consul: add k8s servers joining the au-syd1 VM datacenter
This commit is contained in:
@@ -1,7 +1,10 @@
|
||||
# consul (k8s)
|
||||
|
||||
Consul server cluster (DC `au-syd1`), deployed via the HashiCorp helm chart with
|
||||
ACLs enabled (`default_policy: deny`, parity with the VM cluster).
|
||||
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that
|
||||
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N`
|
||||
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
|
||||
`198.18.200.5:53`. Agent/default ACL tokens are synced by VSO from
|
||||
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`.
|
||||
|
||||
## API access (ACL auth)
|
||||
|
||||
@@ -10,9 +13,7 @@ The HTTP API and UI are served on port 8500 behind the gateway at
|
||||
With ACLs enabled, requests beyond the anonymous policy require a token:
|
||||
|
||||
```bash
|
||||
# management (bootstrap) token — seeded from Vault, synced by VSO into the
|
||||
# consul-bootstrap-acl-token secret; same value as the VM cluster's
|
||||
# initial_management token:
|
||||
# management token (the VM cluster's initial_management token):
|
||||
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
|
||||
|
||||
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
|
||||
|
||||
Reference in New Issue
Block a user