Luke Kysow
9093b99dfd
Document new annotations for Connect injections
2019-10-04 15:31:24 -07:00
Sarah Christoff
9b93dd93c9
Prune Unhealthy Agents ( #6571 )
...
* Add -prune flag to ForceLeave
2019-10-04 16:10:02 -05:00
Freddy
349fa7f97d
Update Force Leave docs ( #6550 )
...
Fixes #2742
Previously the docs didn't clarify that if a server restarts as a client then force-leave won't lead to removing the node from the raft config. This is because the node, which is alive after a restart, will refute messages about it having left . These messages about members leaving are in turn what trigger Consul's leader to remove a server from raft.
2019-09-27 17:49:28 -06:00
Mike Morris
3434c8289d
docs: add managed proxy removal note to specific version upgrade notes ( #6557 )
2019-09-27 10:52:47 -04:00
Judith Malnick
746f786a9f
Specify that mesh gateways require Envoy ( #6506 )
...
* Specify that mesh gateways must operate on L7
* Add feedback from Matt
* clarify gateway requirements
2019-09-26 20:06:58 -07:00
Freddy
5eace88ce2
Expose HTTP-based paths through Connect proxy ( #6446 )
...
Fixes : #5396
This PR adds a proxy configuration stanza called expose. These flags register
listeners in Connect sidecar proxies to allow requests to specific HTTP paths from outside of the node. This allows services to protect themselves by only
listening on the loopback interface, while still accepting traffic from non
Connect-enabled services.
Under expose there is a boolean checks flag that would automatically expose all
registered HTTP and gRPC check paths.
This stanza also accepts a paths list to expose individual paths. The primary
use case for this functionality would be to expose paths for third parties like
Prometheus or the kubelet.
Listeners for requests to exposed paths are be configured dynamically at run
time. Any time a proxy, or check can be registered, a listener can also be
created.
In this initial implementation requests to these paths are not
authenticated/encrypted.
2019-09-25 20:55:52 -06:00
R.B. Boyer
cc889443a5
connect: don't colon-hex-encode the AuthorityKeyId and SubjectKeyId fields in connect certs ( #6492 )
...
The fields in the certs are meant to hold the original binary
representation of this data, not some ascii-encoded version.
The only time we should be colon-hex-encoding fields is for display
purposes or marshaling through non-TLS mediums (like RPC).
2019-09-23 12:52:35 -05:00
Luke Kysow
c5fca5d4b5
Update consul-helm enterprise docs for ACLs
...
If ACLs are added then slightly different commands are needed.
2019-09-19 15:09:38 -07:00
Luke Kysow
bd789f1011
Update Consul DNS on kube docs
...
- fix instructions for CoreDNS (it updated)
- fix instructions for new component names
- recommend installing with the name 'consul'
- add disclaimer that catalog sync is not always required
- clean up example values.yaml files
2019-09-19 15:09:38 -07:00
Iryna Shustava
ca98bd0eb8
Merge pull request #6500 from hashicorp/typo-fix
...
Fix typo in "Service Ports" section
2019-09-18 13:11:52 -07:00
kaitlincarter-hc
483870b01a
[docs]Updated Containers Guide ( #6215 )
...
* Adding the updated containers guide that will be deployed on Learn only.
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
Co-Authored-By: Freddy <freddygv@users.noreply.github.com>
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
* Update website/source/docs/guides/containers-guide.md
2019-09-17 13:35:46 -07:00
Iryna Shustava
b3f1b5afd5
Fix typo in "Service Ports" section
2019-09-17 12:05:04 -07:00
Blake Covarrubias
d6f2371fcd
docs: Fix typo in acl/acl-rules
2019-09-13 19:50:35 -07:00
Hans Hasselberg
62de041a36
docs (Consul Enterprise): Google Cloud Storage snapshot documentation ( #6480 )
2019-09-13 17:54:15 +02:00
Jud White
25aab18339
docs: fix typo in install/performance ( #6428 )
2019-09-09 21:23:25 +01:00
dcallao
876a7cbef9
fixed broken links on consul program page ( #6463 )
2019-09-06 17:18:59 -04:00
dcallao
58f19c5918
docs: added Consul Integration Program Docs Page ( #6459 )
...
* adding the Consul Integration Program page in docs section
2019-09-06 14:52:18 -04:00
Freddy
51fbcc5fcd
Rephrase bind docs ( #6394 )
2019-08-26 11:31:55 -06:00
R.B. Boyer
2d4a3b51d0
Merge pull request #6388 from hashicorp/release/1-6
...
merging release/1-6 into master
2019-08-23 13:44:46 -05:00
Anudeep Reddy
02197b2cd2
Update observability.html.md ( #6379 )
2019-08-23 17:07:48 +02:00
danielehc
992b1a8d88
Update agent.html.markdown.erb ( #6380 )
...
Adding a note on how to make Consul trust S3-compatible storage that expose a self-signed certificate.
2019-08-23 16:09:41 +02:00
R.B. Boyer
17bf364668
docs: remove beta references; leave version notation ( #6372 )
2019-08-21 16:23:08 -05:00
R.B. Boyer
e7b8032b48
docs: document how envoy escape hatches work with the discovery chain ( #6350 )
...
- Bootstrap escape hatches are OK.
- Public listener/cluster escape hatches are OK.
- Upstream listener/cluster escape hatches are not supported.
If an unsupported escape hatch is configured and the discovery chain is
activated log a warning and act like it was not configured.
Fixes #6160
2019-08-21 15:10:12 -05:00
Alvin Huang
387557dc34
Merge Consul OSS branch 'master' at commit ce9cfc773d529ae4b8259d195323c0c350c1f9f1
2019-08-21 16:07:04 -04:00
R.B. Boyer
5f9acb6894
docs: fixing L7 config entries documentation ( #6358 )
...
