Consul
Agents Configuration File Reference
This topic describes the parameters for configuring Consul agents. For information about how to start Consul agents, refer to Starting the Consul Agent.
Overview
You can create one or more files to configure the Consul agent on startup. We recommend grouping similar configurations into separate files, such as ACL parameters, to make it easier to manage configuration changes. Using external files may be easier than configuring agents on the command-line when Consul is being configured using a configuration management system.
The configuration files are formatted as HCL or JSON. JSON formatted configs are easily readable and editable by both humans and computers. JSON formatted configuration consists of a single JSON object with multiple configuration keys specified within it.
Example Configuration File
datacenter = "east-aws"
data_dir = "/opt/consul"
log_level = "INFO"
node_name = "foobar"
server = true
watches = [
{
type = "checks"
handler = "/usr/bin/health-check-handler.sh"
}
]
telemetry {
statsite_address = "127.0.0.1:2180"
}
Time-to-live values
Consul uses the Go time package to parse all time-to-live (TTL) values used in Consul agent configuration files. Specify integer and float values as a string and include one or more of the following units of time:
Examples:
Refer to the formatting specification for additional information.
General parameters
addresses- This is a nested object that allows setting bind addresses. In Consul 1.0 and later these can be set to a space-separated list of addresses to bind to, or a [go-sockaddr] template that can potentially resolve to multiple addresses.http,httpsandgrpcall support binding to a Unix domain socket. A socket can be specified in the formunix:///path/to/socket. A new domain socket will be created at the given path. If the specified file path already exists, Consul will attempt to clear the file and create the domain socket in its place. The permissions of the socket file are tunable via theunix_socketsconfig construct.When running Consul agent commands against Unix socket interfaces, use the
-http-addrargument to specify the path to the socket. You can also place the desired values in theCONSUL_HTTP_ADDRenvironment variable.For TCP addresses, the environment variable value should be an IP address with the port. For example:
10.0.0.1:8500and not10.0.0.1. However, ports are set separately in theportsstructure when defining them in a configuration file.The following keys are valid:
alt_domainEquivalent to the-alt-domaincommand-line flagauditEnterprise - Added in Consul 1.8, the audit object allow users to enable auditing and configure a sink and filters for their audit logs. For more information, review the audit log tutorial.Example audit configuration
audit { enabled = true sink "My sink" { type = "file" format = "json" path = "data/audit/audit.json" delivery_guarantee = "best-effort" rotate_duration = "24h" rotate_max_files = 15 rotate_bytes = 25165824 } }The following sub-keys are available:
enabled- Controls whether Consul logs out each time a user performs an operation. ACLs must be enabled to use this feature. Defaults tofalse.sink- This object provides configuration for the destination to which Consul will log auditing events. Sink is an object containing keys to sink objects, where the key is the name of the sink.type- Type specifies what kind of sink this is. The following keys are valid:file- Currently only file sinks are available, they take the following keys.
format- Format specifies what format the events will be emitted with. The following keys are valid:json- Currently only json events are offered.
path- The directory and filename to write audit events to.delivery_guarantee- Specifies the rules governing how audit events are written. The following keys are valid:best-effort- Consul only supportsbest-effortevent delivery.
mode- The permissions to set on the audit log files.rotate_duration- Specifies the interval by which the system rotates to a new log file. At least one ofrotate_durationorrotate_bytesmust be configured to enable audit logging.rotate_max_files- Defines the limit that Consul should follow before it deletes old log files.rotate_bytes- Specifies how large an individual log file can grow before Consul rotates to a new file. At least one ofrotate_bytesorrotate_durationmust be configured to enable audit logging.
autopilotAdded in Consul 0.8, this object allows a number of sub-keys to be set which can configure operator-friendly settings for Consul servers. When these keys are provided as configuration, they will only be respected on bootstrapping. If they are not provided, the defaults will be used. In order to change the value of these options after bootstrapping, you will need to use the Consul Operator Autopilot command. For more information about Autopilot, review the Autopilot tutorial.The following sub-keys are available:
cleanup_dead_servers- This controls the automatic removal of dead server nodes periodically and whenever a new server is added to the cluster. Defaults totrue.last_contact_threshold- Controls the maximum amount of time a server can go without contact from the leader before being considered unhealthy. Must be a duration value such as10s. Defaults to200ms.max_trailing_logs- Controls the maximum number of log entries that a server can trail the leader by before being considered unhealthy. Defaults to 250.min_quorum- Sets the minimum number of servers necessary in a cluster. Autopilot will stop pruning dead servers when this minimum is reached. There is no default.server_stabilization_time- Controls the minimum amount of time a server must be stable in the 'healthy' state before being added to the cluster. Only takes effect if all servers are running Raft protocol version 3 or higher. Must be a duration value such as30s. Defaults to10s.redundancy_zone_tagEnterprise - This controls thenode_metakey to use when Autopilot is separating servers into zones for redundancy. Only one server in each zone can be a voting member at one time. If left blank (the default), this feature will be disabled.disable_upgrade_migrationEnterprise - If set totrue, this setting will disable Autopilot's upgrade migration strategy in Consul Enterprise of waiting until enough newer-versioned servers have been added to the cluster before promoting any of them to voters. Defaults tofalse.upgrade_version_tagEnterprise - The node_meta tag to use for version info when performing upgrade migrations. If this is not set, the Consul version will be used.
auto_configThis object allows setting options for theauto_configfeature.The following sub-keys are available:
enabled(Defaults tofalse) This option enablesauto_configon a client agent. When starting up but before joining the cluster, the client agent will make an RPC to the configured server addresses to request configuration settings, such as itsagentACL token, TLS certificates, Gossip encryption key as well as other configuration settings. These configurations get merged in as defaults with any user-supplied configuration on the client agent able to override them. The initial RPC uses a JWT specified with eitherintro_token,intro_token_fileor theCONSUL_INTRO_TOKENenvironment variable to authorize the request. How the JWT token is verified is controlled by theauto_config.authorizerobject available for use on Consul servers. Enabling this option also enables service mesh because it is vital forauto_config, more specifically the service mesh CA and certificates infrastructure.Warning: Enabling
auto_configconflicts with theauto_encrypt.tlsfeature. Only one option may be specified.intro_token(Defaults to"") This specifies the JWT to use for the initialauto_configRPC to the Consul servers. This can be overridden with theCONSUL_INTRO_TOKENenvironment variableintro_token_file(Defaults to"") This specifies a file containing the JWT to use for the initialauto_configRPC to the Consul servers. This token from this file is only loaded if theintro_tokenconfiguration is unset as well as theCONSUL_INTRO_TOKENenvironment variableserver_addresses(Defaults to[]) This specifies the addresses of servers in the local datacenter to use for the initial RPC. These addresses support Cloud Auto-Joining and can optionally include a port to use when making the outbound connection. If no port is provided, theserver_portwill be used.dns_sans(Defaults to[]) This is a list of extra DNS SANs to request in the client agent's TLS certificate. ThelocalhostDNS SAN is always requested.ip_sans(Defaults to[]) This is a list of extra IP SANs to request in the client agent's TLS certificate. The::1and127.0.0.1IP SANs are always requested.authorizationThis object controls how a Consul server will authorizeauto_configrequests and in particular how to verify the JWT intro token.enabled(Defaults tofalse) This option enablesauto_configauthorization capabilities on the server.staticThis object controls configuring the static authorizer setup in the Consul configuration file. Almost all sub-keys are identical to those provided by the JWT Auth Method.jwt_validation_pub_keys(Defaults to[]) A list of PEM-encoded public keys to use to authenticate signatures locally.Exactly one of
jwks_urljwt_validation_pub_keys, oroidc_discovery_urlis required.oidc_discovery_url(Defaults to"") The OIDC Discovery URL, without any .well-known component (base path).Exactly one of
jwks_urljwt_validation_pub_keys, oroidc_discovery_urlis required.oidc_discovery_ca_cert(Defaults to"") PEM encoded CA cert for use by the TLS client used to talk with the OIDC Discovery URL. NOTE: Every line must end with a newline (\n). If not set, system certificates are used.jwks_url(Defaults to"") The JWKS URL to use to authenticate signatures.Exactly one of
jwks_urljwt_validation_pub_keys, oroidc_discovery_urlis required.jwks_ca_cert(Defaults to"") PEM encoded CA cert for use by the TLS client used to talk with the JWKS URL. NOTE: Every line must end with a newline (\n). If not set, system certificates are used.claim_mappings(Defaults to(map[string]string)Mappings of claims (key) that will be copied to a metadata field (value). Use this if the claim you are capturing is singular (such as an attribute).When mapped, the values can be any of a number, string, or boolean and will all be stringified when returned.
list_claim_mappings(Defaults to(map[string]string)) Mappings of claims (key) will be copied to a metadata field (value). Use this if the claim you are capturing is list-like (such as groups).When mapped, the values in each list can be any of a number, string, or boolean and will all be stringified when returned.
jwt_supported_algs(Defaults to["RS256"]) JWTSupportedAlgs is a list of supported signing algorithms.bound_audiences(Defaults to[]) List ofaudclaims that are valid for login; any match is sufficient.bound_issuer(Defaults to"") The value against which to match theissclaim in a JWT.expiration_leeway(Defaults to"0s") Duration of leeway when validating expiration of a token to account for clock skew. Defaults to 150s (2.5 minutes) if set to 0s and can be disabled if set to -1ns.not_before_leeway(Defaults to"0s") Duration of leeway when validating not before values of a token to account for clock skew. Defaults to 150s (2.5 minutes) if set to 0s and can be disabled if set to -1.clock_skew_leeway(Defaults to"0s") Duration of leeway when validating all claims to account for clock skew. Defaults to 60s (1 minute) if set to 0s and can be disabled if set to -1ns.claim_assertions(Defaults to[]) List of assertions about the mapped claims required to authorize the incoming RPC request. The syntax uses github.com/hashicorp/go-bexpr which is shared with the API filtering feature. For example, the following configurations when combined will ensure that the JWTsubmatches the node name requested by the client.Ensure that the JWT sub matches the node name requested by the client
claim_mappings { sub = "node_name" } claim_assertions = [ "value.node_name == \"${node}\"" ]The assertions are lightly templated using HIL syntax to interpolate some values from the RPC request. The list of variables that can be interpolated are:
auto_reload_configEquivalent to the-auto-reload-configcommand-line flag.bind_addrEquivalent to the-bindcommand-line flag.This parameter can be set to a go-sockaddr template that resolves to a single address. Special characters such as backslashes
\or double quotes"within a double quoted string value must be escaped with a backslash\. Some example templates:bind_addr = "{{ GetPrivateInterfaces | include \"network\" \"10.0.0.0/8\" | attr \"address\" }}"cacheconfiguration for client agents. When an?indexquery parameter is specified but '?cached' is not appended in a streaming backend call, Consul bypasses these configuration values. The configurable values are the following:entry_fetch_max_burstThe size of the token bucket used to recharge the rate-limit per cache entry. The default value is 2 and means that when cache has not been updated for a long time, 2 successive queries can be made as long as the rate-limit is not reached.entry_fetch_rateconfigures the rate-limit at which the cache may refresh a single entry. On a cluster with many changes/s, watching changes in the cache might put high pressure on the servers. This ensures the number of requests for a single cache entry will never go beyond this limit, even when a given service changes every 1/100s. Since this is a per cache entry limit, having a highly unstable service will only rate limit the watched on this service, but not the other services/entries. The value is strictly positive, expressed in queries per second as a float, 1 means 1 query per second, 0.1 mean 1 request every 10s maximum. The default value is "No limit" and should be tuned on large clusters to avoid performing too many RPCs on entries changing a lot.
