How Do I Harden the VPC Security Group Rules for CCE Cluster Nodes?

CCE is a universal container platform. Its default security group rules apply to common scenarios. Based on security requirements, you can harden the security group rules set for CCE clusters on the Security Groups page of Network Console.

To view security groups, log in to the CCE console, choose Service List > Network > Virtual Private Cloud, and choose Access Control > Security Groups in the navigation pane.

The security group name of a master node is {Cluster name}-cce-control-{Random ID}. The security group name of a worker node is {Cluster name}-cce-node-{Random ID}.

Enable the following ports in security groups:

For {Cluster name}-cce-control-{Random ID}:

For {Cluster name}-cce-node-{Random ID}: