consul: add k8s servers joining the au-syd1 VM datacenter
This commit is contained in:
@@ -1,7 +1,10 @@
|
||||
# consul (k8s)
|
||||
|
||||
Consul server cluster (DC `au-syd1`), deployed via the HashiCorp helm chart with
|
||||
ACLs enabled (`default_policy: deny`, parity with the VM cluster).
|
||||
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that
|
||||
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N`
|
||||
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
|
||||
`198.18.200.5:53`. Agent/default ACL tokens are synced by VSO from
|
||||
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`.
|
||||
|
||||
## API access (ACL auth)
|
||||
|
||||
@@ -10,9 +13,7 @@ The HTTP API and UI are served on port 8500 behind the gateway at
|
||||
With ACLs enabled, requests beyond the anonymous policy require a token:
|
||||
|
||||
```bash
|
||||
# management (bootstrap) token — seeded from Vault, synced by VSO into the
|
||||
# consul-bootstrap-acl-token secret; same value as the VM cluster's
|
||||
# initial_management token:
|
||||
# management token (the VM cluster's initial_management token):
|
||||
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
|
||||
|
||||
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
|
||||
|
||||
@@ -12,7 +12,7 @@ metadata:
|
||||
cert-manager.io/cluster-issuer: vault-issuer
|
||||
cert-manager.io/common-name: consul.k8s.syd1.au.unkin.net
|
||||
cert-manager.io/private-key-size: "4096"
|
||||
cert-manager.io/alt-names: consul.service.consul
|
||||
cert-manager.io/alt-names: consul.service.consul,consul.service.au-syd1.consul,consul
|
||||
external-dns.alpha.kubernetes.io/hostname: consul.k8s.syd1.au.unkin.net
|
||||
external-dns.alpha.kubernetes.io/target: 198.18.200.4
|
||||
spec:
|
||||
|
||||
@@ -1,9 +1,6 @@
|
||||
---
|
||||
# ClusterIP service targeting the consul server pods' HTTP API (8500).
|
||||
# The HashiCorp chart only ships consul-ui (also 8500 via the server pods)
|
||||
# and the headless consul-server; this named service gives the Gateway a
|
||||
# stable API backend. Consul serves both the HTTP API and the UI (at /ui/)
|
||||
# on this same port, so routing the API hostname here preserves the UI too.
|
||||
# ClusterIP service targeting the consul server pods' HTTP API and UI (8500),
|
||||
# the Gateway's backend.
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
|
||||
@@ -2,16 +2,16 @@
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: bootstrap-acl-token
|
||||
name: server-acl
|
||||
namespace: consul
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
name: consul-bootstrap-acl-token
|
||||
name: consul-server-acl
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/consul/default/bootstrap-acl-token
|
||||
path: kubernetes/namespace/consul/default/server-acl
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
|
||||
Reference in New Issue
Block a user