check_update_intervalThis interval controls how often check output from checks in a steady state is synchronized with the server. By default, this is set to 5 minutes ("5m"). Many checks which are in a steady state produce slightly different output per run (timestamps, etc) which cause constant writes. This configuration allows deferring the sync of check output for a given interval to reduce write pressure. If a check ever changes state, the new state and associated output is synchronized immediately. To disable this behavior, set the value to "0s".client_addrEquivalent to the-clientcommand-line flag.config_entriesThis object allows setting options for centralized config entries.The following sub-keys are available:
bootstrapThis is a list of inlined config entries to insert into the state store when the Consul server gains leadership. This option is only applicable to server nodes. Each bootstrap entry will be created only if it does not exist. When reloading, any new entries that have been added to the configuration will be processed. See the configuration entry docs for more details about the contents of each entry.
datacenterEquivalent to the-datacentercommand-line flag.data_dirEquivalent to the-data-dircommand-line flag.default_intention_policyControls how service-to-service traffic is authorized in the absence of specific intentions. Can be set toallow,deny, or left empty to default toacl.default_policy.disable_anonymous_signatureDisables providing an anonymous signature for de-duplication with the update check. Seedisable_update_check.disable_http_unprintable_char_filterDefaults to false. Consul 1.0.3 fixed a potential security vulnerability where malicious users could craft KV keys with unprintable chars that would confuse operators using the CLI or UI into taking wrong actions. Users who had data written in older versions of Consul that did not have this restriction will be unable to delete those values by default in 1.0.3 or later. This setting enables those users to temporarily disable the filter such that delete operations can work on those keys again to get back to a healthy state. It is strongly recommended that this filter is not disabled permanently as it exposes the original security vulnerability.disable_remote_execDisables support for remote execution. When set to true, the agent will ignore any incoming remote exec requests. In versions of Consul prior to 0.8, this defaulted to false. In Consul 0.8 the default was changed to true, to make remote exec opt-in instead of opt-out.disable_update_checkDisables automatic checking for security bulletins and new version releases. This is disabled in Consul Enterprise.discard_check_outputDiscards the output of health checks before storing them. This reduces the number of writes to the Consul raft log in environments where health checks have volatile output like timestamps, process ids, ...discovery_max_stale- Enables stale requests for all service discovery HTTP endpoints. This is equivalent to themax_staleconfiguration for DNS requests. If this value is zero (default), all service discovery HTTP endpoints are forwarded to the leader. If this value is greater than zero, any Consul server can handle the service discovery request. If a Consul server is behind the leader by more thandiscovery_max_stale, the query will be re-evaluated on the leader to get more up-to-date results. Consul agents also add a newX-Consul-Effective-Consistencyresponse header which indicates if the agent did a stale read.discover-max-stalewas introduced in Consul 1.0.7 as a way for Consul operators to force stale requests from clients at the agent level, and defaults to zero which matches default consistency behavior in earlier Consul versions.enable_agent_tls_for_checksWhen set, uses a subset of the agent's TLS configuration (key_file,cert_file,ca_file,ca_path, andserver_name) to set up the client for HTTP or gRPC health checks. This allows services requiring 2-way TLS to be checked using the agent's credentials. This was added in Consul 1.0.1 and defaults to false.enable_central_service_configWhen set, the Consul agent will look for any centralized service configuration that match a registering service instance. If it finds any, the agent will merge the centralized defaults with the service instance configuration. This allows for things like service protocol or proxy configuration to be defined centrally and inherited by any affected service registrations. This defaults tofalsein versions of Consul prior to 1.9.0, and defaults totruein Consul 1.9.0 and later.enable_debug(boolean, default isfalse): When set totrue, enables Consul to report additional debugging information, including runtime profiling (pprof) data. This setting is only required for clusters without ACL enabled. If you change this setting, you must restart the agent for the change to take effect.enable_script_checksEquivalent to the-enable-script-checkscommand-line flag.ACLs must be enabled for agents and the
enable_script_checksoption must be set totrueto enable script checks in Consul 0.9.0 and later. See Registering and Querying Node Information for related information.Security Warning: Enabling script checks in some configurations may introduce a known remote execution vulnerability targeted by malware. We strongly recommend
enable_local_script_checksinstead. Refer to the following article for additional guidance: Protecting Consul from RCE Risk in Specific Configurations for more details.enable_local_script_checksEquivalent to the-enable-local-script-checkscommand-line flag.disable_keyring_file- Equivalent to the-disable-keyring-filecommand-line flag.disable_coordinates- Disables sending of network coordinates. When network coordinates are disabled thenearquery param will not work to sort the nodes, and theconsul rttcommand will not be able to provide round trip time between nodes.http_configThis object allows setting options for the HTTP API and UI.The following sub-keys are available:
block_endpointsThis object is a list of HTTP API endpoint prefixes to block on the agent, and defaults to an empty list, meaning all endpoints are enabled. Any endpoint that has a common prefix with one of the entries on this list will be blocked and will return a 403 response code when accessed. For example, to block all of the V1 ACL endpoints, set this to["/v1/acl"], which will block/v1/acl/create,/v1/acl/update, and the other ACL endpoints that begin with/v1/acl. This only works with API endpoints, not/uior/debug, those must be disabled with their respective configuration options. Any CLI commands that use disabled endpoints will no longer function as well. For more general access control, Consul's ACL system should be used, but this option is useful for removing access to HTTP API endpoints completely, or on specific agents. This is available in Consul 0.9.0 and later.response_headersThis object allows adding headers to the HTTP API and UI responses. For example, the following config can be used to enable CORS on the HTTP API endpoints:Enable CORS on the HTTP API endpoints
http_config { response_headers { Access-Control-Allow-Origin = "*" } }allow_write_http_fromThis object is a list of networks in CIDR notation (eg "127.0.0.0/8") that are allowed to call the agent write endpoints. It defaults to an empty list, which means all networks are allowed. This is used to make the agent read-only, except for select ip ranges. - To block write calls from anywhere, use[ "255.255.255.255/32" ]. - To only allow write calls from localhost, use[ "127.0.0.0/8" ]- To only allow specific IPs, use[ "10.0.0.1/32", "10.0.0.2/32" ]use_cacheDefaults to true. If disabled, the agent won't be using agent caching to answer the request. Even when the url parameter is provided.max_header_bytesThis setting controls the maximum number of bytes the consul http server will read parsing the request header's keys and values, including the request line. It does not limit the size of the request body. If zero, or negative, http.DefaultMaxHeaderBytes is used, which equates to 1 Megabyte.
leave_on_terminateIf enabled, when the agent receives a TERM signal, it will send aLeavemessage to the rest of the cluster and gracefully leave. The default behavior for this feature varies based on whether or not the agent is running as a client or a server (prior to Consul 0.7 the default value was unconditionally set tofalse). On agents in client-mode, this defaults totrueand for agents in server-mode, this defaults tofalse.license_pathEnterprise This specifies the path to a file that contains the Consul Enterprise license. Alternatively the license may also be specified in either theCONSUL_LICENSEorCONSUL_LICENSE_PATHenvironment variables. See the licensing documentation for more information about Consul Enterprise license management. Added in versions 1.10.0, 1.9.7 and 1.8.13. Prior to version 1.10.0 the value may be set for all agents to facilitate forwards compatibility with 1.10 but will only actually be used by client agents.limits: This block specifies various types of limits that the Consul server agent enforces.http_max_conns_per_client- Configures a limit of how many concurrent TCP connections a single client IP address is allowed to open to the agent's HTTP(S) server. This affects the HTTP(S) servers in both client and server agents. Default value is200.https_handshake_timeout- Configures the limit for how long the HTTPS server in both client and server agents will wait for a client to complete a TLS handshake. This should be kept conservative as it limits how many connections an unauthenticated attacker can open ifverify_incomingis being using to authenticate clients (strongly recommended in production). Default value is5s.request_limits- This object specifies configurations that limit the rate of RPC and gRPC requests on the Consul server. Limiting the rate of gRPC and RPC requests also limits HTTP requests to the Consul server.mode- String value that specifies an action to take if the rate of requests exceeds the limit. You can specify the following values:permissive: The server continues to allow requests and records an error in the logs.enforcing: The server stops accepting requests and records an error in the logs.disabled: Limits are not enforced or tracked. This is the default value formode.
read_rate- Integer value that specifies the number of read requests per second. Default is-1which represents infinity.write_rate- Integer value that specifies the number of write requests per second. Default is-1which represents infinity.
rpc_handshake_timeout- Configures the limit for how long servers will wait after a client TCP connection is established before they complete the connection handshake. When TLS is used, the same timeout applies to the TLS handshake separately from the initial protocol negotiation. All Consul clients should perform this immediately on establishing a new connection. This should be kept conservative as it limits how many connections an unauthenticated attacker can open ifverify_incomingis being using to authenticate clients (strongly recommended in production). Whenverify_incomingis true on servers, this limits how long the connection socket and associated goroutines will be held open before the client successfully authenticates. Default value is5s.rpc_client_timeout- Configures the limit for how long a client is allowed to read from an RPC connection. This is used to set an upper bound for calls to eventually terminate so that RPC connections are not held indefinitely. Blocking queries can override this timeout. Default is60s.rpc_max_conns_per_client- Configures a limit of how many concurrent TCP connections a single source IP address is allowed to open to a single server. It affects both clients connections and other server connections. In general Consul clients multiplex many RPC calls over a single TCP connection so this can typically be kept low. It needs to be more than one though since servers open at least one additional connection for raft RPC, possibly more for WAN federation when using network areas, and snapshot requests from clients run over a separate TCP conn. A reasonably low limit significantly reduces the ability of an unauthenticated attacker to consume unbounded resources by holding open many connections. You may need to increase this if WAN federated servers connect via proxies or NAT gateways or similar causing many legitimate connections from a single source IP. Default value is100which is designed to be extremely conservative to limit issues with certain deployment patterns. Most deployments can probably reduce this safely. 100 connections on modern server hardware should not cause a significant impact on resource usage from an unauthenticated attacker though.rpc_rate- Configures the RPC rate limiter on Consul clients by setting the maximum request rate that this agent is allowed to make for RPC requests to Consul servers, in requests per second. Defaults to infinite, which disables rate limiting.rpc_max_burst- The size of the token bucket used to recharge the RPC rate limiter on Consul clients. Defaults to 1000 tokens, and each token is good for a single RPC call to a Consul server. See https://en.wikipedia.org/wiki/Token_bucket for more details about how token bucket rate limiters operate.kv_max_value_size- (Advanced) Configures the maximum number of bytes for a kv request body to the/v1/kvendpoint. This limit defaults to raft's suggested max size (512KB). Note that tuning these improperly can cause Consul to fail in unexpected ways, it may potentially affect leadership stability and prevent timely heartbeat signals by increasing RPC IO duration. This option affects the txn endpoint too, but Consul 1.7.2 introducedtxn_max_req_lenwhich is the preferred way to set the limit for the txn endpoint. If both limits are set, the higher one takes precedence.txn_max_req_len- (Advanced) Configures the maximum number of bytes for a transaction request body to the/v1/txnendpoint. This limit defaults to raft's suggested max size (512KB). Note that tuning these improperly can cause Consul to fail in unexpected ways, it may potentially affect leadership stability and prevent timely heartbeat signals by increasing RPC IO duration.
