Enable ACLs on k8s consul with Vault-sourced bootstrap token
Phase 1 of the consul VM->k8s migration: bring the k8s consul cluster to ACL parity with the authoritative VM cluster before snapshot-restore. The VM cluster runs ACLs enabled with default_policy deny and down_policy extend-cache; the k8s cluster currently runs with ACLs disabled. Sourcing the bootstrap/management token from Vault lets the k8s cluster bootstrap with the SAME initial_management token as the VM cluster, so puppet automation and the eventual snapshot-restore line up. No token material is placed in git. - Enable global.acls.manageSystemACLs so the chart manages system ACL tokens/policies for consul components. - Point global.acls.bootstrapToken at a pre-existing Kubernetes secret consul-bootstrap-acl-token (key token); when populated the server-acl-init job skips bootstrapping and adopts that token as the management token. - Add a VaultAuth (mount k8s/au/syd1, role default) and VaultStaticSecret in the consul namespace that sync kv/kubernetes/namespace/consul/default/ bootstrap-acl-token into the consul-bootstrap-acl-token secret via VSO. - Merge the acl block (enabled, default_policy deny, down_policy extend-cache, enable_token_persistence) into the server extraConfig to match the VM cluster posture.
This commit is contained in:
@@ -6,3 +6,5 @@ resources:
|
|||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- gateway.yaml
|
- gateway.yaml
|
||||||
- httproute.yaml
|
- httproute.yaml
|
||||||
|
- vaultauth.yaml
|
||||||
|
- vaultstaticsecret.yaml
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
|
kind: VaultAuth
|
||||||
|
metadata:
|
||||||
|
name: default
|
||||||
|
namespace: consul
|
||||||
|
spec:
|
||||||
|
allowedNamespaces:
|
||||||
|
- consul
|
||||||
|
kubernetes:
|
||||||
|
audiences:
|
||||||
|
- vault
|
||||||
|
role: default
|
||||||
|
serviceAccount: default
|
||||||
|
tokenExpirationSeconds: 600
|
||||||
|
method: kubernetes
|
||||||
|
mount: k8s/au/syd1
|
||||||
|
vaultConnectionRef: vso-system/default
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
|
kind: VaultStaticSecret
|
||||||
|
metadata:
|
||||||
|
name: bootstrap-acl-token
|
||||||
|
namespace: consul
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
create: true
|
||||||
|
name: consul-bootstrap-acl-token
|
||||||
|
overwrite: true
|
||||||
|
hmacSecretData: true
|
||||||
|
mount: kv
|
||||||
|
path: kubernetes/namespace/consul/default/bootstrap-acl-token
|
||||||
|
refreshAfter: 5m
|
||||||
|
type: kv-v2
|
||||||
|
vaultAuthRef: default
|
||||||
@@ -3,6 +3,19 @@ global:
|
|||||||
datacenter: au-syd1
|
datacenter: au-syd1
|
||||||
domain: consul
|
domain: consul
|
||||||
|
|
||||||
|
acls:
|
||||||
|
# Enable chart-managed ACL tokens/policies for Consul system components.
|
||||||
|
manageSystemACLs: true
|
||||||
|
# Source the bootstrap/management token from a pre-existing Kubernetes secret
|
||||||
|
# instead of letting the chart generate one. The secret is synced from Vault
|
||||||
|
# via VSO (see ../../../base/consul/vaultauth.yaml and vaultstaticsecret.yaml).
|
||||||
|
# When this secret is populated the server-acl-init job SKIPS bootstrapping and
|
||||||
|
# uses the supplied token as the management token, so the k8s cluster bootstraps
|
||||||
|
# with the SAME initial_management token as the authoritative VM cluster.
|
||||||
|
bootstrapToken:
|
||||||
|
secretName: consul-bootstrap-acl-token
|
||||||
|
secretKey: token
|
||||||
|
|
||||||
server:
|
server:
|
||||||
image: hashicorp/consul:1.22.7
|
image: hashicorp/consul:1.22.7
|
||||||
replicas: 5
|
replicas: 5
|
||||||
@@ -17,6 +30,12 @@ server:
|
|||||||
|
|
||||||
extraConfig: |
|
extraConfig: |
|
||||||
{
|
{
|
||||||
|
"acl": {
|
||||||
|
"enabled": true,
|
||||||
|
"default_policy": "deny",
|
||||||
|
"down_policy": "extend-cache",
|
||||||
|
"enable_token_persistence": true
|
||||||
|
},
|
||||||
"disable_remote_exec": true,
|
"disable_remote_exec": true,
|
||||||
"disable_update_check": true,
|
"disable_update_check": true,
|
||||||
"performance": {
|
"performance": {
|
||||||
|
|||||||
Reference in New Issue
Block a user