Repository navigation
Conversation
Consul server addresses may now use the https scheme, per server and mixed with http ones. TLS goes through lua-resty-consul (ssl, sni_host, ssl_verify), with the certificate verified against the host of the address and the trust store from lua_ssl_trusted_certificate. Any other scheme is still rejected, now with an error instead of a raise from unpack() on the nil parse result.
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
3 open findings
What changed in this PR
Adds HTTPS support to Consul service discovery so APISIX can communicate with Consul agents over TLS, including mixed http/https server lists, with docs and tests to validate behavior.
Changes:
- Allow Consul server addresses using
https://(mixed withhttp://) and pass TLS options to the Consul client. - Improve handling of unsupported schemes so they return a proper error instead of crashing.
- Add an E2E-style TLS test and update documentation/examples to explain CA trust configuration.
| File | Description |
|---|---|
apisix/discovery/consul/client.lua |
Adds per-server scheme parsing and wires TLS/SNI/verify options into resty-consul usage. |
t/discovery/consul-tls.t |
New test coverage validating HTTPS Consul discovery and mixed-scheme parsing/error cases. |
docs/en/latest/discovery/consul.md |
Documents HTTPS scheme support and how to configure the trusted CA bundle. |
conf/config.yaml.example |
Updates comment to indicate Consul servers may be http or https. |
🧠 Review effort: Lite
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Copilot stopped reviewing on behalf of
nic-6443 due to an error
October 8, 2026 11:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
This lets consul discovery talk to Consul servers over https. Today
format_consul_paramsonly acceptshttp://addresses. Anhttps://server fails registry startup withonly support consul http schema address, and since that runs inside the init_worker / start path, discovery for it just never comes up.The scheme is now decided per server address, so one
serverslist can mixhttpandhttps. For https entries the client hands TLS to lua-resty-consul (ssl = true,sni_host = <host>,ssl_verify = true) at both places that build a client: the watch path (get_opts) andfetch_services_from_server. The certificate is checked against the host in the address. Trust comes fromlua_ssl_trusted_certificate, i.e.apisix.ssl.ssl_trusted_certificate, the same way the nacos https support works. An https address without a port uses 443 (parse_uri's default). I didn't add schema fields for skip-verify or a per-registry CA.Any other scheme is still rejected, with a message that now mentions https. One small side fix:
http.parse_urireturns nil for a scheme other than http/https, so something liketcp://...used to crash inunpack(nil)instead of reaching that message. It now returns the error properly.t/discovery/consul-tls.tputs a TLS server block (test cert signed byapisix.crt) in front of the CI consul on 8500. It checks that a route withdiscovery_type: consulresolves through anhttps://localhost:18501server in both long and short connect mode, and it checks the per-address scheme handling and the rejection of other schemes. The docs for consul discovery and theconfig.yaml.examplecomment are updated too.Which issue(s) this PR fixes:
N/A
Checklist