consul: support token auth for catalog api requests, too (#1353)

Even when using the catalog an dedicated token for authentication
might be needed.

**Approach**: Support the token header even with client certs was the simplist approach and somebody might need/want to use it.

**Background**: I want to run garage via Nomad but within containers (with host volumes). Nomad generates consul tokens (but at least not at the moment client certs). I need to use the catalog as with the services API garage tries to use the host/node IPs (instead of the actual service IPs).

**Tests**: I deployed this version and it works well.

Reviewed-on: https://git.deuxfleurs.fr/Deuxfleurs/garage/pulls/1353
Reviewed-by: Alex <lx@deuxfleurs.fr>
Co-authored-by: Malte Swart <mswart@devtation.de>
Co-committed-by: Malte Swart <mswart@devtation.de>
This commit is contained in:
Malte Swart
2026-02-20 21:27:59 +00:00
committed by Alex
parent ce1ea79bf1
commit 55370d9b4d
2 changed files with 12 additions and 11 deletions
+2 -1
View File
@@ -56,10 +56,11 @@ tls_skip_verify = false
service_name = "garage-daemon"
ca_cert = "/etc/consul/consul-ca.crt"
# for `agent` API mode, unset client_cert and client_key:
client_cert = "/etc/consul/consul-client.crt"
client_key = "/etc/consul/consul-key.crt"
# for `agent` API mode, unset client_cert and client_key, and optionally enable `token`
# optionally enable `token` for authentication:
# token = "abcdef-01234-56789"
tags = [ "dns-enabled" ]
+3 -3
View File
@@ -108,7 +108,9 @@ impl ConsulDiscovery {
(None, None) => {}
_ => return Err(ConsulError::InvalidTLSConfig),
},
ConsulDiscoveryAPI::Agent => {
ConsulDiscoveryAPI::Agent => {}
}
if let Some(token) = &config.token {
let mut headers = reqwest::header::HeaderMap::new();
headers.insert(
@@ -117,8 +119,6 @@ impl ConsulDiscovery {
);
builder = builder.default_headers(headers);
}
}
}
let client: reqwest::Client = builder.build()?;