default_query_timeEquivalent to the-default-query-timecommand-line flag.max_query_timeEquivalent to the-max-query-timecommand-line flag.peeringThis object allows setting options for cluster peering.The following sub-keys are available:
enabled(Defaults totrue) Controls whether cluster peering is enabled. When disabled, the UI won't show peering, all peering APIs will return an error, any peerings stored in Consul already will be ignored (but they will not be deleted), and all peering connections from other clusters will be rejected. This was added in Consul 1.13.0.
partitionEnterprise - This flag is used to set the name of the admin partition the agent belongs to. An agent can only join and communicate with other agents within its admin partition. Review the Admin Partitions documentation for more details. By default, this is an empty string, which is thedefaultadmin partition. This cannot be set on a server agent.performanceAvailable in Consul 0.7 and later, this is a nested object that allows tuning the performance of different subsystems in Consul. See the Server Performance documentation for more details. The following parameters are available:leave_drain_time- A duration that a server will dwell during a graceful leave in order to allow requests to be retried against other Consul servers. Under normal circumstances, this can prevent clients from experiencing "no leader" errors when performing a rolling update of the Consul servers. This was added in Consul 1.0. Must be a duration value such as 10s. Defaults to 5s.raft_multiplier- An integer multiplier used by Consul servers to scale key Raft timing parameters. Omitting this value or setting it to 0 uses default timing described below. Lower values are used to tighten timing and increase sensitivity while higher values relax timings and reduce sensitivity. Tuning this affects the time it takes Consul to detect leader failures and to perform leader elections, at the expense of requiring more network and CPU resources for better performance.By default, Consul will use a lower-performance timing that's suitable for minimal Consul servers, currently equivalent to setting this to a value of 5 (this default may be changed in future versions of Consul, depending if the target minimum server profile changes). Setting this to a value of 1 will configure Raft to its highest-performance mode, equivalent to the default timing of Consul prior to 0.7, and is recommended for production Consul servers.
See the note on last contact timing for more details on tuning this parameter. The maximum allowed value is 10.
rpc_hold_timeout- A duration that a client or server will retry internal RPC requests during leader elections. Under normal circumstances, this can prevent clients from experiencing "no leader" errors. This was added in Consul 1.0. Must be a duration value such as 10s. Defaults to 7s.grpc_keepalive_interval- A duration that determines the frequency that Consul servers send keep-alive messages to inactive gRPC clients. Configure this setting to modify how quickly Consul detects and removes improperly closed xDS or peering connections. Default is30s.grpc_keepalive_timeout- A duration that determines how long a Consul server waits for a reply to a keep-alive message. If the server does not receive a reply before the end of the duration, Consul flags the gRPC connection as unhealthy and forcibly removes it. Defaults to20s.
pid_fileEquivalent to the-pid-filecommand line flag.portsThis is a nested object that allows setting the bind ports for the following keys:dns- The DNS server, -1 to disable. Default 8600. TCP and UDP.http- The HTTP API, -1 to disable. Default 8500. TCP only.https- The HTTPS API, -1 to disable. Default -1 (disabled). We recommend using8501forhttpsby convention as some tooling will work automatically with this.grpc- The gRPC API, -1 to disable. Default -1 (disabled). We recommend using8502forgrpcas your conventional gRPC port number, as it allows some tools to work automatically. This parameter is set to8502by default when the agent runs in-devmode. Thegrpcport only supports plaintext traffic starting in Consul 1.14. Refer togrpc_tlsfor more information on configuring a TLS-enabled port.grpc_tls- The gRPC API with TLS connections, -1 to disable. gRPC_TLS is enabled by default on port 8503 for Consul servers. We recommend using8503forgrpc_tlsas your conventional gRPC port number, as it allows some tools to work automatically.grpc_tlsis always guaranteed to be encrypted. Bothgrpcandgrpc_tlscan be configured at the same time, but they may not utilize the same port number. This field was added in Consul 1.14.serf_lan- The Serf LAN port. Default 8301. TCP and UDP. Equivalent to the-serf-lan-portcommand line flag.serf_wan- The Serf WAN port. Default 8302. Equivalent to the-serf-wan-portcommand line flag. Set to -1 to disable. Note: this will disable WAN federation which is not recommended. Various catalog and WAN related endpoints will return errors or empty results. TCP and UDP.server- Server RPC address. Default 8300. TCP only.sidecar_min_port- Inclusive minimum port number to use for automatically assigned sidecar service registrations. Default 21000. Set to0to disable automatic port assignment.sidecar_max_port- Inclusive maximum port number to use for automatically assigned sidecar service registrations. Default 21255. Set to0to disable automatic port assignment.expose_min_port- Inclusive minimum port number to use for automatically assigned exposed check listeners. Default 21500. Set to0to disable automatic port assignment.expose_max_port- Inclusive maximum port number to use for automatically assigned exposed check listeners. Default 21755. Set to0to disable automatic port assignment.
primary_datacenter- This designates the datacenter which is authoritative for ACL information, intentions and is the root Certificate Authority for service mesh. It must be provided to enable ACLs. All servers and datacenters must agree on the primary datacenter. Setting it on the servers is all you need for cluster-level enforcement, but for the APIs to forward properly from the clients, it must be set on them too. In Consul 0.8 and later, this also enables agent-level enforcement of ACLs.primary_gatewaysEquivalent to the-primary-gatewaycommand-line flag. Takes a list of addresses to use as the mesh gateways for the primary datacenter when authoritative replicated catalog data is not present. Discovery happens everyprimary_gateways_intervaluntil at least one primary mesh gateway is discovered. This was added in Consul 1.8.0.primary_gateways_intervalTime to wait betweenprimary_gatewaysdiscovery attempts. Defaults to 30s. This was added in Consul 1.8.0.protocolEquivalent to the-protocolcommand-line flag.reapThis controls Consul's automatic reaping of child processes, which is useful if Consul is running as PID 1 in a Docker container. If this isn't specified, then Consul will automatically reap child processes if it detects it is running as PID 1. If this is set to true or false, then it controls reaping regardless of Consul's PID (forces reaping on or off, respectively). This option was removed in Consul 0.7.1. For later versions of Consul, you will need to reap processes using a wrapper, please see the Consul Docker image entry point script for an example. If you are using Docker 1.13.0 or later, you can use the new--initoption of thedocker runcommand and docker will enable an init process with PID 1 that reaps child processes for the container. More info on Docker docs.reconnect_timeoutThis controls how long it takes for a failed node to be completely removed from the cluster. This defaults to 72 hours and it is recommended that this is set to at least double the maximum expected recoverable outage time for a node or network partition. WARNING: Setting this time too low could cause Consul servers to be removed from quorum during an extended node failure or partition, which could complicate recovery of the cluster. The value is a time with a unit suffix, which can be "s", "m", "h" for seconds, minutes, or hours. The value must be >= 8 hours.reconnect_timeout_wanThis is the WAN equivalent of thereconnect_timeoutparameter, which controls how long it takes for a failed server to be completely removed from the WAN pool. This also defaults to 72 hours, and must be >= 8 hours.recursorsThis flag provides addresses of upstream DNS servers that are used to recursively resolve queries if they are not inside the service domain for Consul. For example, a node can use Consul directly as a DNS server, and if the record is outside of the "consul." domain, the query will be resolved upstream. As of Consul 1.0.1 recursors can be provided as IP addresses or as go-sockaddr templates. IP addresses are resolved in order, and duplicates are ignored.rpcconfiguration for Consul servers.enable_streamingdefaults to true. If set to false it will disable the gRPC subscribe endpoint on a Consul Server. All servers in all federated datacenters must have this enabled before any client can useuse_streaming_backend.
reportingEnterprise - This option allows options for HashiCorp reporting.segmentEnterprise - Equivalent to the-segmentcommand-line flag.Warning: The
segmentoption cannot be used with thepartitionoption.segmentsEnterprise - (Server agents only) This is a list of nested objects that specifies user-defined network segments, not including the<default>segment, which is created automatically. Refer to the network segments documentationfor additional information. for more details.name- The name of the segment. Must be a string between 1 and 64 characters in length.bind- The bind address to use for the segment's gossip layer. Defaults to the-bindvalue if not provided.port- The port to use for the segment's gossip layer (required).advertise- The advertise address to use for the segment's gossip layer. Defaults to the-advertisevalue if not provided.rpc_listener- If true, a separate RPC listener will be started on this segment's-bindaddress on the rpc port. Only valid if the segment's bind address differs from the-bindaddress. Defaults to false.
serverEquivalent to the-servercommand-line flag.server_rejoin_age_max- controls the allowed maximum age of a stale server attempting to rejoin a cluster. If the server has not ran during this period, it will refuse to start up again until an operator intervenes by manually deleting theserver_metadata.jsonfile located in the data dir. This is to protect clusters from instability caused by decommissioned servers accidentally being started again. Note: the default value is 168h (equal to 7d) and the minimum value is 6h.non_voting_server- This field is deprecated in Consul 1.9.1. See theread_replicafield instead.read_replica- Equivalent to the-read-replicacommand-line flag.session_ttl_minThe minimum allowed session TTL. This ensures sessions are not created with TTLs shorter than the specified limit. It is recommended to keep this limit at or above the default to encourage clients to send infrequent heartbeats. Defaults to 10s.skip_leave_on_interruptThis is similar toleave_on_terminatebut only affects interrupt handling. When Consul receives an interrupt signal (such as hitting Control-C in a terminal), Consul will gracefully leave the cluster. Setting this totruedisables that behavior. The default behavior for this feature varies based on whether or not the agent is running as a client or a server (prior to Consul 0.7 the default value was unconditionally set tofalse). On agents in client-mode, this defaults tofalseand for agents in server-mode, this defaults totrue(i.e. Ctrl-C on a server will keep the server in the cluster and therefore quorum, and Ctrl-C on a client will gracefully leave).translate_wan_addrsIf set to true, Consul will prefer a node's configured WAN address when servicing DNS and HTTP requests for a node in a remote datacenter. This allows the node to be reached within its own datacenter using its local address, and reached from other datacenters using its WAN address, which is useful in hybrid setups with mixed networks. This is disabled by default.Starting in Consul 0.7 and later, node addresses in responses to HTTP requests will also prefer a node's configured WAN address when querying for a node in a remote datacenter. An
X-Consul-Translate-Addressesheader will be present on all responses when translation is enabled to help clients know that the addresses may be translated. TheTaggedAddressesfield in responses also have alanaddress for clients that need knowledge of that address, regardless of translation.The following endpoints translate addresses:
unix_sockets- This allows tuning the ownership and permissions of the Unix domain socket files created by Consul. Domain sockets are only used if the HTTP address is configured with theunix://prefix.It is important to note that this option may have different effects on different operating systems. Linux generally observes socket file permissions while many BSD variants ignore permissions on the socket file itself. It is important to test this feature on your specific distribution. This feature is currently not functional on Windows hosts.
The following options are valid within this construct and apply globally to all sockets created by Consul:
use_streaming_backenddefaults to true. When enabled Consul client agents will use streaming rpc, instead of the traditional blocking queries, for endpoints which support streaming. All servers must haverpc.enable_streamingenabled before any client can enableuse_streaming_backend.watches- Watches is a list of watch specifications which allow an external process to be automatically invoked when a particular data view is updated. See the watch documentation for more detail. Watches can be modified when the configuration is reloaded.
