consul: add k8s servers joining the au-syd1 VM datacenter
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

This commit is contained in:
2026-10-09 22:34:51 +11:00
parent 41abdd42ef
commit e66abc17d0
8 changed files with 357 additions and 14 deletions
+6 -5
View File
@@ -1,7 +1,10 @@
# consul (k8s)
Consul server cluster (DC `au-syd1`), deployed via the HashiCorp helm chart with
ACLs enabled (`default_policy: deny`, parity with the VM cluster).
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N`
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
`198.18.200.5:53`. Agent/default ACL tokens are synced by VSO from
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`.
## API access (ACL auth)
@@ -10,9 +13,7 @@ The HTTP API and UI are served on port 8500 behind the gateway at
With ACLs enabled, requests beyond the anonymous policy require a token:
```bash
# management (bootstrap) token — seeded from Vault, synced by VSO into the
# consul-bootstrap-acl-token secret; same value as the VM cluster's
# initial_management token:
# management token (the VM cluster's initial_management token):
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
+1 -1
View File
@@ -12,7 +12,7 @@ metadata:
cert-manager.io/cluster-issuer: vault-issuer
cert-manager.io/common-name: consul.k8s.syd1.au.unkin.net
cert-manager.io/private-key-size: "4096"
cert-manager.io/alt-names: consul.service.consul
cert-manager.io/alt-names: consul.service.consul,consul.service.au-syd1.consul,consul
external-dns.alpha.kubernetes.io/hostname: consul.k8s.syd1.au.unkin.net
external-dns.alpha.kubernetes.io/target: 198.18.200.4
spec:
+2 -5
View File
@@ -1,9 +1,6 @@
---
# ClusterIP service targeting the consul server pods' HTTP API (8500).
# The HashiCorp chart only ships consul-ui (also 8500 via the server pods)
# and the headless consul-server; this named service gives the Gateway a
# stable API backend. Consul serves both the HTTP API and the UI (at /ui/)
# on this same port, so routing the API hostname here preserves the UI too.
# ClusterIP service targeting the consul server pods' HTTP API and UI (8500),
# the Gateway's backend.
apiVersion: v1
kind: Service
metadata:
+3 -3
View File
@@ -2,16 +2,16 @@
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: bootstrap-acl-token
name: server-acl
namespace: consul
spec:
destination:
create: true
name: consul-bootstrap-acl-token
name: consul-server-acl
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/consul/default/bootstrap-acl-token
path: kubernetes/namespace/consul/default/server-acl
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default