See Managing security groups for instructions on creating groups and defining rules.
If you use your own security groups to restrict egress traffic, make sure that the cluster can still access the resources it needs. For example, blocking outbound internet access can break functionality that depends on it, such as pulling images from external registries.
Set up the interface that you are going to use:

How to attach security groups to a node group

To attach a security group to a node group:
  1. In the web console, go to  Compute → Kubernetes.
  2. Open the page of the cluster with the node group where you want to attach a security group.
  3. Switch to the Node groups tab and open the page of the required node group.
  4. On the node group page, switch to the Security groups tab and click Attach security groups.
  5. In the window that opens, select one or multiple security groups and click Attach security groups.

How to update security groups on an existing node group

To change or delete the attached security group from a node group:
  1. In the web console, go to  Compute → Kubernetes.
  2. Open the page of the cluster with the node group where you want to change a security group.
  3. Switch to the Node groups tab and open the page of the required node group.
  4. On the node group page, switch to the Security groups tab.
    • To attach a different security group:
      1. Click Attach security groups.
      2. In the window that opens, select one or multiple security groups and click Attach security groups.
    • To detach a security group:
      1. Click next to the security group you want to detach and select Detach.
      2. In the window that opens, enter the name of the security group and click Detach security group.
The update replaces the whole network interface list, so include every subnet and security group that the node group must keep.