diff --git a/doc/book/reference-manual/configuration.md b/doc/book/reference-manual/configuration.md index adc3286b..312afed0 100644 --- a/doc/book/reference-manual/configuration.md +++ b/doc/book/reference-manual/configuration.md @@ -56,10 +56,11 @@ tls_skip_verify = false service_name = "garage-daemon" ca_cert = "/etc/consul/consul-ca.crt" +# for `agent` API mode, unset client_cert and client_key: client_cert = "/etc/consul/consul-client.crt" client_key = "/etc/consul/consul-key.crt" -# for `agent` API mode, unset client_cert and client_key, and optionally enable `token` +# optionally enable `token` for authentication: # token = "abcdef-01234-56789" tags = [ "dns-enabled" ] diff --git a/src/rpc/consul.rs b/src/rpc/consul.rs index 7aac4277..54d46679 100644 --- a/src/rpc/consul.rs +++ b/src/rpc/consul.rs @@ -108,16 +108,16 @@ impl ConsulDiscovery { (None, None) => {} _ => return Err(ConsulError::InvalidTLSConfig), }, - ConsulDiscoveryAPI::Agent => { - if let Some(token) = &config.token { - let mut headers = reqwest::header::HeaderMap::new(); - headers.insert( - "x-consul-token", - reqwest::header::HeaderValue::from_str(token)?, - ); - builder = builder.default_headers(headers); - } - } + ConsulDiscoveryAPI::Agent => {} + } + + if let Some(token) = &config.token { + let mut headers = reqwest::header::HeaderMap::new(); + headers.insert( + "x-consul-token", + reqwest::header::HeaderValue::from_str(token)?, + ); + builder = builder.default_headers(headers); } let client: reqwest::Client = builder.build()?;