ACL Parameters
acl- This object allows a number of sub-keys to be set which controls the ACL system. Configuring the ACL system within the ACL stanza was added in Consul 1.4.0The following sub-keys are available:
enabled- Enables ACLs.policy_ttl- Used to control Time-To-Live caching of ACL policies. By default, this is 30 seconds. This setting has a major performance impact: reducing it will cause more frequent refreshes while increasing it reduces the number of refreshes. However, because the caches are not actively invalidated, ACL policy may be stale up to the TTL value.role_ttl- Used to control Time-To-Live caching of ACL roles. By default, this is 30 seconds. This setting has a major performance impact: reducing it will cause more frequent refreshes while increasing it reduces the number of refreshes. However, because the caches are not actively invalidated, ACL role may be stale up to the TTL value.token_ttl- Used to control Time-To-Live caching of ACL tokens. By default, this is 30 seconds. This setting has a major performance impact: reducing it will cause more frequent refreshes while increasing it reduces the number of refreshes. However, because the caches are not actively invalidated, ACL token may be stale up to the TTL value.down_policy- Either "allow", "deny", "extend-cache" or "async-cache"; "extend-cache" is the default. In the case that a policy or token cannot be read from theprimary_datacenteror leader node, the down policy is applied. In "allow" mode, all actions are permitted, "deny" restricts all operations, and "extend-cache" allows any cached objects to be used, ignoring the expiry time of the cached entry. If the request uses an ACL that is not in the cache, "extend-cache" falls back to the behavior ofdefault_policy. The value "async-cache" acts the same way as "extend-cache" but performs updates asynchronously when ACL is present but its TTL is expired, thus, if latency is bad between the primary and secondary datacenters, latency of operations is not impacted.default_policy- Either "allow" or "deny"; defaults to "allow" but this will be changed in a future major release. The default policy controls the behavior of a token when there is no matching rule. In "allow" mode, ACLs are a denylist: any operation not specifically prohibited is allowed. In "deny" mode, ACLs are an allowlist: any operation not specifically allowed is blocked. Note: this will not take effect until you've enabled ACLs.enable_key_list_policy- Boolean value, defaults to false. When true, thelistpermission will be required on the prefix being recursively read from the KV store. Regardless of being enabled, the full set of KV entries under the prefix will be filtered to remove any entries that the request's ACL token does not grant at least read permissions. This option is only available in Consul 1.0 and newer.enable_token_replication- By default secondary Consul datacenters will perform replication of only ACL policies and roles. Setting this configuration will will enable ACL token replication and allow for the creation of both local tokens and auth methods in connected secondary datacenters.Warning: When enabling ACL token replication on the secondary datacenter, global tokens already present in the secondary datacenter will be lost. For production environments, consider configuring ACL replication in your initial datacenter bootstrapping process.
enable_token_persistence- Eithertrueorfalse. Whentruetokens set using the API will be persisted to disk and reloaded when an agent restarts.tokens- This object holds all of the configured ACL tokens for the agents usage.initial_management- This is available in Consul 1.11 and later. In prior versions, useacl.tokens.master.Only used for servers in the
primary_datacenter. This token will be created with management-level permissions if it does not exist. It allows operators to bootstrap the ACL system with a token Secret ID that is well-known.The
initial_managementtoken is only installed when a server acquires cluster leadership. If you would like to install or change it, set the new value forinitial_managementin the configuration for all servers. Once this is done, restart the current leader to force a leader election. If theinitial_managementtoken is not supplied, then the servers do not create an initial management token. When you provide a value, it should be a UUID. To maintain backwards compatibility and an upgrade path this restriction is not currently enforced but will be in a future major Consul release.masterRenamed in Consul 1.11 toacl.tokens.initial_management.default- When provided, this agent will use this token by default when making requests to the Consul servers instead of the anonymous token. Consul HTTP API requests can provide an alternate token in their authorization header to override thedefaultor anonymous token on a per-request basis, as described in HTTP API Authentication.agent- Used for clients and servers to perform internal operations. If this isn't specified, then thedefaultwill be used.This token must at least have write access to the node name it will register as in order to set any of the node-level information in the catalog such as metadata, or the node's tagged addresses.
agent_recovery- This is available in Consul 1.11 and later. In prior versions, useacl.tokens.agent_master.Used to access agent endpoints that require agent read or write privileges, or node read privileges, even if Consul servers aren't present to validate any tokens. This should only be used by operators during outages, regular ACL tokens should normally be used by applications.
agent_masterRenamed in Consul 1.11 toacl.tokens.agent_recovery.config_file_service_registration- Specifies the ACL token the agent uses to register services and checks from service and check definitions specified in configuration files or fragments passed to the agent using the-hclflag.If the
tokenfield is defined in the service or check definition, then that token is used to register the service or check instead. If theconfig_file_service_registrationtoken is not defined and if thetokenfield is not defined in the service or check definition, then the agent uses thedefaulttoken to register the service or check.This token needs write permission to register all services and checks defined in this agent's configuration. For example, if there are two service definitions in the agent's configuration files for services "A" and "B", then the token needs
service:writepermissions for both services "A" and "B" in order to successfully register both services. If the token is missingservice:writepermissions for service "B", the agent will successfully register service "A" and fail to register service "B". Failed registration requests are eventually retried as part of anti-entropy enforcement. If a registration request is failing due to missing permissions, the token for this agent can be updated with additional policy rules or theconfig_file_service_registrationtoken can be replaced using the Set Agent Token CLI command.dns- Specifies the token that agents use to request information needed to respond to DNS queries. If thednstoken is not set, thedefaulttoken is used instead. Because thedefaulttoken allows unauthenticated HTTP API access to list nodes and services, we strongly recommend using thednstoken. Create DNS tokens using the templated policy option to ensure that the token has the permissions needed to respond to all DNS queries.replication- Specifies the token that the agent uses to authorize secondary datacenters with the primary datacenter for replication operations. This token is required for servers outside theprimary_datacenterwhen ACLs are enabled. This token may be provided later using the agent token API on each server. This token must have at least "read" permissions on ACL data but if ACL token replication is enabled then it must have "write" permissions. This also enables service mesh data replication, for which the token will require both operator "write" and intention "read" permissions for replicating CA and Intention data.Warning: When enabling ACL token replication on the secondary datacenter, policies and roles already present in the secondary datacenter will be lost. For production environments, consider configuring ACL replication in your initial datacenter bootstrapping process.
managed_service_providerEnterprise - An array of ACL tokens used by Consul managed service providers for cluster operations.Example managed_service_provider configuration
managed_service_provider { accessor_id = "ed22003b-0832-4e48-ac65-31de64e5c2ff" secret_id = "cb6be010-bba8-4f30-a9ed-d347128dde17" }
acl_datacenter- This field is deprecated in Consul 1.4.0. See theprimary_datacenterfield instead.This designates the datacenter which is authoritative for ACL information. It must be provided to enable ACLs. All servers and datacenters must agree on the ACL datacenter. Setting it on the servers is all you need for cluster-level enforcement, but for the APIs to forward properly from the clients, it must be set on them too. In Consul 0.8 and later, this also enables agent-level enforcement of ACLs. Please review the ACL tutorial for more details.
acl_default_policy- Deprecated in Consul 1.4.0. See theacl.default_policyfield instead. Either "allow" or "deny"; defaults to "allow". The default policy controls the behavior of a token when there is no matching rule. In "allow" mode, ACLs are a denylist: any operation not specifically prohibited is allowed. In "deny" mode, ACLs are an allowlist: any operation not specifically allowed is blocked. Note: this will not take effect until you've setprimary_datacenterto enable ACL support.acl_down_policy- Deprecated in Consul 1.4.0. See theacl.down_policyfield instead. Either "allow", "deny", "extend-cache" or "async-cache"; "extend-cache" is the default. In the case that the policy for a token cannot be read from theprimary_datacenteror leader node, the down policy is applied. In "allow" mode, all actions are permitted, "deny" restricts all operations, and "extend-cache" allows any cached ACLs to be used, ignoring their TTL values. If a non-cached ACL is used, "extend-cache" acts like "deny". The value "async-cache" acts the same way as "extend-cache" but performs updates asynchronously when ACL is present but its TTL is expired, thus, if latency is bad between ACL authoritative and other datacenters, latency of operations is not impacted.acl_agent_master_token- Deprecated in Consul 1.4.0. See theacl.tokens.agent_masterfield instead. Used to access agent endpoints that require agent read or write privileges, or node read privileges, even if Consul servers aren't present to validate any tokens. This should only be used by operators during outages, regular ACL tokens should normally be used by applications. This was added in Consul 0.7.2 and is only used whenacl_enforce_version_8is set to true.acl_agent_token- Deprecated in Consul 1.4.0. See theacl.tokens.agentfield instead. Used for clients and servers to perform internal operations. If this isn't specified, then theacl_tokenwill be used. This was added in Consul 0.7.2.This token must at least have write access to the node name it will register as in order to set any of the node-level information in the catalog such as metadata, or the node's tagged addresses.
acl_enforce_version_8- Deprecated in Consul 1.4.0 and removed in 1.8.0. Used for clients and servers to determine if enforcement should occur for new ACL policies being previewed before Consul 0.8. Added in Consul 0.7.2, this defaults to false in versions of Consul prior to 0.8, and defaults to true in Consul 0.8 and later. This helps ease the transition to the new ACL features by allowing policies to be in place before enforcement begins.acl_master_token- Deprecated in Consul 1.4.0. See theacl.tokens.masterfield instead.acl_replication_token- Deprecated in Consul 1.4.0. See theacl.tokens.replicationfield instead. Only used for servers outside theprimary_datacenterrunning Consul 0.7 or later. When provided, this will enable ACL replication using this ACL replication using this token to retrieve and replicate the ACLs to the non-authoritative local datacenter. In Consul 0.9.1 and later you can enable ACL replication usingacl.enable_token_replicationand then set the token later using the agent token API on each server. If theacl_replication_tokenis set in the config, it will automatically setacl.enable_token_replicationto true for backward compatibility.If there's a partition or other outage affecting the authoritative datacenter, and the
acl_down_policyis set to "extend-cache", tokens not in the cache can be resolved during the outage using the replicated set of ACLs.acl_token- Deprecated in Consul 1.4.0. See theacl.tokens.defaultfield instead.acl_ttl- Deprecated in Consul 1.4.0. See theacl.token_ttlfield instead.Used to control Time-To-Live caching of ACLs. By default, this is 30 seconds. This setting has a major performance impact: reducing it will cause more frequent refreshes while increasing it reduces the number of refreshes. However, because the caches are not actively invalidated, ACL policy may be stale up to the TTL value.enable_acl_replicationDeprecated in Consul 1.11. Use theacl.enable_token_replicationfield instead. When set on a Consul server, enables ACL replication without having to set the replication token viaacl_replication_token. Instead, enable ACL replication and then introduce the token using the agent token API on each server. Seeacl_replication_tokenfor more details.Warning: When enabling ACL token replication on the secondary datacenter, policies and roles already present in the secondary datacenter will be lost. For production environments, consider configuring ACL replication in your initial datacenter bootstrapping process.
