如何通过CIDR块隔离Consul服务发现(VPC对等连接场景)
Absolutely, you can lock down Consul service discovery to specific CIDR blocks even when your VPCs are fully peered—no need to modify the VPC peering setup itself. Here are the most reliable approaches tailored to your scenario:
1. Use Consul ACLs with Source IP Restrictions
Consul's ACL system lets you create policies that grant service discovery permissions only to clients coming from your target CIDRs. This is the most robust method because it enforces access at the Consul layer, not just the network layer.
For example, create a policy that allows service:read access only for requests from 10.1.0.0/24 (your allowed CIDR):
policy = <<EOF node_prefix "" { policy = "read" source_prefix = "10.1.0.0/24" } service_prefix "" { policy = "read" source_prefix = "10.1.0.0/24" } EOF
Attach this policy to the tokens used by your Consul clients or services. Any requests from outside 10.1.0.0/24 will be denied access to service discovery data, even if the network path is open via VPC peering.
2. Filter Discovered Services via Client-Side Configuration
If you want to limit which services your local Consul clients can see (instead of blocking access entirely), you can add a service filter to your Consul client config. This filters out any services whose advertised addresses fall outside your target CIDR.
Add this to your client's config.hcl:
dns_config { filter = "Meta.Addr matches '10.1.0.0/24'" }
This ensures that when clients query Consul DNS, they only get services with addresses in 10.1.0.0/24. You can also apply similar filters to the HTTP API by appending ?filter=Meta.Addr matches '10.1.0.0/24' to your service list requests.
3. Restrict Service Registration to Local CIDRs
To prevent cross-VPC services from being registered in your Consul cluster in the first place, configure your Consul clients to only advertise addresses from your local VPC's CIDR.
In your client config:
advertise_addr = "10.1.0.0/24" bind_addr = "10.1.0.0/24"
This forces the client to use only addresses within your allowed CIDR when registering services, so even if the VPC is peered, cross-VPC services won't show up with addresses outside your target range. Combine this with ACLs for extra safety.
Key Notes
- VPC peering being "full" doesn't restrict you from enforcing application-layer controls like Consul ACLs—this is exactly the kind of use case where layer-7 policies shine.
- Always test these changes in a staging environment first to avoid breaking existing service dependencies.
内容的提问来源于stack exchange,提问作者jugg1es

