Consul Enterprise

Consul Enterprise features address the organizational complexities of collaboration, operations, scale, and governance. If you have purchased or wish to try out Consul Enterprise, refer to how to access Consul Enterprise.

Enterprise features

The following features are available in several forms of Consul Enterprise.

Multi-Tenancy

  • Admin Partitions: Define administrative boundaries between tenants within a single Consul datacenter
  • Namespaces: Define resource boundaries within a single admin partition for further organizational flexibility
  • Sameness Groups: Define partitions and cluster peers as members of a group with identical services

Resiliency

Scalability

  • Read Replicas: Deploy non-voting Consul servers to enhance the scalability of read requests

Operational simplification

  • Automated Upgrades: Ease upgrades by automating the transition from existing to newly deployed Consul servers
  • Consul-Terraform-Sync Enterprise: Leverage the enhanced network infrastructure automation capabilities of the enterprise version of Consul-Terraform-Sync

Complex network topology support

  • Network Areas: Support complex network topologies between federated Consul datacenters with pairwise federation rather than full mesh federation
  • Network Segments: Support complex network topologies within a Consul datacenter by enforcing boundaries in Consul client gossip traffic

Governance

  • OIDC Auth Method: Manage user access to Consul through an OIDC identity provider instead of Consul ACL tokens directly
  • Audit Logging: Understand Consul access and usage patterns by reviewing access to the Consul HTTP API

Regulatory compliance

  • FIPS 140-2 Compliance: Leverage FIPS builds of Consul Enterprise to ensure your Consul deployments are secured with BoringCrypto and CNGCrypto, and compliant with FIPS 140-2.

    Overview - 图1

    Note

    FIPS 140-2 builds of Consul Enterprise support all runtimes (VMs, Kubernetes) except for Lambda and ECS. In addition, HCP does not currently support FIPS builds of Consul Enterprise.

Access Consul Enterprise

The method of accessing Consul Enterprise and its features depends on the whether using HashiCorp Cloud Platform or self-managed Consul.

HCP Consul

No action is required to access Consul Enterprise in a HashiCorp Cloud Platform installation.

You can try out HCP Consul for free. Refer to the HCP Consul product page for more details.

Self-Managed Consul

To access Consul Enterprise in a self-managed installation, apply a purchased license to the Consul Enterprise binary that grants access to the desired features.

Contact your HashiCorp Support contact for a development license.

Consul Enterprise feature availability

The Consul Enterprise features that are available depend on your license and the runtimes you use in your deployment.

Feature availability by license

Available Enterprise features per Consul form and license include:

FeatureHashiCorp Cloud Platform (HCP) ConsulConsul EnterpriseLegacy Consul Enterprise (module-based)
Consul servers as a managed serviceYesNo (self-managed)No (self-managed)
Admin PartitionsAll tiersYesWith Governance and Policy module
Audit LoggingStandard tier and aboveYesWith Governance and Policy module
Automated Server BackupsAll tiersYesYes
Automated Server UpgradesAll tiersYesYes
Consul-Terraform-Sync EnterpriseAll tiersYesYes
Enhanced Read ScalabilityNoYesWith Global Visibility, Routing, and Scale module
FIPS 140-2 ComplianceNoYesNo
NamespacesAll tiersYesWith Governance and Policy module
Network AreasNoYesWith Global Visibility, Routing, and Scale module
Network SegmentsNoYesWith Global Visibility, Routing, and Scale module
OIDC Auth MethodNoYesYes
Redundancy ZonesNot applicableYesWith Global Visibility, Routing, and Scale module
Sameness GroupsNoYesN/A
Server request rate limits per source IPAll tiersYesWith Governance and Policy module

Feature availability by runtime

Consul Enterprise feature availability can change depending on your server and client agent runtimes.

Enterprise FeatureVM ClientK8s ClientECS Client
Admin Partitions
Audit Logging
Automated Server Backups
Automated Server Upgrades
Enhanced Read Scalability
FIPS 140-2 Compliance
Namespaces
Network Areas
Network Segments
OIDC Auth Method
Redundancy Zones
Sameness Groups
Server request rate limits per source IP
Enterprise FeatureVM ClientK8s ClientECS Client
Admin Partitions
Audit Logging
Automated Server Backups
Automated Server Upgrades
Enhanced Read Scalability
FIPS 140-2 Compliance
Namespaces
Network Areas
Network Segments
OIDC Auth Method
Redundancy Zones
Sameness Groups
Server request rate limits per source IP
Enterprise FeatureVM ClientK8s ClientECS Client
Admin Partitions
Audit Logging
Automated Server Backups
Automated Server Upgrades
Enhanced Read Scalability
FIPS 140-2 Compliance
Namespaces
Network Areas
Network Segments
OIDC Auth Method
Redundancy Zonesn/an/an/a
Sameness Groups
Server request rate limits per source IP