Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create federation secret with default consul-gossip-encryption-key secret when global.gossipEncryption.autoGenerate is set to true #854

Merged
merged 4 commits into from
Nov 15, 2021

Conversation

david-yu
Copy link
Contributor

@david-yu david-yu commented Nov 10, 2021

Changes proposed in this PR:

  • Check to see whether autoGenerate is set to true and use default secret name and secret key to export out gossipEncryptionKey for consul federation secret. Previously the generated gossip encryption key was not exported when setting autoGenerate to true.

How I've tested this PR:

global:
  name: consul
  datacenter: dc1
  image: hashicorp/consul:1.10.3
  tls: 
    enabled: true
  acls: 
    manageSystemACLs: true
    createReplicationToken: true
  federation: 
    enabled: true
    createFederationSecret: true
  gossipEncryption:
    autoGenerate: true
server:
  replicas: 1
ui:
  enabled: true
  service:
    enabled: true
connectInject:
  enabled: true
controller:
  enabled: true
meshGateway:
  enabled: true

Export out consul-federation secret

kubectl get secret consul-federation -o yaml > consul-federation-secret.yaml

Inspect contents of federation secret

> cat consul-federation-secret.yaml
apiVersion: v1
data:
  caCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURRekNDQXVpZ0F3SUJBZ0lVWmdhSGU1MGo1NU1mK0gwZmc5eXRKTnBxQ2Nrd0NnWUlLb1pJemowRUF3SXcKZ1pFeEN6QUpCZ05WQkFZVEFsVlRNUXN3Q1FZRFZRUUlFd0pEUVRFV01CUUdBMVVFQnhNTlUyRnVJRVp5WVc1agphWE5qYnpFYU1CZ0dBMVVFQ1JNUk1UQXhJRk5sWTI5dVpDQlRkSEpsWlhReERqQU1CZ05WQkJFVEJUazBNVEExCk1SY3dGUVlEVlFRS0V3NUlZWE5vYVVOdmNuQWdTVzVqTGpFWU1CWUdBMVVFQXhNUFEyOXVjM1ZzSUVGblpXNTAKSUVOQk1CNFhEVEl4TVRFeE1EQTBORGswTmxvWERUTXhNVEV3T0RBME5UQTBObG93Z1pFeEN6QUpCZ05WQkFZVApBbFZUTVFzd0NRWURWUVFJRXdKRFFURVdNQlFHQTFVRUJ4TU5VMkZ1SUVaeVlXNWphWE5qYnpFYU1CZ0dBMVVFCkNSTVJNVEF4SUZObFkyOXVaQ0JUZEhKbFpYUXhEakFNQmdOVkJCRVRCVGswTVRBMU1SY3dGUVlEVlFRS0V3NUkKWVhOb2FVTnZjbkFnU1c1akxqRVlNQllHQTFVRUF4TVBRMjl1YzNWc0lFRm5aVzUwSUVOQk1Ga3dFd1lIS29aSQp6ajBDQVFZSUtvWkl6ajBEQVFjRFFnQUVkbmk1cUI3dTBxMk40dldBRjVaVTNpeXVTS2JrTWxNV2FObmt3VVNWCmRMZjJ0bHc2VlNNelAyelQ5Smx6WDAxTVBzZnZSaTRrVGxaN1pEM0VNcW93QjZPQ0FSb3dnZ0VXTUE0R0ExVWQKRHdFQi93UUVBd0lCaGpBZEJnTlZIU1VFRmpBVUJnZ3JCZ0VGQlFjREFRWUlLd1lCQlFVSEF3SXdEd1lEVlIwVApBUUgvQkFVd0F3RUIvekJvQmdOVkhRNEVZUVJmTm1RNk16TTZPR1U2WkRrNllUTTZZVFE2TW1FNk1HTTZOekE2Ck5XSTZNMk02TjJZNlpUSTZOamc2T0dJNllUTTZaakE2WVRFNk1UZzZNVE02WTJZNk1HTTZZV1E2WlRVNlpqVTYKTVRjNlpUazZPREU2TlRjNll6RTZNMkU2T1dJd2FnWURWUjBqQkdNd1lZQmZObVE2TXpNNk9HVTZaRGs2WVRNNgpZVFE2TW1FNk1HTTZOekE2TldJNk0yTTZOMlk2WlRJNk5qZzZPR0k2WVRNNlpqQTZZVEU2TVRnNk1UTTZZMlk2Ck1HTTZZV1E2WlRVNlpqVTZNVGM2WlRrNk9ERTZOVGM2WXpFNk0yRTZPV0l3Q2dZSUtvWkl6ajBFQXdJRFNRQXcKUmdJaEFOTkdmNGNCYTkrOXFUSTBjeXF4MHc2T0kwYUFLblEwS3pvSjdCdUl1Q1hYQWlFQXZmN053OVI4clhORwpabVNYazNBSTJwQ1hXWmY4QUt5cGk1Z2VLSHAycjBNPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
  caKey: LS0tLS1CRUdJTiBFQyBQUklWQVRFIEtFWS0tLS0tCk1IY0NBUUVFSUtoWExJL1RaYkhkZzRYdXFWTjhYMTdJOU4yVGx4K3NUTGpDWk8zcHA5K3NvQW9HQ0NxR1NNNDkKQXdFSG9VUURRZ0FFZG5pNXFCN3UwcTJONHZXQUY1WlUzaXl1U0tia01sTVdhTm5rd1VTVmRMZjJ0bHc2VlNNegpQMnpUOUpselgwMU1Qc2Z2Umk0a1RsWjdaRDNFTXFvd0J3PT0KLS0tLS1FTkQgRUMgUFJJVkFURSBLRVktLS0tLQo=
  gossipEncryptionKey: eUxlLzdGRTZJU3ZBUi8rTS9BM2NzK2NPR25Bbm1tdDJiNGo5eDZxRmw3az0=
  replicationToken: MjZlMGY0MmYtZTdlMy1jYjBmLTVkNzctNDY4YjNhNTZjMDYy
  serverConfigJSON: eyJwcmltYXJ5X2RhdGFjZW50ZXIiOiJkYzEiLCJwcmltYXJ5X2dhdGV3YXlzIjpbIjM0LjEwNS4xMTAuNzE6NDQzIl19
kind: Secret
metadata:
  creationTimestamp: "2021-11-10T04:51:44Z"
  name: consul-federation
  namespace: consul
  resourceVersion: "16343"
  uid: 2b145443-8361-4dd3-abbb-dfd5cc0c3404
type: Opaque

How I expect reviewers to test this PR:

Manually, I'm not sure how to automate it.

Checklist:

  • Tests added
  • CHANGELOG entry added

    HashiCorp engineers only, community PRs should not add a changelog entry.
    Entries should use present tense (e.g. Add support for...)

@david-yu david-yu requested a review from t-eckert November 10, 2021 05:14
@david-yu david-yu requested a review from lkysow November 11, 2021 20:33
@david-yu david-yu changed the title Create federation with default consul-gossip-encryption-key secret when global.gossipEncryption.autoGenerate is set to true Create federation secret with default consul-gossip-encryption-key secret when global.gossipEncryption.autoGenerate is set to true Nov 11, 2021
Copy link
Member

@lkysow lkysow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Needs a changelog entry.

@david-yu david-yu merged commit 31586a7 into hashicorp:main Nov 15, 2021
rrondeau pushed a commit to rrondeau/consul-k8s that referenced this pull request Dec 21, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants