Success doesn’t happen overnight, nor does migrating from a legacy environment to a service mesh platform, that’s why HashiCorp today announced the beta availability of its service networking platform. Consul 1.8 includes features that enable incremental migration towards a service mesh in heterogeneous environments.

Consul is a service mesh platform with a control plane that can handle service discovery, configuration, and segmentation functionality. Those functions can be used individually or all together as part of the service mesh. It includes a built-in proxy to work out of the box, but it can also support third-party proxy integrators like Envoy.

Version1.8 includes a new ingress gateway to enable communication between external traffic with the internal services; an terminating gateway to enable communication between applications inside the service mesh with existing services outside of the mesh; and a wide area network (WAN) federation over mesh gateway that allows data centers to federate WAN gossip through mesh gateways. 

Consul does not require a user to accept all the components to form a service mesh, providing organizations with more options and further fortifies Consul as a more broadly-focused service mesh option than the Kubernetes-focused Istio platform.

HashiCorp’s angle with Consul is to target heterogeneous workloads that an enterprise is likely to have spread across different infrastructure. This would include on premises, in a public cloud, or in multiple public clouds.

Ingress Gateway

Gone are the days where traditional network connection – from client-to-server or client-to-client – is the only avenue to transmit data. Emerging technologies from edge computing to microservices and containers need platform-level automation to create the network connectivity required by microservices-based software architectures. And that’s where service mesh comes in. 

To strip away some of the complexity associated with running a service mesh HashiCorp added a new ingress gateway capability in Consul that enables a slow drip migration toward a service mesh architecture. Ingress gateways route traffic into the service mesh without requiring networking overrides or overhead for additional service capacity.

It’s worth noting that HashiCorp joins a growing number of service mesh options that are claiming to make it easier to support the deployment of microservices. Kong claims that its Kuma platform is “a universal service mesh" and recently added a Kubernetes ingress controller to the platform. And much like Consul, Kuma is designed to work within and outside of the Kubernetes ecosystem.

Terminating Gateway

“The transition to service mesh will often be made incrementally due to organizational constraints or a lack of infrastructure automation. In this scenario users may be operating services inside and outside the mesh for long periods of time as they transition,” wrote Neena Pemmaraju director of product management at HashiCorp in a blog post. 

To this end, Consul now supports creating a terminating gateway. According to Pemmaraju, terminating gateways are egress proxies that terminate Connect mTLS connections, enforce intentions, and forward requests to appropriate destination services. In Consul, intentions control the service-to-service connections to determine which services may establish connections. 

WAN Federation Over Mesh Gateway

HashiCorp claims one of the key features of Consul is its ability to support multiple data centers. To accommodate for operators existing workflows and data centers that reside in different clouds or runtime environments, 1.8 features a composite Consul Cluster, WAN join.

It also uses a gossip protocol, which is a style of computer-to-computer communication protocol similar to the form of gossip seen in social networks, to manage membership and broadcast messages through two different gossip pools – local area network (LAN) and WAN.

The LAN gossip pool contains all members of the datacenter, both clients and servers, where membership information is used to grant clients access to discover servers, reducing the amount of configuration needed.

The WAN pool permits all servers to participate in the WAN pool regardless of data center. In this pool membership information provided by the WAN pool allows servers to perform cross datacenter requests. The WAN federation over mesh gateway allows operators to federate data centers together with only mesh gateways exposed to the WAN and improve both setup UX and security.

HashiCorp's Slice of the Service Mesh Sector

HashiCorp is most often grouped together with larger cloud-focused vendors like Red Hat and VMware, as well as DevOps and infrastructure-as-a-code (IaaS) firms like GitHub, Chef, Puppet, SUSE, Docker, and Rancher Labs

The company, which has raised hundreds of millions of dollars in multiple funding rounds, offers open source-based software platforms that allow enterprises to manage distributed application infrastructure. Its product portfolio includes its Terraform IaaS software, the Vault centralized security management platform, and the Nomad cluster scheduler. 

The current economic climate – as executives that delayed moving to the cloud are now scrambling to reset and execute a full digital transformation in matter of days and weeks — will provide further proof to whether HashiCorp's portfolio of service mesh options do make it easier to support the deployment of microservices.