Consul is a distributed, highly available, and data center aware solution to connect and configure applications across dynamic, distributed infrastructure.
 
 
 
 
 
 
Go to file
Iryna Shustava 54a12ab3c9
mesh: sidecar proxy controller improvements (#19083)
This change builds on #19043 and #19067 and updates the sidecar controller to use those computed resources. This achieves several benefits:

   * The cache is now simplified which helps us solve for previous bugs (such as multiple Upstreams/Destinations targeting the same service would overwrite each other)
   * We no longer need proxy config cache
   * We no longer need to do merging of proxy configs as part of the controller logic
   * Controller watches are simplified because we no longer need to have complex mapping using cache and can instead use the simple ReplaceType mapper.

It also makes several other improvements/refactors:

  * Unifies all caches into one. This is because originally the caches were more independent, however, now that they need to interact with each other it made sense to unify them where sidecar proxy controller uses one cache with 3 bimappers
   * Unifies cache and mappers. Mapper already needed all caches anyway and so it made sense to make the cache do the mapping also now that the cache is unified.
   * Gets rid of service endpoints watches. This was needed to get updates in a case when service's identities have changed and we need to update proxy state template's spiffe IDs for those destinations. This will however generate a lot of reconcile requests for this controller as service endpoints objects can change a lot because they contain workload's health status. This is solved by adding a status to the service object tracking "bound identities" and have service endpoints controller update it. Having service's status updated allows us to get updates in the sidecar proxy controller because it's already watching service objects
   * Add a watch for workloads. We need it so that we get updates if workload's ports change. This also ensures that we update cached identities in case workload's identity changes.
2023-10-12 13:20:13 -06:00
.changelog Update Vault CA provider namespace configuration (#19095) 2023-10-10 13:53:00 +00:00
.github Fix BUSL license checker to skip >= 1.17.x target branches (#19152) (#19154) 2023-10-11 17:15:13 -05:00
.release OSS -> CE (community edition) changes (#18517) 2023-08-22 09:46:03 -05:00
acl Remove old build tags (#19128) 2023-10-10 10:58:06 -04:00
agent Refactor connect_auth.go into agent_endpoint.go (#19166) 2023-10-12 12:54:32 -04:00
api test: fix container test enterprise drift (#19101) 2023-10-11 15:39:09 -05:00
bench
build-support NET-5657 - consul-containers test for explicit upstreams (#18952) 2023-09-26 16:21:47 -04:00
command cli: do not hide the resource HCL parsing error and replace it with a JSON error (#19107) 2023-10-11 11:37:50 -05:00
connect [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
contributing Move contributing to docs 2021-08-30 16:17:09 -04:00
docs resource: allow for the ACLs.Read hook to request the entire data payload to perform the authz check (#18925) 2023-09-22 09:53:55 -05:00
envoyextensions feat: remove resource api client from api module (#18984) 2023-09-22 16:32:08 -04:00
grafana grafana: fix a query metrics from ent and add consul version (#18998) 2023-09-25 12:41:13 -04:00
internal mesh: sidecar proxy controller improvements (#19083) 2023-10-12 13:20:13 -06:00
ipaddr [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
lib OSS -> CE (community edition) changes (#18517) 2023-08-22 09:46:03 -05:00
logging Remove old build tags (#19128) 2023-10-10 10:58:06 -04:00
proto v2tenancy: cluster scoped reads (#19082) 2023-10-10 13:30:23 -05:00
proto-public mesh: sidecar proxy controller improvements (#19083) 2023-10-12 13:20:13 -06:00
sdk sdk: update testutil.WaitForLeader to not use the v1 catalog api (#19146) 2023-10-11 15:28:25 -05:00
sentinel Remove old build tags (#19128) 2023-10-10 10:58:06 -04:00
service_os Remove old build tags (#19128) 2023-10-10 10:58:06 -04:00
snapshot [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
test test: fix container test enterprise drift (#19101) 2023-10-11 15:39:09 -05:00
test-integ dns token (#17936) 2023-09-20 15:50:06 -06:00
testing/deployer chore: fix ce/ent drift in sdk and testing/deployer submodules (#19041) 2023-10-03 10:06:50 -05:00
testrpc [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
tlsutil Remove old build tags (#19128) 2023-10-10 10:58:06 -04:00
tools/internal-grpc-proxy [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
troubleshoot feat: remove resource api client from api module (#18984) 2023-09-22 16:32:08 -04:00
types [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
ui feat: copy edits for built-in policy alert (#18655) 2023-09-01 13:58:03 -07:00
version [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
website fix broken link (#19140) 2023-10-11 17:14:34 +00:00
.copywrite.hcl Move ACL templated policies to hcl files (#18853) 2023-09-18 17:10:35 -04:00
.dockerignore
.gitignore add peering_commontopo tests [NET-3700] (#17951) 2023-07-18 16:41:30 -07:00
.golangci.yml dataplane: Allow getting bootstrap parameters when using V2 APIs (#18504) 2023-09-06 16:46:25 -06:00
CHANGELOG.md Fix changelog order (#18918) 2023-09-20 13:42:17 -04:00
Dockerfile [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
Dockerfile-windows Envoy Integration Test Windows (#18007) 2023-07-21 20:26:00 +05:30
LICENSE [COMPLIANCE] License update (#18479) 2023-08-16 09:42:07 -05:00
Makefile Add traffic permissions integration tests. (#19008) 2023-10-06 12:06:12 -04:00
NOTICE.md add copyright notice file 2018-07-09 10:58:26 -07:00
README.md README - re-order badges and update hub link (#18498) 2023-08-16 18:41:43 -07:00
buf.work.yaml [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
fixup_acl_move.sh [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00
go.mod feat: remove resource api client from api module (#18984) 2023-09-22 16:32:08 -04:00
go.sum NET-4519 Collecting journald logs in "consul debug" bundle (#18797) 2023-09-19 08:46:50 +05:30
main.go [COMPLIANCE] License changes (#18443) 2023-08-11 09:12:13 -04:00

