Virtual Event
Join us for the next HashiConf Digital October 12-15, 2020 Register for Free

Day 1: Security and Network Operations

Introduction

»Security and networking

This learning collection is part of the Day 1 learning path, and will cover how to secure and set up networking for your first Consul datacenter. It assumes that you have already completed the Day 1: Deploying Your First Datacenter tutorial.

By following this collection, you will learn about:

»Gossip encryption

By the end of this tutorial, you will be able to configure gossip encryption on a your Consul datacenter. Gossip communication between all agents in the datacenter can be secured with a symmetric key.

Gossip Encryption

»Securing Agent Communication with TLS Encryption

By the end of the this tutorial, you will know how to generate certificates for your datacenter. This tutorial will cover how to create a Certificate Authority (CA), and how to generate server certificates and client certificates. Encrypting both incoming and outgoing communication is crucial for securing your datacenter.

Securing Agent Communication with TLS Encryption

»Securing Consul with ACLs

By the end of this tutorial, you will have ACLs configured on the Consul agents, servers and clients. For each step, you will be able to recognize if the process is not properly executed. Optionally, you can also configure the anonymous token and token for the UI.

Securing Consul with ACLs

»Managing ACL policies

By the end of this tutorial, you will be able to discover the minimum privileges required for any datacenter operation.

Managing ACL Policies

»DNS caching

By the end of this tutorial, you will be able to update the parameters for tuning stale reads, negative response caching, and TTL in the agent's configuration file.

DNS Caching

»Forwarding DNS

By the end of this tutorial, you will be able to setup DNS forwarding from BIND, dnsmasq, Unbound, systemd-resolved, iptables, or macOS. You will also be able to test and troubleshoot the DNS service after the initial setup.

Forwarding DNS

»Datacenter federation with WAN gossip

By the end of this tutorial, you will connect two datacenters using WAN gossip. This tutorial includes two methods for connecting the Consul servers, on the command line or in the agent's configuration file.

Datacenter Federation