Advertise Address Parameters
advertise_addrEquivalent to the-advertisecommand-line flag.advertise_addr_ipv4This was added together withadvertise_addr_ipv6to support dual stack IPv4/IPv6 environments. Using this, both IPv4 and IPv6 addresses can be specified and requested during eg service discovery.advertise_addr_ipv6This was added together withadvertise_addr_ipv4to support dual stack IPv4/IPv6 environments. Using this, both IPv4 and IPv6 addresses can be specified and requested during eg service discovery.advertise_addr_wanEquivalent to the-advertise-wancommand-line flag.advertise_addr_wan_ipv4This was added together withadvertise_addr_wan_ipv6to support dual stack IPv4/IPv6 environments. Using this, both IPv4 and IPv6 addresses can be specified and requested during eg service discovery.advertise_addr_wan_ipv6This was added together withadvertise_addr_wan_ipv4to support dual stack IPv4/IPv6 environments. Using this, both IPv4 and IPv6 addresses can be specified and requested during eg service discovery.advertise_reconnect_timeoutThis is a per-agent setting of thereconnect_timeoutparameter. This agent will advertise to all other nodes in the cluster that after this timeout, the node may be completely removed from the cluster. This may only be set on client agents and if unset then other nodes will use the mainreconnect_timeoutsetting when determining when this node may be removed from the cluster.
Bootstrap Parameters
bootstrapEquivalent to the-bootstrapcommand-line flag.bootstrap_expectEquivalent to the-bootstrap-expectcommand-line flag.
Self-managed HCP Parameters
cloudThis object specifies settings for connecting self-managed clusters to HCP. This was added in Consul 1.14client_idThe OAuth2 client ID for authentication with HCP. This can be overridden using theHCP_CLIENT_IDenvironment variable.client_secretThe OAuth2 client secret for authentication with HCP. This can be overridden using theHCP_CLIENT_SECRETenvironment variable.resource_idThe HCP resource identifier. This can be overridden using theHCP_RESOURCE_IDenvironment variable.
Service Mesh Parameters
The noun connect is used throughout this documentation to refer to the connect subsystem that provides Consul's service mesh capabilities.
connectThis object allows setting options for the Connect feature.The following sub-keys are available:
enabled(Defaults totrue) Controls whether Connect features are enabled on this agent. Should be enabled on all servers in the cluster in order for service mesh to function properly. Will be set totrueautomatically ifauto_config.enabledorauto_encrypt.allow_tlsistrue.enable_mesh_gateway_wan_federation(Defaults tofalse) Controls whether cross-datacenter federation traffic between servers is funneled through mesh gateways. This was added in Consul 1.8.0.ca_providerControls which CA provider to use for the service mesh's CA. Currently only theaws-pca,consul, andvaultproviders are supported. This is only used when initially bootstrapping the cluster. For an existing cluster, use the Update CA Configuration Endpoint.ca_configAn object which allows setting different config options based on the CA provider chosen. This is only used when initially bootstrapping the cluster. For an existing cluster, use the Update CA Configuration Endpoint.The following providers are supported:
AWS ACM Private CA Provider (
ca_provider = "aws-pca")existing_arnThe Amazon Resource Name (ARN) of an existing private CA in your ACM account. If specified, Consul will attempt to use the existing CA to issue certificates.
Consul CA Provider (
ca_provider = "consul")private_keyThe PEM contents of the private key to use for the CA.root_certThe PEM contents of the root certificate to use for the CA.
Vault CA Provider (
ca_provider = "vault")addressThe address of the Vault server to connect to.tokenThe Vault token to use. In Consul 1.8.5 and later, if the token has the renewable flag set, Consul will attempt to renew its lease periodically after half the duration has expired.root_pki_pathThe path to use for the root CA pki backend in Vault. This can be an existing backend with a CA already configured, or a blank/unmounted backend in which case Consul will automatically mount/generate the CA. The Vault token given above must havesudoaccess to this backend, as well as permission to mount the backend at this path if it is not already mounted.intermediate_pki_pathThe path to use for the temporary intermediate CA pki backend in Vault. Consul will overwrite any data at this path in order to generate a temporary intermediate CA. The Vault token given above must havewriteaccess to this backend, as well as permission to mount the backend at this path if it is not already mounted.auth_methodVault auth method to use for logging in to Vault. Please see Vault Auth Methods for more information on how to configure individual auth methods. If auth method is provided, Consul will obtain a new token from Vault when the token can no longer be renewed.typeThe type of Vault auth method.mount_pathThe mount path of the auth method. If not provided the auth method type will be used as the mount path.paramsThe parameters to configure the auth method. Please see Vault Auth Methods for information on how to configure the auth method you wish to use. If using the Kubernetes auth method, Consul will read the service account token from the default mount path/var/run/secrets/kubernetes.io/serviceaccount/tokenif thejwtparameter is not provided.
Common CA Config Options
There are also a number of common configuration options supported by all providers:
csr_max_concurrentSets a limit on the number of Certificate Signing Requests that can be processed concurrently. Defaults to 0 (disabled). This is useful when you want to limit the number of CPU cores available to the server for certificate signing operations. For example, on an 8 core server, setting this to 1 will ensure that no more than one CPU core will be consumed when generating or rotating certificates. Setting this is recommended instead ofcsr_max_per_secondwhen you want to limit the number of cores consumed since it is simpler to reason about limiting CSR resources this way without artificially slowing down rotations. Added in 1.4.1.csr_max_per_secondSets a rate limit on the maximum number of Certificate Signing Requests (CSRs) the servers will accept. This is used to prevent CA rotation from causing unbounded CPU usage on servers. It defaults to 50 which is conservative – a 2017 Macbook can process about 100 per second using only ~40% of one CPU core – but sufficient for deployments up to ~1500 service instances before the time it takes to rotate is impacted. For larger deployments we recommend increasing this based on the expected number of server instances and server resources, or usecsr_max_concurrentinstead if servers have more than one CPU core. Setting this to zero disables rate limiting. Added in 1.4.1.leaf_cert_ttlSpecifies the upper bound on the expiry of a leaf certificate issued for a service. In most cases a new leaf certificate will be requested by a proxy before this limit is reached. This is also the effective limit on how long a server outage can last (with no leader) before network connections will start being rejected. Defaults to72h.You can specify a range from one hour (minimum) up to one year (maximum) using the following units:
h,m,s,ms,us(orµs),ns, or a combination of those units, e.g.1h5m.This value is also used when rotating out old root certificates from the cluster. When a root certificate has been inactive (rotated out) for more than twice the current
leaf_cert_ttl, it will be removed from the trusted list.intermediate_cert_ttlSpecifies the expiry for the intermediate certificates. Defaults to8760h(1 year). Must be at least 3 timesleaf_cert_ttl.root_cert_ttlSpecifies the expiry for a root certificate. Defaults to 10 years as87600h. This value, if provided, needs to be higher than the intermediate certificate TTL.This setting applies to all Consul CA providers.
For the Vault provider, this value is only used if the backend is not initialized at first.
This value is also applied on the
ca set-configcommand.private_key_typeThe type of key to generate for this CA. This is only used when the provider is generating a new key. Ifprivate_keyis set for the Consul provider, or existing root or intermediate PKI paths given for Vault then this will be ignored. Currently supported options areecorrsa. Default isec.It is required that all servers in a datacenter have the same config for the CA. It is recommended that servers in different datacenters use the same key type and size, although the built-in CA and Vault provider will both allow mixed CA key types.
Some CA providers (currently Vault) will not allow cross-signing a new CA certificate with a different key type. This means that if you migrate from an RSA-keyed Vault CA to an EC-keyed CA from any provider, you may have to proceed without cross-signing which risks temporary connection issues for workloads during the new certificate rollout. We highly recommend testing this outside of production to understand the impact and suggest sticking to same key type where possible.
Note that this only affects CA keys generated by the provider. Leaf certificate keys are always EC 256 regardless of the CA configuration.
private_key_bitsThe length of key to generate for this CA. This is only used when the provider is generating a new key. Ifprivate_keyis set for the Consul provider, or existing root or intermediate PKI paths given for Vault then this will be ignored.Currently supported values are:
private_key_type = ec(default):224, 256, 384, 521corresponding to the NIST P-* curves of the same name.private_key_type = rsa:2048, 4096
localityEnterprise: Specifies a map of configurations that set the region and zone of the Consul agent. When specified on server agents,localityapplies to all partitions on the server. When specified on clients,localityapplies to all services registered to the client. Configure this field to enable Consul to route traffic to the nearest physical service instance. This field is intended for use primarily with VM and Nomad workloads. Refer to Route traffic to local upstreams for additional information.region: String value that specifies the region where the Consul agent is running. Consul assigns this value to services registered to that agent. When service proxy regions match, Consul is able to prioritize routes between service instances in the same region over instances in other regions. You must specify values that are consistent with how regions are defined in your network, for exampleus-west-1for networks in AWS.zone: String value that specifies the availability zone where the Consul agent is running. Consul assigns this value to services registered to that agent. When service proxy regions match, Consul is able to prioritize routes between service instances in the same region and zone over instances in other regions and zones. When healthy service instances are available in multiple zones within the most-local region, Consul prioritizes instances that also match the downstream proxy'szone. You must specify values that are consistent with how zones are defined in your network, for exampleus-west-1afor networks in AWS.
DNS and Domain Parameters
dns_configThis object allows a number of sub-keys to be set which can tune how DNS queries are serviced. Refer to DNS caching for more information.The following sub-keys are available:
allow_stale- Enables a stale query for DNS information. This allows any Consul server, rather than only the leader, to service the request. The advantage of this is you get linear read scalability with Consul servers. In versions of Consul prior to 0.7, this defaulted to false, meaning all requests are serviced by the leader, providing stronger consistency but less throughput and higher latency. In Consul 0.7 and later, this defaults to true for better utilization of available servers.max_stale- Whenallow_staleis specified, this is used to limit how stale results are allowed to be. If a Consul server is behind the leader by more thanmax_stale, the query will be re-evaluated on the leader to get more up-to-date results. Prior to Consul 0.7.1 this defaulted to 5 seconds; in Consul 0.7.1 and later this defaults to 10 years ("87600h") which effectively allows DNS queries to be answered by any server, no matter how stale. In practice, servers are usually only milliseconds behind the leader, so this lets Consul continue serving requests in long outage scenarios where no leader can be elected.node_ttl- By default, this is "0s", so all node lookups are served with a 0 TTL value. DNS caching for node lookups can be enabled by setting this value. This should be specified with the "s" suffix for second or "m" for minute.service_ttl- This is a sub-object which allows for setting a TTL on service lookups with a per-service policy. The "*" wildcard service can be used when there is no specific policy available for a service. By default, all services are served with a 0 TTL value. DNS caching for service lookups can be enabled by setting this value.enable_truncate- If set to true, a UDP DNS query that would return more than 3 records, or more than would fit into a valid UDP response, will set the truncated flag, indicating to clients that they should re-query using TCP to get the full set of records.only_passing- If set to true, any nodes whose health checks are warning or critical will be excluded from DNS results. If false, the default, only nodes whose health checks are failing as critical will be excluded. For service lookups, the health checks of the node itself, as well as the service-specific checks are considered. For example, if a node has a health check that is critical then all services on that node will be excluded because they are also considered critical.recursor_strategy- If set tosequential, Consul will query recursors in the order listed in therecursorsoption. If set torandom, Consul will query an upstream DNS resolvers in a random order. Defaults tosequential.recursor_timeout- Timeout used by Consul when recursively querying an upstream DNS server. Seerecursorsfor more details. Default is 2s. This is available in Consul 0.7 and later.disable_compression- If set to true, DNS responses will not be compressed. Compression was added and enabled by default in Consul 0.7.udp_answer_limit- Limit the number of resource records contained in the answer section of a UDP-based DNS response. This parameter applies only to UDP DNS queries that are less than 512 bytes. This setting is deprecated and replaced in Consul 1.0.7 bya_record_limit.a_record_limit- Limit the number of resource records contained in the answer section of a A, AAAA or ANY DNS response (both TCP and UDP). When answering a question, Consul will use the complete list of matching hosts, shuffle the list randomly, and then limit the number of answers toa_record_limit(default: no limit). This limit does not apply to SRV records.In environments where RFC 3484 Section 6 Rule 9 is implemented and enforced (i.e. DNS answers are always sorted and therefore never random), clients may need to set this value to
1to preserve the expected randomized distribution behavior (note: RFC 3484 has been obsoleted by RFC 6724 and as a result it should be increasingly uncommon to need to change this value with modern resolvers).enable_additional_node_meta_txt- When set to true, Consul will add TXT records for Node metadata into the Additional section of the DNS responses for several query types such as SRV queries. When set to false those records are not emitted. This does not impact the behavior of those same TXT records when they would be added to the Answer section of the response like when querying with type TXT or ANY. This defaults to true.soaAllow to tune the setting set up in SOA. Non specified values fallback to their default values, all values are integers and expressed as seconds.The following settings are available:
expire- Configure SOA Expire duration in seconds, default value is 86400, ie: 24 hours.min_ttl- Configure SOA DNS minimum TTL. As explained in RFC-2308 this also controls negative cache TTL in most implementations. Default value is 0, ie: no minimum delay or negative TTL.refresh- Configure SOA Refresh duration in seconds, default value is3600, ie: 1 hour.retry- Configures the Retry duration expressed in seconds, default value is 600, ie: 10 minutes.