README.md

Consul logo Consul

License: BUSL-1.1 Docker Pulls Go Report Card

Consul is a distributed, highly available, and data center aware solution to connect and configure applications across dynamic, distributed infrastructure.

Consul provides several key features:

  • Multi-Datacenter - Consul is built to be datacenter aware, and can support any number of regions without complex configuration.

  • Service Mesh - Consul Service Mesh enables secure service-to-service communication with automatic TLS encryption and identity-based authorization. Applications can use sidecar proxies in a service mesh configuration to establish TLS connections for inbound and outbound connections with Transparent Proxy.

  • Service Discovery - Consul makes it simple for services to register themselves and to discover other services via a DNS or HTTP interface. External services such as SaaS providers can be registered as well.

  • Health Checking - Health Checking enables Consul to quickly alert operators about any issues in a cluster. The integration with service discovery prevents routing traffic to unhealthy hosts and enables service level circuit breakers.

  • Dynamic App Configuration - An HTTP API that allows users to store indexed objects within Consul, for storing configuration parameters and application metadata.

Consul runs on Linux, macOS, FreeBSD, Solaris, and Windows and includes an optional browser based UI. A commercial version called Consul Enterprise is also available.

Please note: We take Consul's security and our users' trust very seriously. If you believe you have found a security issue in Consul, please responsibly disclose by contacting us at security@hashicorp.com.

Quick Start

A few quick start guides are available on the Consul website:

Documentation

Full, comprehensive documentation is available on the Consul website: https://consul.io/docs

Contributing

Thank you for your interest in contributing! Please refer to CONTRIBUTING.md for guidance. For contributions specifically to the browser based UI, please refer to the UI's README.md for guidance.