consul: add k8s servers joining the au-syd1 VM datacenter
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

This commit is contained in:
2026-10-09 22:34:51 +11:00
parent 41abdd42ef
commit e66abc17d0
8 changed files with 357 additions and 14 deletions
+6 -5
View File
@@ -1,7 +1,10 @@
# consul (k8s)
Consul server cluster (DC `au-syd1`), deployed via the HashiCorp helm chart with
ACLs enabled (`default_policy: deny`, parity with the VM cluster).
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N`
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
`198.18.200.5:53`. Agent/default ACL tokens are synced by VSO from
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`.
## API access (ACL auth)
@@ -10,9 +13,7 @@ The HTTP API and UI are served on port 8500 behind the gateway at
With ACLs enabled, requests beyond the anonymous policy require a token:
```bash
# management (bootstrap) token — seeded from Vault, synced by VSO into the
# consul-bootstrap-acl-token secret; same value as the VM cluster's
# initial_management token:
# management token (the VM cluster's initial_management token):
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader