Add consul server federation SANs to consul server certs #547

Merged
benvin merged 1 commits from benvin/consul-server-fed-sans into develop 2026-10-09 21:51:47 +11:00
Member

WAN federation through mesh gateways makes Consul verify server certs against server.<dc>.consul and <node_name>.server.<dc>.consul. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified.

  • add server.<country>-<region>.consul to consul server alt_names
  • add <fqdn>.server.<country>-<region>.consul to consul server alt_names
WAN federation through mesh gateways makes Consul verify server certs against `server.<dc>.consul` and `<node_name>.server.<dc>.consul`. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified. - add `server.<country>-<region>.consul` to consul server alt_names - add `<fqdn>.server.<country>-<region>.consul` to consul server alt_names
unkin-agent added 1 commit 2026-10-07 11:46:37 +11:00
Add consul server federation SANs to consul server certs
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
f35b385714
Author
Member
  • hieradata/roles/infra/storage/consul.yaml:34-35 — SANs land in the Vault host cert (/etc/pki/tls/vault), but profiles::consul::server config_hash has no tls block (no cert_file/key_file/ca_file/verify_server_hostname), so Consul never presents this cert and the federation verification in the why is unaffected → wire the consul server TLS config to this cert in this PR, or reword the why to state this is prep for a follow-up PR that does.
- hieradata/roles/infra/storage/consul.yaml:34-35 — SANs land in the Vault host cert (/etc/pki/tls/vault), but profiles::consul::server config_hash has no tls block (no cert_file/key_file/ca_file/verify_server_hostname), so Consul never presents this cert and the federation verification in the why is unaffected → wire the consul server TLS config to this cert in this PR, or reword the why to state this is prep for a follow-up PR that does.
Author
Member

No findings.

No findings.
benvin merged commit 6c880d9794 into develop 2026-10-09 21:51:47 +11:00
benvin deleted branch benvin/consul-server-fed-sans 2026-10-09 21:51:50 +11:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/puppet-prod#547