From 55370d9b4da75d302afa3a043386b8a79164403c Mon Sep 17 00:00:00 2001 From: Malte Swart Date: Fri, 20 Feb 2026 21:27:59 +0000 Subject: [PATCH] consul: support token auth for catalog api requests, too (#1353) Even when using the catalog an dedicated token for authentication might be needed. **Approach**: Support the token header even with client certs was the simplist approach and somebody might need/want to use it. **Background**: I want to run garage via Nomad but within containers (with host volumes). Nomad generates consul tokens (but at least not at the moment client certs). I need to use the catalog as with the services API garage tries to use the host/node IPs (instead of the actual service IPs). **Tests**: I deployed this version and it works well. Reviewed-on: https://git.deuxfleurs.fr/Deuxfleurs/garage/pulls/1353 Reviewed-by: Alex Co-authored-by: Malte Swart Co-committed-by: Malte Swart --- doc/book/reference-manual/configuration.md | 3 ++- src/rpc/consul.rs | 20 ++++++++++---------- 2 files changed, 12 insertions(+), 11 deletions(-) diff --git a/doc/book/reference-manual/configuration.md b/doc/book/reference-manual/configuration.md index adc3286b..312afed0 100644 --- a/doc/book/reference-manual/configuration.md +++ b/doc/book/reference-manual/configuration.md @@ -56,10 +56,11 @@ tls_skip_verify = false service_name = "garage-daemon" ca_cert = "/etc/consul/consul-ca.crt" +# for `agent` API mode, unset client_cert and client_key: client_cert = "/etc/consul/consul-client.crt" client_key = "/etc/consul/consul-key.crt" -# for `agent` API mode, unset client_cert and client_key, and optionally enable `token` +# optionally enable `token` for authentication: # token = "abcdef-01234-56789" tags = [ "dns-enabled" ] diff --git a/src/rpc/consul.rs b/src/rpc/consul.rs index 7aac4277..54d46679 100644 --- a/src/rpc/consul.rs +++ b/src/rpc/consul.rs @@ -108,16 +108,16 @@ impl ConsulDiscovery { (None, None) => {} _ => return Err(ConsulError::InvalidTLSConfig), }, - ConsulDiscoveryAPI::Agent => { - if let Some(token) = &config.token { - let mut headers = reqwest::header::HeaderMap::new(); - headers.insert( - "x-consul-token", - reqwest::header::HeaderValue::from_str(token)?, - ); - builder = builder.default_headers(headers); - } - } + ConsulDiscoveryAPI::Agent => {} + } + + if let Some(token) = &config.token { + let mut headers = reqwest::header::HeaderMap::new(); + headers.insert( + "x-consul-token", + reqwest::header::HeaderValue::from_str(token)?, + ); + builder = builder.default_headers(headers); } let client: reqwest::Client = builder.build()?;