← Consul: discovery, mesh, and operations
05 / 7 · 45 MIN

Agent security and ACLs

Separate channel encryption, credentials, and resource permissions.

Concept and mechanism

Consul uses multiple channels with different responsibilities. Gossip maintains membership and events; RPC, API, and mesh communication need their corresponding controls. A gossip key does not turn an HTTP listener into HTTPS, and TLS alone does not limit authorized operations. Confirm effective configuration rather than assuming universal defaults across versions. For TLS, verify the chain, trusted CA, and expected identity; failure after renewal does not justify permanently disabling verification. Gossip rotation should install the new key, confirm distribution, promote it, and then remove the previous key. Raft majority is not sufficient evidence that a key reached every participant.

Guided application

ACL tokens connect callers to permissions granted through policies and identities. SecretID is the presented credential; AccessorID identifies the token for management operations. Distinguish descriptions from privilege: naming a management token reader does not restrict it. Automation updating apps/funds/ should receive the required scope and be tested outside it. The bootstrap token should not become every integration’s shared identity. Also protect configuration and data files through operating-system controls. If the API accepts remote registration of executable scripts, there is a host execution surface requiring its own controls. At RUN handover, document rotation, revocation, and recovery without placing secrets in logs.

IN PRACTICE

New key on six of seven agents: finish distribution before promotion.

Common pitfalls

TLS as authorization; gossip as HTTPS; AccessorID as credential; policy name as control.

Related topics: Discovery, architecture, and quorum · Deployment and bootstrap · Registration, health checks, and DNS

Take this idea with you

Verify each channel and grant only necessary operations per integration.

Create account

Reference: Consul security layers · Historical Consul Associate (003), retired 2026-07-15; technical references inspected 2026-09-30