Client Auto-Config
- Dominant language
- Go
- Stars
- 17k
- Forks
- 2.1k
- Avg merge
- 1d 9h
- Merged PRs (30d)
- 105
Description
### Proposal
Consul has an [Auto-Config feature](https://www.hashicorp.com/blog/automate-consul-agent-security-with-auto-config) which allows Consul clients to automatically configure TLS without having to manually manage certs and config files.
In addition to TLS config, other [Nomad client config](https://developer.hashicorp.com/nomad/docs/configuration) values could be sent to clients via some centralized way.
More research and exploration is needed, but opening this ticket now in case people have ideas, feedback on how Consul's auto config is working, or any other thoughts.
### Use-cases
Remove complexity from the process of security Nomad:
- Reduce chance of churning during Nomad set up process
- Reduce chances of an insecure Nomad cluster going to prod
- Reduce necessity of configuration management tooling for client config
### Feedback
I am actively looking to discuss this with potential users, so if you would like to chat about client config, pleas book a 30 minute slot using [this link](https://calendly.com/mnomitch/roadmap-chat) or send an email to mnomitch@hashicorp.com
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are identified. Start by reviewing the linked Consul Auto-Config feature and Nomad client configuration documentation, then use the stated feedback channels to define a concrete scope; done requires an agreed design and implementation plan.
Written by the indexing model from the issue text.
Assessment
- Domain
- infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100