Skip to content
/ consul Public
  • Notifications You must be signed in to change notification settings
  • Fork 4.4k
  • Star 28k
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Sign up for GitHub

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Jump to bottom

Unexpected response code: 403 (rpc error making call: Permission denied) - Consul 1.4 #5196

Closed
marcuschaney opened this issue Jan 7, 2019 · 2 comments
Closed

Unexpected response code: 403 (rpc error making call: Permission denied) - Consul 1.4 #5196

marcuschaney opened this issue Jan 7, 2019 · 2 comments

Comments

@marcuschaney
Copy link

marcuschaney commented Jan 7, 2019

Hello All,

I am currently trying to deploy a new Consul cluster running version 1.4, and I've encountered an issue following the configuration guide.

Steps below:

$ consul acl bootstrap
AccessorID: 1ee820ce-e149-829f-caba-77ec37be3c98
SecretID: be13b885-ddd4-830a-857c-d5fec72bbe8b (random from the guide)
Description: Bootstrap Token (Global Management)
Local: false
Create Time: 2018-10-19 11:48:25.614214 -0400 EDT
Policies:
00000000-0000-0000-0000-000000000001 - global-management

After the servers are restarted above, you will see new errors in the logs of the Consul servers related to permission denied errors:

2017/07/08 23:38:24 [WARN] agent: Node info update blocked by ACLs
2017/07/08 23:38:44 [WARN] agent: Coordinate update blocked by ACLs

These errors are because the agent doesn't yet have a properly configured acl.tokens.agent that it can use for its own internal operations like updating its node information in the catalog and performing anti-entropy syncing. We can create a token using the ACL API, and the ACL master token we set in the previous step:

The first step is to create a policy for your agent tokens (THIS IS WHERE I'M RECEIVING THE ERROR)

$ consul acl policy create -name "agent-token" -description "Agent Token Policy" -rules @agent-policy.hcl

I created the above file, specified the current file path, but receive the below error:

"Failed to create new policy: Unexpected response code: 403 (rpc error making call: Permission denied)"

Basically trying to call any acl create function, I receive the aforementioned error. Again, I didn't experience this until I bootstrapped a master token. What am I missing ? Is there something I need to do with my newly created master?

Any insight would be greatly appreciated! Thanks!

@ChipV223
Copy link
Contributor

ChipV223 commented Jan 7, 2019

@marcuschaney : When running any commands under an ACL-enabled Consul cluster, you would need to pass in the ACL master token, otherwise you'll get errors such as

"Failed to create new policy: Unexpected response code: 403 (rpc error making call: Permission denied)"

You can try adding the master token via including -token={token_id} to the CLI command. You can bypass this by setting the token id as the value of the CONSUL_HTTP_TOKEN env variable.

Please try either of those options and re-run the command again!

@ChipV223 ChipV223 closed this as completed Jan 7, 2019
@marcuschaney
Copy link
Author

marcuschaney commented Jan 7, 2019

@ChipV223 thanks for the timely response! Using the -token={token_id} worked for me!

Thanks again!
Marcus

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants
@ChipV223 @marcuschaney

Footer

© 2024 GitHub, Inc.

哆哆女性网网站制作网站推广优化毕业设计网站计划书天才高手app推广营销策划长沙网站建设推广网站建设及其网络推广喝养生海淀网站设计公司凤凰项目读后感商业计划书餐饮高端网站的建设工程大连seo顾问seo老师上街网站优化会议简报算八字寿命准吗周公解梦梦见狗是什么意思金额公司起名字虚空凝剑行嘉华珠宝气垫营销推广方式起名子有啥讲究传奇网站制作187zg有哪些工业设计网站在线发型设计网站爸妈姓氏合起来名字手机制作网站的软件seo高级视频教程河南新密范三书梦的解析淀粉肠小王子日销售额涨超10倍罗斯否认插足凯特王妃婚姻不负春光新的一天从800个哈欠开始有个姐真把千机伞做出来了国产伟哥去年销售近13亿充个话费竟沦为间接洗钱工具重庆警方辟谣“男子杀人焚尸”男子给前妻转账 现任妻子起诉要回春分繁花正当时呼北高速交通事故已致14人死亡杨洋拄拐现身医院月嫂回应掌掴婴儿是在赶虫子男孩疑遭霸凌 家长讨说法被踢出群因自嘲式简历走红的教授更新简介网友建议重庆地铁不准乘客携带菜筐清明节放假3天调休1天郑州一火锅店爆改成麻辣烫店19岁小伙救下5人后溺亡 多方发声两大学生合买彩票中奖一人不认账张家界的山上“长”满了韩国人?单亲妈妈陷入热恋 14岁儿子报警#春分立蛋大挑战#青海通报栏杆断裂小学生跌落住进ICU代拍被何赛飞拿着魔杖追着打315晚会后胖东来又人满为患了当地回应沈阳致3死车祸车主疑毒驾武汉大学樱花即将进入盛花期张立群任西安交通大学校长为江西彩礼“减负”的“试婚人”网友洛杉矶偶遇贾玲倪萍分享减重40斤方法男孩8年未见母亲被告知被遗忘小米汽车超级工厂正式揭幕周杰伦一审败诉网易特朗普谈“凯特王妃P图照”考生莫言也上北大硕士复试名单了妈妈回应孩子在校撞护栏坠楼恒大被罚41.75亿到底怎么缴男子持台球杆殴打2名女店员被抓校方回应护栏损坏小学生课间坠楼外国人感慨凌晨的中国很安全火箭最近9战8胜1负王树国3次鞠躬告别西交大师生房客欠租失踪 房东直发愁萧美琴窜访捷克 外交部回应山西省委原副书记商黎光被逮捕阿根廷将发行1万与2万面值的纸币英国王室又一合照被质疑P图男子被猫抓伤后确诊“猫抓病”

哆哆女性网 XML地图 TXT地图 虚拟主机 SEO 网站制作 网站优化