- add service-router example involving gRPC
- fix indentation on service-router page by splitting it up
- remove reference to removed setting
2019-08-21 12:29:53 -05:00
R.B. Boyer
e04395ae1a
docs: add documentation for discovery chains
...
Fixes #6273
2019-08-21 12:29:53 -05:00
Ján Dzurek
e79a3a9e19
docs: ports docs missing paren fix ( #6367 )
2019-08-21 10:23:03 +02:00
hashicorp-ci
f3a46e5a48
Merge Consul OSS branch 'master' at commit a7ded1bd8efcbc3c67978f050b6f16ec5e8a832d
2019-08-21 02:00:53 +00:00
Matt Keeler
80b67c50da
Turned on Envoy 1.11.1 integration tests ( #6347 )
...
I also ran this against 1.5.2 so the docs update claiming compatibility should still be accurate.
2019-08-20 10:20:13 -04:00
tryan225
a57dbc0d2a
Clarifying autopilot bootstrap and config options
2019-08-16 10:54:13 -07:00
hashicorp-ci
29767157ed
Merge Consul OSS branch 'master' at commit 8f7586b339dbb518eff3a2eec27d7b8eae7a3fbb
2019-08-13 02:00:43 +00:00
Sarah Adams
2f7a90bc52
add flag to allow /operator/keyring requests to only hit local servers ( #6279 )
...
Add parameter local-only to operator keyring list requests to force queries to only hit local servers (no WAN traffic).
HTTP API: GET /operator/keyring?local-only=true
CLI: consul keyring -list --local-only
Sending the local-only flag with any non-GET/list request will result in an error.
2019-08-12 11:11:11 -07:00
hashicorp-ci
eb53f9175c
Merge Consul OSS branch 'master' at commit 8241787e922955e973c0e762ad3cb8db1804f6cd
2019-08-11 02:01:18 +00:00
Jake Lundberg
a530fee06e
docs: Update consul-helm example to pull latest tag
2019-08-09 16:33:43 -06:00
Mike Morris
88df658243
connect: remove managed proxies ( #6220 )
...
* connect: remove managed proxies implementation and all supporting config options and structs
* connect: remove deprecated ProxyDestination
* command: remove CONNECT_PROXY_TOKEN env var
* agent: remove entire proxyprocess proxy manager
* test: remove all managed proxy tests
* test: remove irrelevant managed proxy note from TestService_ServerTLSConfig
* test: update ContentHash to reflect managed proxy removal
* test: remove deprecated ProxyDestination test
* telemetry: remove managed proxy note
* http: remove /v1/agent/connect/proxy endpoint
* ci: remove deprecated test exclusion
* website: update managed proxies deprecation page to note removal
* website: remove managed proxy configuration API docs
* website: remove managed proxy note from built-in proxy config
* website: add note on removing proxy subdirectory of data_dir
2019-08-09 15:19:30 -04:00
Matt Keeler
ef7cbc5850
mesh-gateway ACL tokens should also have node:read
on everyth… ( #6291 )
2019-08-07 13:52:57 -04:00
Alvin Huang
ae898a4a33
Merge remote-tracking branch 'origin/master' into release/1-6
2019-08-02 18:09:32 -04:00
Omer Zach
1e80fc9c0f
Fix typo in architecture.html.md ( #6261 )
2019-08-01 12:21:37 -06:00
Venkata Krishna Annam
5011f305e0
docs: Fix minor mistakes in index.html.md ( #6239 )
2019-08-01 12:57:26 -05:00
freddygv
00157a2c1f
Update default gossip encryption key size to 32 bytes
2019-07-30 09:45:41 -06:00
Alvin Huang
7972514b82
Merge remote-tracking branch 'origin/master' into release/1-6
2019-07-26 16:22:53 -04:00
Matt Keeler
9dd72121e1
Set --max-obj-name-len 256 when execing Envoy ( #6202 )
...
* Pass -max-obj-name-len 256 to envoy
* Update test expectations.
* Add a note about requireing the max-obj-name-len option to be set
2019-07-26 15:43:15 -04:00
Todd Radel
c253a23630
Merge pull request #6210 from hashicorp/docs/fix-ambassador-link
...
Fix links to ambassador website
2019-07-26 14:29:03 -04:00
R.B. Boyer
1b95d2e5e3
Merge Consul OSS branch master at commit b3541c4f34d43ab92fe52256420759f17ea0ed73
2019-07-26 10:34:24 -05:00
Mike Morris
2c78c476a0
docs: add TCP half-close broken pipe to common errors ( #6203 )
2019-07-25 16:01:33 -04:00
Todd Radel
7575bce5c9
Fix links to ambassador website
2019-07-24 13:23:49 -04:00
R.B. Boyer
bd4a2d7be2
connect: allow L7 routers to match on http methods ( #6164 )
...
Fixes #6158
2019-07-23 20:56:39 -05:00
R.B. Boyer
67f3da61af
connect: change router syntax for matching query parameters to resemble the syntax for matching paths and headers for consistency. ( #6163 )
...
This is a breaking change, but only in the context of the beta series.
2019-07-23 20:55:26 -05:00
R.B. Boyer
2bfad66efa
connect: rework how the service resolver subset OnlyPassing flag works ( #6173 )
...
The main change is that we no longer filter service instances by health,
preferring instead to render all results down into EDS endpoints in
envoy and merely label the endpoints as HEALTHY or UNHEALTHY.
When OnlyPassing is set to true we will force consul checks in a
'warning' state to render as UNHEALTHY in envoy.
Fixes #6171
2019-07-23 20:20:24 -05:00
Alvin Huang
5b6fa58453
resolve circleci config conflicts
2019-07-23 20:18:36 -04:00