mirror of
https://github.com/deuxfleurs-org/garage.git
synced 2026-09-01 17:58:24 +00:00
consul: support token auth for catalog api requests, too (#1353)
Even when using the catalog an dedicated token for authentication might be needed. **Approach**: Support the token header even with client certs was the simplist approach and somebody might need/want to use it. **Background**: I want to run garage via Nomad but within containers (with host volumes). Nomad generates consul tokens (but at least not at the moment client certs). I need to use the catalog as with the services API garage tries to use the host/node IPs (instead of the actual service IPs). **Tests**: I deployed this version and it works well. Reviewed-on: https://git.deuxfleurs.fr/Deuxfleurs/garage/pulls/1353 Reviewed-by: Alex <lx@deuxfleurs.fr> Co-authored-by: Malte Swart <mswart@devtation.de> Co-committed-by: Malte Swart <mswart@devtation.de>
This commit is contained in:
@@ -56,10 +56,11 @@ tls_skip_verify = false
|
|||||||
service_name = "garage-daemon"
|
service_name = "garage-daemon"
|
||||||
|
|
||||||
ca_cert = "/etc/consul/consul-ca.crt"
|
ca_cert = "/etc/consul/consul-ca.crt"
|
||||||
|
# for `agent` API mode, unset client_cert and client_key:
|
||||||
client_cert = "/etc/consul/consul-client.crt"
|
client_cert = "/etc/consul/consul-client.crt"
|
||||||
client_key = "/etc/consul/consul-key.crt"
|
client_key = "/etc/consul/consul-key.crt"
|
||||||
|
|
||||||
# for `agent` API mode, unset client_cert and client_key, and optionally enable `token`
|
# optionally enable `token` for authentication:
|
||||||
# token = "abcdef-01234-56789"
|
# token = "abcdef-01234-56789"
|
||||||
|
|
||||||
tags = [ "dns-enabled" ]
|
tags = [ "dns-enabled" ]
|
||||||
|
|||||||
+10
-10
@@ -108,16 +108,16 @@ impl ConsulDiscovery {
|
|||||||
(None, None) => {}
|
(None, None) => {}
|
||||||
_ => return Err(ConsulError::InvalidTLSConfig),
|
_ => return Err(ConsulError::InvalidTLSConfig),
|
||||||
},
|
},
|
||||||
ConsulDiscoveryAPI::Agent => {
|
ConsulDiscoveryAPI::Agent => {}
|
||||||
if let Some(token) = &config.token {
|
}
|
||||||
let mut headers = reqwest::header::HeaderMap::new();
|
|
||||||
headers.insert(
|
if let Some(token) = &config.token {
|
||||||
"x-consul-token",
|
let mut headers = reqwest::header::HeaderMap::new();
|
||||||
reqwest::header::HeaderValue::from_str(token)?,
|
headers.insert(
|
||||||
);
|
"x-consul-token",
|
||||||
builder = builder.default_headers(headers);
|
reqwest::header::HeaderValue::from_str(token)?,
|
||||||
}
|
);
|
||||||
}
|
builder = builder.default_headers(headers);
|
||||||
}
|
}
|
||||||
|
|
||||||
let client: reqwest::Client = builder.build()?;
|
let client: reqwest::Client = builder.build()?;
|
||||||
|
|||||||
Reference in New Issue
Block a user