Go to file
Michael Zalimeni 4cae008559
Disable remote proxy patching except AWS Lambda (#17415)
To avoid unintended tampering with remote downstreams via service
config, refactor BasicEnvoyExtender and RuntimeConfig to disallow
typical Envoy extensions from being applied to non-local proxies.

Continue to allow this behavior for AWS Lambda and the read-only
Validate builtin extensions.

Addresses CVE-2023-2816.
2023-05-23 11:55:06 +00:00
.changelog Disable remote proxy patching except AWS Lambda (#17415) 2023-05-23 11:55:06 +00:00
.github consul-container test: no splitting and on single runner (#17394) 2023-05-17 14:57:12 -04:00
.release
acl
agent Disable remote proxy patching except AWS Lambda (#17415) 2023-05-23 11:55:06 +00:00
api Disable remote proxy patching except AWS Lambda (#17415) 2023-05-23 11:55:06 +00:00
bench
build-support
command Add ACLs Enabled field to consul agent startup status message (#17086) 2023-05-16 13:47:02 -05:00
connect
contributing
docs
envoyextensions Disable remote proxy patching except AWS Lambda (#17415) 2023-05-23 11:55:06 +00:00
grafana
internal Add the workload health controller (#17215) 2023-05-19 13:53:29 -04:00
ipaddr
lib
logging
proto prototest: fix early return condition in AssertElementsMatch (#17416) 2023-05-22 13:49:50 -05:00
proto-public
sdk
sentinel
service_os
snapshot
test xds: generate endpoints directly from API gateway snapshot (#17390) 2023-05-19 18:50:59 +00:00
testrpc
tlsutil
tools/internal-grpc-proxy
troubleshoot Disable remote proxy patching except AWS Lambda (#17415) 2023-05-23 11:55:06 +00:00
types
ui
version
website updates to links in services overview description paragraph (#17406) 2023-05-18 09:51:29 -07:00
.copywrite.hcl
.dockerignore
.gitattributes
.gitignore
.golangci.yml
CHANGELOG.md Add changelog entries for Consul 1.13.8 + 1.14.7 (#17399) 2023-05-17 18:28:29 -04:00
Dockerfile
GNUmakefile
LICENSE
NOTICE.md
README.md
buf.work.yaml
fixup_acl_move.sh
go.mod
go.sum
main.go

README.md

Consul logo Consul

Docker Pulls Go Report Card

Consul is a distributed, highly available, and data center aware solution to connect and configure applications across dynamic, distributed infrastructure.

Consul provides several key features:

  • Multi-Datacenter - Consul is built to be datacenter aware, and can support any number of regions without complex configuration.

  • Service Mesh - Consul Service Mesh enables secure service-to-service communication with automatic TLS encryption and identity-based authorization. Applications can use sidecar proxies in a service mesh configuration to establish TLS connections for inbound and outbound connections with Transparent Proxy.

  • Service Discovery - Consul makes it simple for services to register themselves and to discover other services via a DNS or HTTP interface. External services such as SaaS providers can be registered as well.

  • Health Checking - Health Checking enables Consul to quickly alert operators about any issues in a cluster. The integration with service discovery prevents routing traffic to unhealthy hosts and enables service level circuit breakers.

  • Key/Value Storage - A flexible key/value store enables storing dynamic configuration, feature flagging, coordination, leader election and more. The simple HTTP API makes it easy to use anywhere.

Consul runs on Linux, macOS, FreeBSD, Solaris, and Windows and includes an optional browser based UI. A commercial version called Consul Enterprise is also available.

Please note: We take Consul's security and our users' trust very seriously. If you believe you have found a security issue in Consul, please responsibly disclose by contacting us at security@hashicorp.com.

Quick Start

A few quick start guides are available on the Consul website:

Documentation

Full, comprehensive documentation is available on the Consul website: https://consul.io/docs

Contributing

Thank you for your interest in contributing! Please refer to CONTRIBUTING.md for guidance. For contributions specifically to the browser based UI, please refer to the UI's README.md for guidance.