Skip to main content
See All Integrations

HashiCorp Consul

Protect the HashiCorp Consul user interface and HTTP API, with separate DNS routes when required.

Separate standard routes by protocol

Categories
Cloud Native Tools, Upstream Applications

Overview

HashiCorp Consul provides service discovery, configuration, and service networking. Its user interface and HTTP API normally use ports 8500 or 8501. Its DNS interface uses port 8600 over UDP and TCP. Gossip and server RPC are internal cluster traffic.

HashiCorp Consul can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to HashiCorp Consul. HashiCorp Consul remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.

Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.

Use an HTTPS route for the interface and API. Add separate UDP and TCP routes only when users need DNS access. Confirm the exact Consul ports in the deployment.

Example

Operators use a Pomerium HTTPS route for the Consul user interface. A separate DNS route is added only for approved users who need the Consul DNS interface. Consul ACLs remain active.

Considerations

  • Do not route Consul gossip or server RPC as user traffic.
  • Preserve Consul ACLs and TLS. API automation needs noninteractive credentials.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect access to the HashiCorp Nomad user interface and HTTP API as upstream applications.

  • Protect access to the HashiCorp Vault user interface and HTTP API as upstream applications.

  • Protect access to private DNS services through separate Pomerium UDP and TCP routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo