← Consul: discovery, mesh, and operations
04 / 7 · 40 MIN

Mesh, identity, and intentions

Apply authorization on the actual service-request path.

Concept and mechanism

Service mesh uses proxies to manage workload traffic. mTLS establishes identity and protects transport on the configured path; intentions define permitted relationships. A valid certificate does not authorize every call. Identify source and destination: allowing frontend to pricing does not equal the reverse direction. Set default policy explicitly and validate missing rules, permission, and denial. For HTTP method or path decisions, use L7 permissions with suitable protocol configuration. An L4 rule permitting a connection does not become a GET filter simply because the application uses HTTP. Request normalization and actual proxy behavior also deserve review when control depends on paths.

Guided application

In a fictional pilot, the proxy test is denied while the direct port responds. The proxy policy can be correct while the design remains incomplete. Restrict listeners and network paths so relevant communication traverses enforcement. Loopback helps on a host, but local processes without isolation may still reach the service; the trust model must reflect that. Acceptance should include authorized and denied access plus direct-path attempts. Record observed identity, destination, and effective rule. Avoid distributing broader credentials to hide configuration failures and do not declare an entire network protected from one successful request.

IN PRACTICE

Proxy-enforced deny does not prove control over a port reachable outside it.

Common pitfalls

Certificate as universal permission; reversed direction; testing only the intended path.

Related topics: Discovery, architecture, and quorum · Deployment and bootstrap · Registration, health checks, and DNS

Take this idea with you

Demonstrate identity, authorization, and absence of bypass within accepted scope.

Create account

Reference: Service intentions and L7 permissions · Historical Consul Associate (003), retired 2026-07-15; technical references inspected 2026-09-30