Skip to Content
Consul: Up and Running
book

Consul: Up and Running

by Luke Kysow
June 2022
Intermediate to advanced
260 pages
5h 34m
English
O'Reilly Media, Inc.
Content preview from Consul: Up and Running

Chapter 5. Ingress Gateways

Consul service mesh is secure by default. This means that Consul requires all requests to be authorized. Chapter 6 covers authorization in detail, but the long and short of it is that user-facing services can’t be accessed directly. Instead, they must be accessed through a gateway that sets the necessary authorization.

This is the purpose of a Consul ingress gateway. Ingress gateways take unauthorized requests from outside the service mesh and route the requests to services running securely inside the mesh.1

In this chapter, you’ll learn how ingress gateways work and how to deploy them on Kubernetes or VMs. You’ll then continue the exercise from Chapter 4 and expose the Birdwatcher frontend service via an ingress gateway.

Why You Need an Ingress Gateway

Most companies require some of their services to be accessed externally by users or API consumers. For example, an ecommerce company may have many internal services that only receive requests from other internal services, but they will also run public-facing services that are accessed by users. Figure 5-1 shows a typical architecture with a load balancer proxying traffic from the public internet directly through to the public-facing services.

Diagram of a typical architecture.
Figure 5-1. A typical architecture with a public-facing service

In this architecture, if the public-facing service is running in the service mesh, it will reject ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Kubernetes in Action

Kubernetes in Action

Marko Luksa
Istio: Up and Running

Istio: Up and Running

Lee Calcote, Zack Butcher
Microservices Security in Action

Microservices Security in Action

Prabath Siriwardena, Wajjakkara Kankanamge Anthony Nuwan Dias

Publisher Resources

ISBN: 9781098106133Errata Page