use_cache- When set to true, DNS resolution will use the agent cache described in agent caching. This setting affects all service and prepared queries DNS requests. Impliesallow_stalecache_max_age- When use_cache is enabled, the agent will attempt to re-fetch the result from the servers if the cached value is older than this duration. See: agent caching.Note that unlike the
max-ageHTTP header, a value of 0 for this field is equivalent to "no max age". To get a fresh value from the cache use a very small value of1nsinstead of 0.prefer_namespaceEnterprise Deprecated in Consul 1.11. Use the canonical DNS format for enterprise service lookups instead. - When set totrue, in a DNS query for a service, a single label between the domain and theservicelabel is treated as a namespace name instead of a datacenter. When set tofalse, the default, the behavior is the same as non-Enterprise versions and treats the single label as the datacenter.
domainEquivalent to the-domaincommand-line flag.
Encryption Parameters
auto_encryptThis object allows setting options for theauto_encryptfeature.The following sub-keys are available:
allow_tls(Defaults tofalse) This option enablesauto_encrypton the servers and allows them to automatically distribute certificates from the service mesh CA to the clients. If enabled, the server can accept incoming connections from both the built-in CA and the service mesh CA, as well as their certificates. Note, the server will only present the built-in CA and certificate, which the client can verify using the CA it received fromauto_encryptendpoint. If disabled, a client configured withauto_encrypt.tlswill be unable to start.tls(Defaults tofalse) Allows the client to request the service mesh CA and certificates from the servers, for encrypting RPC communication. The client will make the request to any servers listed in the-retry-joinoption. This requires that every server to haveauto_encrypt.allow_tlsenabled. When bothauto_encryptoptions are used, it allows clients to receive certificates that are generated on the servers. If the-server-portis not the default one, it has to be provided to the client as well. Usually this is discovered through LAN gossip, butauto_encryptprovision happens before the information can be distributed through gossip. The most secureauto_encryptsetup is when the client is provided with the built-in CA,verify_server_hostnameis turned on, and when an ACL token withnode.writepermissions is setup. It is also possible to useauto_encryptwith a CA and ACL, but withoutverify_server_hostname, or only with a ACL enabled, or only with CA andverify_server_hostname, or only with a CA, or finally without a CA and without ACL enabled. In any case, the communication to theauto_encryptendpoint is always TLS encrypted.Warning: Enabling
auto_encrypt.tlsconflicts with theauto_configfeature. Only one option may be specified.dns_san(Defaults to[]) When this option is being used, the certificates requested byauto_encryptfrom the server have thesedns_sanset as DNS SAN.ip_san(Defaults to[]) When this option is being used, the certificates requested byauto_encryptfrom the server have theseip_sanset as IP SAN.
encryptEquivalent to the-encryptcommand-line flag.encrypt_verify_incoming- This is an optional parameter that can be used to disable enforcing encryption for incoming gossip in order to upshift from unencrypted to encrypted gossip on a running cluster. See this section for more information. Defaults to true.encrypt_verify_outgoing- This is an optional parameter that can be used to disable enforcing encryption for outgoing gossip in order to upshift from unencrypted to encrypted gossip on a running cluster. See this section for more information. Defaults to true.
Gossip Parameters
gossip_lan- (Advanced) This object contains a number of sub-keys which can be set to tune the LAN gossip communications. These are only provided for users running especially large clusters that need fine tuning and are prepared to spend significant effort correctly tuning them for their environment and workload. Tuning these improperly can cause Consul to fail in unexpected ways. The default values are appropriate in almost all deployments.gossip_nodes- The number of random nodes to send gossip messages to per gossip_interval. Increasing this number causes the gossip messages to propagate across the cluster more quickly at the expense of increased bandwidth. The default is 3.gossip_interval- The interval between sending messages that need to be gossiped that haven't been able to piggyback on probing messages. If this is set to zero, non-piggyback gossip is disabled. By lowering this value (more frequent) gossip messages are propagated across the cluster more quickly at the expense of increased bandwidth. The default is 200ms.probe_interval- The interval between random node probes. Setting this lower (more frequent) will cause the cluster to detect failed nodes more quickly at the expense of increased bandwidth usage. The default is 1s.probe_timeout- The timeout to wait for an ack from a probed node before assuming it is unhealthy. This should be at least the 99-percentile of RTT (round-trip time) on your network. The default is 500ms and is a conservative value suitable for almost all realistic deployments.retransmit_mult- The multiplier for the number of retransmissions that are attempted for messages broadcasted over gossip. The number of retransmits is scaled using this multiplier and the cluster size. The higher the multiplier, the more likely a failed broadcast is to converge at the expense of increased bandwidth. The default is 4.suspicion_mult- The multiplier for determining the time an inaccessible node is considered suspect before declaring it dead. The timeout is scaled with the cluster size and the probe_interval. This allows the timeout to scale properly with expected propagation delay with a larger cluster size. The higher the multiplier, the longer an inaccessible node is considered part of the cluster before declaring it dead, giving that suspect node more time to refute if it is indeed still alive. The default is 4.
gossip_wan- (Advanced) This object contains a number of sub-keys which can be set to tune the WAN gossip communications. These are only provided for users running especially large clusters that need fine tuning and are prepared to spend significant effort correctly tuning them for their environment and workload. Tuning these improperly can cause Consul to fail in unexpected ways. The default values are appropriate in almost all deployments.gossip_nodes- The number of random nodes to send gossip messages to per gossip_interval. Increasing this number causes the gossip messages to propagate across the cluster more quickly at the expense of increased bandwidth. The default is 4.gossip_interval- The interval between sending messages that need to be gossiped that haven't been able to piggyback on probing messages. If this is set to zero, non-piggyback gossip is disabled. By lowering this value (more frequent) gossip messages are propagated across the cluster more quickly at the expense of increased bandwidth. The default is 500ms.probe_interval- The interval between random node probes. Setting this lower (more frequent) will cause the cluster to detect failed nodes more quickly at the expense of increased bandwidth usage. The default is 5s.probe_timeout- The timeout to wait for an ack from a probed node before assuming it is unhealthy. This should be at least the 99-percentile of RTT (round-trip time) on your network. The default is 3s and is a conservative value suitable for almost all realistic deployments.retransmit_mult- The multiplier for the number of retransmissions that are attempted for messages broadcasted over gossip. The number of retransmits is scaled using this multiplier and the cluster size. The higher the multiplier, the more likely a failed broadcast is to converge at the expense of increased bandwidth. The default is 4.suspicion_mult- The multiplier for determining the time an inaccessible node is considered suspect before declaring it dead. The timeout is scaled with the cluster size and the probe_interval. This allows the timeout to scale properly with expected propagation delay with a larger cluster size. The higher the multiplier, the longer an inaccessible node is considered part of the cluster before declaring it dead, giving that suspect node more time to refute if it is indeed still alive. The default is 6.
Join Parameters
rejoin_after_leaveEquivalent to the-rejoincommand-line flag.retry_join- Equivalent to the-retry-joincommand-line flag.retry_intervalEquivalent to the-retry-intervalcommand-line flag.retry_max- Equivalent to the-retry-maxcommand-line flag.retry_join_wanEquivalent to the-retry-join-wancommand-line flag. Takes a list of addresses to attempt joining to WAN everyretry_interval_wanuntil at least one join works.retry_interval_wanEquivalent to the-retry-interval-wancommand-line flag.start_joinDeprecated in Consul 1.15. Use theretry_joinfield instead. This field will be removed in a future version of Consul. This field is an alias ofretry_join.start_join_wanDeprecated in Consul 1.15. Use theretry_join_wanfield instead. This field will be removed in a future version of Consul. This field is an alias ofretry_join_wan.
Log Parameters
log_fileEquivalent to the-log-filecommand-line flag.log_rotate_durationEquivalent to the-log-rotate-durationcommand-line flag.log_rotate_bytesEquivalent to the-log-rotate-bytescommand-line flag.log_rotate_max_filesEquivalent to the-log-rotate-max-filescommand-line flag.log_levelEquivalent to the-log-levelcommand-line flag.log_jsonEquivalent to the-log-jsoncommand-line flag.enable_syslogEquivalent to the-syslogcommand-line flag.syslog_facilityWhenenable_syslogis provided, this controls to which facility messages are sent. By default,LOCAL0will be used.
Node Parameters
node_idEquivalent to the-node-idcommand-line flag.node_nameEquivalent to the-nodecommand-line flag.node_metaAvailable in Consul 0.7.3 and later, This object allows associating arbitrary metadata key/value pairs with the local node, which can then be used for filtering results from certain catalog endpoints. See the-node-metacommand-line flag for more information.Example node_meta configuration
node_meta { instance_type = "t2.medium" }disable_host_node_idEquivalent to the-disable-host-node-idcommand-line flag.
