1.5 KiB
consul (k8s)
Consul servers (plain StatefulSet, overlay apps/overlays/au-syd1/consul) that
join the VM datacenter au-syd1 as extra raft voters. Pod consul-server-N
advertises its own purelb LB IP 198.18.200.(11+N); consul-dns serves DNS on
198.18.200.5:53. VSO renders the agent/default ACL tokens from
kv/kubernetes/namespace/consul/default/server-acl into consul-server-acl
(acl-tokens.json, hot-reloaded via auto_reload_config). Port 8501 serves
the consul-server-tls certificate.
API access (ACL auth)
The HTTP API and UI are served on port 8500 behind the gateway at
https://consul.k8s.syd1.au.unkin.net (and https://consul.service.consul).
With ACLs enabled, requests beyond the anonymous policy require a token:
# management token (the VM cluster's initial_management token):
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
# consul CLI:
CONSUL_HTTP_ADDR=https://consul.k8s.syd1.au.unkin.net CONSUL_HTTP_TOKEN=$CONSUL_HTTP_TOKEN consul members
The UI at the same hostname exposes an ACL login (top right) — paste a token. Anonymous requests get the anonymous-token policy only (reads for DNS/service discovery; no writes, no ACL/token APIs).
Prefer short-lived tokens minted by Vault's consul secrets engine over the management token for day-to-day use; the terraform-* CI roles already work this way.