Comparison of Workload Security Group Configuration Methods
In CCE Turbo clusters, pods can be directly bound to security groups using VPC network interfaces or supplementary network interfaces. CCE Turbo provides multi-dimensional security group binding methods to meet your service needs.
Security groups can be associated with workloads through multiple methods: annotations, security group policies, node pool settings, or pod network settings. When multiple methods are used, only the highest-priority method applies. (Lower values in the table below indicate higher priority.)
| Priority | How to Configure | Application and Advantage | Constraint |
|---|---|---|---|
| 1 |
|
| |
| 2 | Binding a Security Group to a Workload Using a Security Group Policy |
| Pre-bound container network interfaces cannot be associated with a target security group. |
| 3 | Using Node Pool Settings to Bind the Default Security Group to Pods in the Node Pool |
|
|
| 4 |
|
| |
| 5 | Default network interface security group of a Turbo cluster (For details about security group rules, see Security Group Rules in a CCE Turbo Cluster That Uses the Cloud Native 2.0 Network Model.) |
| None |