Raft Parameters
raft_boltdbThese fields are deprecated in Consul v1.15.0. Useraft_logstoreinstead. This is a nested object that allows configuring options for Raft's BoltDB-based log store.NoFreelistSyncThis field is deprecated in Consul v1.15.0. Use theraft_logstore.boltdb.no_freelist_syncfield instead. Setting this totruedisables syncing the BoltDB freelist to disk within the raft.db file. Not syncing the freelist to disk reduces disk IO required for write operations at the expense of potentially increasing start up time due to needing to scan the db to discover where the free space resides within the file.
raft_logstoreThis is a nested object that allows configuring options for Raft's LogStore component which is used to persist logs and crucial Raft state on disk during writes. This was added in Consul v1.15.0.backendSpecifies which storage engine to use to persist logs. Valid options areboltdborwal. Default isboltdb. Thewaloption specifies an experimental backend that should be used with caution. Refer to Experimental WAL LogStore backend for more information.disable_log_cacheDisables the in-memory cache for recent logs. We recommend using it for performance testing purposes, as no significant improvement has been measured when the cache is disabled. While the in-memory log cache theoretically prevents disk reads for recent logs, recent logs are also stored in the OS page cache, which does not slow either theboltdborwalbackend's ability to read them.verificationThis is a nested object that allows configuring the online verification of the LogStore. Verification provides additional assurances that LogStore backends are correctly storing data. It imposes low overhead on servers and is safe to run in production. It is most useful when evaluating a new backend implementation.Verification must be enabled on the leader to have any effect and can be used with any backend. When enabled, the leader periodically writes a special "checkpoint" log message that includes the checksums of all log entries written to Raft since the last checkpoint. Followers that have verification enabled run a background task for each checkpoint that reads all logs directly from the LogStore and then recomputes the checksum. A report is output as an INFO level log for each checkpoint.
Checksum failure should never happen and indicate unrecoverable corruption on that server. The only correct response is to stop the server, remove its data directory, and restart so it can be caught back up with a correct server again. Please report verification failures including details about your hardware and workload via GitHub issues. Refer to Experimental WAL LogStore backend for more information.
enabled- Set totrueto allow this Consul server to write and verify log verification checkpoints when elected leader.interval- Specifies the time interval between checkpoints. There is no default value. You must configure theintervaland setenabledtotrueto correctly enable intervals. We recommend using an interval between30sand5m. The performance overhead is insignificant when the interval is set to5mor less.
boltdb- Object that configures options for Raft'sboltdbbackend. It has no effect if thebackendis notboltdb.no_freelist_sync- Set totrueto disable storing BoltDB's freelist to disk within theraft.dbfile. Disabling freelist syncs reduces the disk IO required for write operations, but could potentially increase start up time because Consul must scan the database to find free space within the file.
wal- Object that configures thewalbackend. Refer to Experimental WAL LogStore backend for more information.segment_size_mb- Integer value that represents the target size in MB for each segment file before rolling to a new segment. The default value is64and is suitable for most deployments. While a smaller value may use less disk space because you can reclaim space by deleting old segments sooner, the smaller segment that results may affect performance because safely rotating to a new file more frequently can impact tail latencies. Larger values are unlikely to improve performance significantly. We recommend using this configuration for performance testing purposes.
raft_protocolEquivalent to the-raft-protocolcommand-line flag.raft_snapshot_thresholdThis controls the minimum number of raft commit entries between snapshots that are saved to disk. This is a low-level parameter that should rarely need to be changed. Very busy clusters experiencing excessive disk IO may increase this value to reduce disk IO, and minimize the chances of all servers taking snapshots at the same time. Increasing this trades off disk IO for disk space since the log will grow much larger and the space in the raft.db file can't be reclaimed till the next snapshot. Servers may take longer to recover from crashes or failover if this is increased significantly as more logs will need to be replayed. In Consul 1.1.0 and later this defaults to 16384, and in prior versions it was set to 8192.Since Consul 1.10.0 this can be reloaded using
consul reloador sending the server aSIGHUPto allow tuning snapshot activity without a rolling restart in emergencies.raft_snapshot_intervalThis controls how often servers check if they need to save a snapshot to disk. This is a low-level parameter that should rarely need to be changed. Very busy clusters experiencing excessive disk IO may increase this value to reduce disk IO, and minimize the chances of all servers taking snapshots at the same time. Increasing this trades off disk IO for disk space since the log will grow much larger and the space in the raft.db file can't be reclaimed till the next snapshot. Servers may take longer to recover from crashes or failover if this is increased significantly as more logs will need to be replayed. In Consul 1.1.0 and later this defaults to30s, and in prior versions it was set to5s.Since Consul 1.10.0 this can be reloaded using
consul reloador sending the server aSIGHUPto allow tuning snapshot activity without a rolling restart in emergencies.raft_trailing_logs- This controls how many log entries are left in the log store on disk after a snapshot is made. This should only be adjusted when followers cannot catch up to the leader due to a very large snapshot size and high write throughput causing log truncation before an snapshot can be fully installed on a follower. If you need to use this to recover a cluster, consider reducing write throughput or the amount of data stored on Consul as it is likely under a load it is not designed to handle. The default value is 10000 which is suitable for all normal workloads. Added in Consul 1.5.3.Since Consul 1.10.0 this can be reloaded using
consul reloador sending the server aSIGHUPto allow recovery without downtime when followers can't keep up.
Serf Parameters
serf_lanEquivalent to the-serf-lan-bindcommand-line flag. This is an IP address, not to be confused withports.serf_lan.serf_lan_allowed_cidrsEquivalent to the-serf-lan-allowed-cidrscommand-line flag.serf_wanEquivalent to the-serf-wan-bindcommand-line flag.serf_wan_allowed_cidrsEquivalent to the-serf-wan-allowed-cidrscommand-line flag.
Telemetry Parameters
telemetryThis is a nested object that configures where Consul sends its runtime telemetry, and contains the following keys:circonus_api_tokenA valid API Token used to create/manage check. If provided, metric management is enabled.circonus_api_appA valid app name associated with the API token. By default, this is set to "consul".circonus_api_urlThe base URL to use for contacting the Circonus API. By default, this is set to "https://api.circonus.com/v2".circonus_submission_intervalThe interval at which metrics are submitted to Circonus. By default, this is set to "10s" (ten seconds).circonus_submission_urlThecheck.config.submission_urlfield, of a Check API object, from a previously created HTTPTrap check.circonus_check_idThe Check ID (not check bundle) from a previously created HTTPTrap check. The numeric portion of thecheck._cidfield in the Check API object.circonus_check_force_metric_activationForce activation of metrics which already exist and are not currently active. If check management is enabled, the default behavior is to add new metrics as they are encountered. If the metric already exists in the check, it will not be activated. This setting overrides that behavior. By default, this is set to false.circonus_check_instance_idUniquely identifies the metrics coming from this instance. It can be used to maintain metric continuity with transient or ephemeral instances as they move around within an infrastructure. By default, this is set to hostname:application name (e.g. "host123:consul").circonus_check_search_tagA special tag which, when coupled with the instance id, helps to narrow down the search results when neither a Submission URL or Check ID is provided. By default, this is set to service:application name (e.g. "service:consul").circonus_check_display_nameSpecifies a name to give a check when it is created. This name is displayed in the Circonus UI Checks list. Available in Consul 0.7.2 and later.circonus_check_tagsComma separated list of additional tags to add to a check when it is created. Available in Consul 0.7.2 and later.circonus_broker_idThe ID of a specific Circonus Broker to use when creating a new check. The numeric portion ofbroker._cidfield in a Broker API object. If metric management is enabled and neither a Submission URL nor Check ID is provided, an attempt will be made to search for an existing check using Instance ID and Search Tag. If one is not found, a new HTTPTrap check will be created. By default, this is not used and a random Enterprise Broker is selected, or the default Circonus Public Broker.circonus_broker_select_tagA special tag which will be used to select a Circonus Broker when a Broker ID is not provided. The best use of this is to as a hint for which broker should be used based on where this particular instance is running (e.g. a specific geo location or datacenter, dc:sfo). By default, this is left blank and not used.disable_hostnameSet totrueto stop prepending the machine's hostname to gauge-type metrics. Default isfalse.disable_per_tenancy_usage_metricsSet totrueto exclude tenancy labels from usage metrics. This significantly decreases CPU utilization in clusters with many admin partitions or namespaces.dogstatsd_addrThis provides the address of a DogStatsD instance in the formathost:port. DogStatsD is a protocol-compatible flavor of statsd, with the added ability to decorate metrics with tags and event information. If provided, Consul will send various telemetry information to that instance for aggregation. This can be used to capture runtime information.dogstatsd_tagsThis provides a list of global tags that will be added to all telemetry packets sent to DogStatsD. It is a list of strings, where each string looks like "my_tag_name:my_tag_value".enable_host_metricsThis enables reporting of host metrics about system resources, defaults to false.filter_defaultThis controls whether to allow metrics that have not been specified by the filter. Defaults totrue, which will allow all metrics when no filters are provided. When set tofalsewith no filters, no metrics will be sent.metrics_prefixThe prefix used while writing all telemetry data. By default, this is set to "consul". This was added in Consul 1.0. For previous versions of Consul, use the config optionstatsite_prefixin this same structure. This was renamed in Consul 1.0 since this prefix applied to all telemetry providers, not just statsite.prefix_filterThis is a list of filter rules to apply for allowing/blocking metrics by prefix in the following format:Example prefix_filter configuration
telemetry { prefix_filter = ["+consul.raft.apply", "-consul.http", "+consul.http.GET"] }A leading "+" will enable any metrics with the given prefix, and a leading "-" will block them. If there is overlap between two rules, the more specific rule will take precedence. Blocking will take priority if the same prefix is listed multiple times.
prometheus_retention_timeIf the value is greater than0s(the default), this enables Prometheus export of metrics. The duration can be expressed using the duration semantics and will aggregates all counters for the duration specified (it might have an impact on Consul's memory usage). A good value for this parameter is at least 2 times the interval of scrape of Prometheus, but you might also put a very high retention time such as a few days (for instance 744h to enable retention to 31 days). Fetching the metrics using prometheus can then be performed using the/v1/agent/metrics?format=prometheusendpoint. The format is compatible natively with prometheus. When running in this mode, it is recommended to also enable the optiondisable_hostnameto avoid having prefixed metrics with hostname. Consul does not use the default Prometheus path, so Prometheus must be configured as follows. Note that using?format=prometheusin the path won't work as?will be escaped, so it must be specified as a parameter.Example Prometheus configuration
metrics_path: '/v1/agent/metrics' params: format: ['prometheus']statsd_addressThis provides the address of a statsd instance in the formathost:port. If provided, Consul will send various telemetry information to that instance for aggregation. This can be used to capture runtime information. This sends UDP packets only and can be used with statsd or statsite.statsite_addressThis provides the address of a statsite instance in the formathost:port. If provided, Consul will stream various telemetry information to that instance for aggregation. This can be used to capture runtime information. This streams via TCP and can only be used with statsite.
