34 lines
1.5 KiB
Markdown
34 lines
1.5 KiB
Markdown
# consul (k8s)
|
|
|
|
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that
|
|
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N`
|
|
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
|
|
`198.18.200.5:53`. VSO renders the agent/default ACL tokens from
|
|
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`
|
|
(`acl-tokens.json`, hot-reloaded via `auto_reload_config`). Port 8501 serves
|
|
the `consul-server-tls` certificate.
|
|
|
|
## API access (ACL auth)
|
|
|
|
The HTTP API and UI are served on port 8500 behind the gateway at
|
|
`https://consul.k8s.syd1.au.unkin.net` (and `https://consul.service.consul`).
|
|
With ACLs enabled, requests beyond the anonymous policy require a token:
|
|
|
|
```bash
|
|
# management token (the VM cluster's initial_management token):
|
|
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
|
|
|
|
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
|
|
|
|
# consul CLI:
|
|
CONSUL_HTTP_ADDR=https://consul.k8s.syd1.au.unkin.net CONSUL_HTTP_TOKEN=$CONSUL_HTTP_TOKEN consul members
|
|
```
|
|
|
|
The UI at the same hostname exposes an ACL login (top right) — paste a token.
|
|
Anonymous requests get the anonymous-token policy only (reads for DNS/service
|
|
discovery; no writes, no ACL/token APIs).
|
|
|
|
Prefer short-lived tokens minted by Vault's consul secrets engine over the
|
|
management token for day-to-day use; the terraform-* CI roles already work this
|
|
way.
|