Ad
 
Learn More

mesh:write is the Important line in Consul 2.0.4

Consul v2.0.4 ships a BREAKING CHANGE on ACL permissions for Envoy extensions. The Important line is mesh:write (and the FIPS rename), not the patch tag.

Written by Watch Changelog Team

•2 min read

mesh:write is the Important line in Consul 2.0.4

So HashiCorp Consul Updates put v2.0.4 on the feed, dated September 9, 2026. We flagged it Important as a breaking change. The version string is kind of the decoy. The line that matters is under BREAKING CHANGES: tokens that hold service:write but not mesh:write now get a permission-denied error when they try to attach builtin/lua or builtin/wasm EnvoyExtensions, or the upstream escape-hatch overrides, to a service-defaults config entry. Same story when registering a connect-proxy sidecar with bootstrap or xDS escape-hatch keys in Proxy.Config.

Recency wants the patch note. Go bumped to 1.26.7 for security. Fine. That is what people screenshot. The partner-break line, to the best of my understanding, is the ACL rewrite. Operators must grant mesh:write to any token that legitimately needs those capabilities. Previously a holder of service:write could attach a Lua script or Wasm module that Envoy compiled and ran on every proxied request as the sidecar process user, with access to mTLS private keys, request bodies, and the host filesystem. That is not a soft nudge. That is a permission model change dressed as a point release.

There is a second Important line in the same note if you sell into Enterprise FIPS shops. FIPS release artifacts are renamed. Version metadata moves from +ent.fips1402 to +ent.fips1403, and package and container artifacts flip from the F2 suffix to F3. Pipelines that pin those names break even when the ACL story does not apply.

I keep almost filing Consul patch tags under "infra bump, ignore." Kind of the wrong habit when your AE is in a service-mesh renewal and the customer asks why their automation started getting permission denied overnight. Let's say the talking point is not "2.0.4 shipped." It is mesh:write now sits beside service:write for those Envoy extension paths, then check FIPS artifact names if you are on Enterprise FIPS. We pull it into a uniform entry shape at /sources/consul-updates. Same JSON as everything else. Recency still wants the version tag. Recency is not the ACL line.