UI Parameters
ui- This field is deprecated in Consul 1.9.0. See theui_config.enabledfield instead. Equivalent to the-uicommand-line flag.ui_config- This object allows a number of sub-keys to be set which controls the display or features available in the UI. Configuring the UI with this stanza was added in Consul 1.9.0.The following sub-keys are available:
enabled- This enables the service of the web UI from this agent. Boolean value, defaults to false. In-devmode this defaults to true. Replacesuifrom before 1.9.0. Equivalent to the-uicommand-line flag.dir- This specifies that the web UI should be served from an external dir rather than the build in one. This allows for customization or development. Replacesui_dirfrom before 1.9.0. Equivalent to the-ui-dircommand-line flag.content_path- This specifies the HTTP path that the web UI should be served from. Defaults to/ui/. Equivalent to the-ui-content-pathflag.metrics_provider- Specifies a named metrics provider implementation the UI should use to fetch service metrics. By default metrics are disabled. Consul 1.9.0 includes a built-in provider namedprometheusthat can be enabled explicitly here. It also requires themetrics_proxyto be configured below and direct queries to a Prometheus instance that has Envoy metrics for all services in the datacenter.metrics_provider_files- An optional array of absolute paths to javascript files on the Agent's disk which will be served as part of the UI. These files should contain metrics provider implementations and registration enabling UI metric queries to be customized or implemented for an alternative time-series backend.Security Note: These javascript files are included in the UI with no further validation or sand-boxing. By configuring them here the operator is fully trusting anyone able to write to them as well as the original authors not to include malicious code in the UI being served.
metrics_provider_options_json- This is an optional raw JSON object as a string which is passed to the provider implementation'sinitmethod at startup to allow arbitrary configuration to be passed through.metrics_proxy- This object configures an internal agent API endpoint that will proxy GET requests to a metrics backend to allow querying metrics data in the UI. This simplifies deployment where the metrics backend is not exposed externally to UI users' browsers. It may also be used to augment requests with API credentials to allow serving graphs to UI users without them needing individual access tokens for the metrics backend.Security Note: Exposing your metrics backend via Consul in this way should be carefully considered in production. As Consul doesn't understand the requests, it can't limit access to only specific resources. For example this might make it possible for a malicious user on the network to query for arbitrary metrics about any server or workload in your infrastructure, or overload the metrics infrastructure with queries. See Metrics Proxy Security for more details.
The following sub-keys are available:
base_url- This is required to enable the proxy. It should be set to the base URL that the Consul agent should proxy requests for metrics too. For example a value ofhttp://prometheus-serverwould target a Prometheus instance with local DNS name "prometheus-server" on port 80. This may include a path prefix which will then not be necessary in provider requests to the backend and the proxy will prevent any access to paths without that prefix on the backend.path_allowlist- This specifies the paths that may be proxies to when appended to thebase_url. It defaults to["/api/v1/query_range", "/api/v1/query"]which are the endpoints required for the built-in Prometheus provider. If a custom provider is used that requires the metrics proxy, the correct allowlist must be specified to enable proxying to necessary endpoints. See Path Allowlist for more information.add_headers- This is an optional list if headers to add to requests that are proxied to the metrics backend. It may be used to inject Authorization tokens within the agent without exposing those to UI users.Each item in the list is an object with the following keys:
dashboard_url_templates- This map specifies URL templates that may be used to render links to external dashboards in various contexts in the UI. It is a map with the name of the template as a key. The value is a string URL with optional placeholders.Each template may contain placeholders which will be substituted for the correct values in content when rendered in the UI. The placeholders available are listed for each template.
For more information and examples see UI Visualization
The following named templates are defined:
service- This is the URL to use when linking to the dashboard for a specific service. It is shown as part of the Topology Visualization.The placeholders available are:
{{Service.Name}}- Replaced with the current service's name.{{Service.Namespace}}- Replaced with the current service's namespace or empty if namespaces are not enabled.{{Service.Partition}}- Replaced with the current service's admin partition or empty if admin partitions are not enabled.{{Datacenter}}- Replaced with the current service's datacenter.
ui_dir- This field is deprecated in Consul 1.9.0. See theui_config.dirfield instead. Equivalent to the-ui-dircommand-line flag. This configuration key is not required as of Consul version 0.7.0 and later. Specifying this configuration key will enable the web UI. There is no need to specify both ui-dir and ui. Specifying both will result in an error.
TLS Configuration Reference
This section documents all of the configuration settings that apply to Agent TLS. Agent TLS is used by the HTTP API, internal RPC, and gRPC/xDS interfaces. Some of these settings may also be applied automatically by auto_config or auto_encrypt.
Security Note: The Certificate Authority (CA) configured on the internal RPC interface
(either explicitly by tls.internal_rpc or implicitly by tls.defaults) should be a private
CA, not a public one. We recommend using a dedicated CA which should not be used with any other
systems. Any certificate signed by the CA will be allowed to communicate with the cluster and a
specially crafted certificate signed by the CA can be used to gain full access to Consul.
tlsAdded in Consul 1.12, for previous versions see Deprecated Options.defaultsProvides default settings that will be applied to every interface unless explicitly overridden bytls.grpc,tls.https, ortls.internal_rpc.ca_fileThis provides a file path to a PEM-encoded certificate authority. The certificate authority is used to check the authenticity of client and server connections with the appropriateverify_incomingorverify_outgoingflags.ca_pathThis provides a path to a directory of PEM-encoded certificate authority files. These certificate authorities are used to check the authenticity of client and server connections with the appropriateverify_incomingorverify_outgoingflags.cert_fileThis provides a file path to a PEM-encoded certificate. The certificate is provided to clients or servers to verify the agent's authenticity. It must be provided along withkey_file.key_fileThis provides a the file path to a PEM-encoded private key. The key is used with the certificate to verify the agent's authenticity. This must be provided along withcert_file.tls_min_versionThis specifies the minimum supported version of TLS. The following values are accepted:verify_server_hostnameWhen set to true, Consul verifies the TLS certificate presented by the servers match the hostnameserver.<datacenter>.<domain>. By default this is false, and Consul does not verify the hostname of the certificate, only that it is signed by a trusted CA.WARNING: TLS 1.1 and lower are generally considered less secure and should not be used if possible.
The following values are also valid, but only when using the deprecated top-level
tls_min_versionconfig, and will be removed in a future release:A warning message will appear if a deprecated value is specified.
tls_cipher_suitesThis specifies the list of supported ciphersuites as a comma-separated-list. Applicable to TLS 1.2 and below only. The list of all ciphersuites supported by Consul is available in the TLS configuration source code.Note: The ordering of cipher suites will not be guaranteed from Consul 1.11 onwards. See this post for details.
verify_incoming- If set to true, Consul requires that all incoming connections make use of TLS and that the client provides a certificate signed by a Certificate Authority from theca_fileorca_path. By default, this is false, and Consul will not enforce the use of TLS or verify a client's authenticity.verify_outgoing- If set to true, Consul requires that all outgoing connections from this agent make use of TLS and that the server provides a certificate that is signed by a Certificate Authority from theca_fileorca_path. By default, this is false, and Consul will not make use of TLS for outgoing connections. This applies to clients and servers as both will make outgoing connections. This setting does not apply to the gRPC interface as Consul makes no outgoing connections on this interface. When set to true for the HTTPS interface, this parameter applies to watches, which operate by making HTTPS requests to the local agent.
grpcProvides settings for the gRPC/xDS interface. To enable the gRPC interface you must define a port viaports.grpc_tls.ca_fileOverridestls.defaults.ca_file.ca_pathOverridestls.defaults.ca_path.cert_fileOverridestls.defaults.cert_file.key_fileOverridestls.defaults.key_file.tls_min_versionOverridestls.defaults.tls_min_version.tls_cipher_suitesOverridestls.defaults.tls_cipher_suites.verify_incoming- Overridestls.defaults.verify_incoming.use_auto_cert- (Defaults tofalse) Enables or disables TLS on gRPC servers. Set totrueto allowauto_encryptTLS settings to apply to gRPC listeners. We recommend disabling TLS on gRPC servers if you are usingauto_encryptfor other TLS purposes, such as enabling HTTPS.
httpsProvides settings for the HTTPS interface. To enable the HTTPS interface you must define a port viaports.https.ca_fileOverridestls.defaults.ca_file.ca_pathOverridestls.defaults.ca_path.cert_fileOverridestls.defaults.cert_file.key_fileOverridestls.defaults.key_file.tls_min_versionOverridestls.defaults.tls_min_version.tls_cipher_suitesOverridestls.defaults.tls_cipher_suites.verify_incoming- Overridestls.defaults.verify_incoming.verify_outgoing- Overridestls.defaults.verify_outgoing.
internal_rpcProvides settings for the internal "server" RPC interface configured byports.server.ca_fileOverridestls.defaults.ca_file.ca_pathOverridestls.defaults.ca_path.cert_fileOverridestls.defaults.cert_file.key_fileOverridestls.defaults.key_file.tls_min_versionOverridestls.defaults.tls_min_version.tls_cipher_suitesOverridestls.defaults.tls_cipher_suites.verify_incoming- Overridestls.defaults.verify_incoming.Security Note:
verify_incomingmust be set to true to prevent anyone with access to the internal RPC port from gaining full access to the Consul cluster.verify_outgoingOverridestls.defaults.verify_outgoing.Security Note: Servers that specify
verify_outgoing = truewill always talk to other servers over TLS, but they still accept non-TLS connections to allow for a transition of all clients to TLS. Currently the only way to enforce that no client can communicate with a server unencrypted is to also enableverify_incomingwhich requires client certificates too.verify_server_hostnameOverrides tls.defaults.verify_server_hostname. When set to true, Consul verifies the TLS certificate presented by the servers match the hostnameserver.<datacenter>.<domain>. By default this is false, and Consul does not verify the hostname of the certificate, only that it is signed by a trusted CA.Security Note:
verify_server_hostnamemust be set to true to prevent a compromised client from gaining full read and write access to all cluster data including all ACL tokens and service mesh CA root keys.
server_nameWhen provided, this overrides thenode_namefor the TLS certificate. It can be used to ensure that the certificate name matches the hostname we declare.
Deprecated Options
The following options were deprecated in Consul 1.12, please use the
tls stanza instead.
ca_fileSee:tls.defaults.ca_file.ca_pathSee:tls.defaults.ca_path.tls_min_versionAdded in Consul 0.7.4. See:tls.defaults.tls_min_version.tls_cipher_suitesAdded in Consul 0.8.2. See:tls.defaults.tls_cipher_suites.tls_prefer_server_cipher_suitesAdded in Consul 0.8.2. This setting will be ignored (see this post for details).verify_server_hostnameSee:tls.internal_rpc.verify_server_hostname.
Example Configuration File, with TLS
Security Note: all three verify options should be set as true to enable
secure mTLS communication, enabling both encryption and authentication. Failing
to set verify_incoming or
verify_outgoing either in the
interface-specific stanza (e.g. tls.internal_rpc, tls.https) or in
tls.defaults will result in TLS not being enabled at all, even when specifying
a ca_file, cert_file,
and key_file.
See, especially, the use of the ports setting highlighted below.
Example configuration with TLS
datacenter = "east-aws"
data_dir = "/opt/consul"
log_level = "INFO"
node_name = "foobar"
server = true
addresses = {
https = "0.0.0.0"
}
ports {
https = 8501
}
tls {
defaults {
key_file = "/etc/pki/tls/private/my.key"
cert_file = "/etc/pki/tls/certs/my.crt"
ca_file = "/etc/pki/tls/certs/ca-bundle.crt"
verify_incoming = true
verify_outgoing = true
verify_server_hostname = true
}
}
Consul will not enable TLS for the HTTP or gRPC API unless the https port has
been assigned a port number > 0. We recommend using 8501 for https as this
default will automatically work with some tooling.
xDS Server Parameters
xds: This object allows you to configure the behavior of Consul's xDS protocol server.update_max_per_second: Specifies the number of proxy configuration updates across all connected xDS streams that are allowed per second. This configuration prevents updates to global resources, such as wildcard intentions, from consuming system resources at the expense of other processes, such as Raft and Gossip, which could cause general cluster instability.The default value is
250. It is based on a load test of 5,000 streams connected to a single server with two CPU cores.If necessary, you can lower or increase the limit without a rolling restart by using the
consul reloadcommand or by sending the server aSIGHUP.