Intention‑Based Security Policies Require Manual Federation Across Datacenters in Consul 1.9+
0 reputation · 28 Jul 2026, 14:53 UTC
Issue Overview
The goal is to clarify whether Consul’s intention‑based security (IBS) policies should be automatically replicated across datacenters or if manual federation is the intended operational model.
Consul Connect IBS, introduced in version 1.9, declares service‑to‑service intentions via the intention API. By default, all traffic is denied unless an explicit allow intention is defined. Documentation notes that IBS policies are not automatically propagated between datacenters; administrators must manually create matching intentions in each DC or set up a federation process.
This raises uncertainty about the design decision: is the lack of cross‑datacenter propagation a deliberate choice to keep policy control local, or a missing feature that should be addressed in a future release?
Is manual federation the expected operational model for IBS policies across datacenters?
Are there plans to enable automatic policy replication through Consul’s gossip or RPC mechanisms?
What are the recommended practices for maintaining consistent intention policies in multi‑dc deployments without manual steps?