Design 25: a host directory bind, not a named volume

Issue 115 is resolved and converted four modules away from named volumes;
the bus's own data is not the place to bring one back. Also: NATS carries
TLS on the client port rather than beside a plaintext one, so there is no
5671/5672 pair to mirror.
This commit is contained in:
2026-09-26 19:34:54 +02:00
parent 814c9e563f
commit b5b68e8852
+8 -3
View File
@@ -158,9 +158,14 @@ signing hierarchy for nothing.
`nats` is a catalogue module claiming the seat `mesh-broker` `nats` is a catalogue module claiming the seat `mesh-broker`
([ADR 0079](../../02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md): the seat ([ADR 0079](../../02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md): the seat
is the server, and the server changes). It declares one container (a single binary; JetStream on a is the server, and the server changes). It declares one container (a single binary; **JetStream on a host
named volume), its listening ports — client, TLS, and the monitoring endpoint on loopback — and a directory bind, not a named volume** — revision, second review:
configuration file the controller composes (accounts, permissions, TLS, JetStream). [issue 115](../../04-ISSUES/115-a-named-docker-volume-is-invisible-and-one-flag-from-gone/00-report.md)
is resolved, and converted the store, the broker and two others away from named volumes for the
reason it names; the bus's own data is not the place to reintroduce one), its listening ports —
**the client port, which carries TLS itself** rather than standing beside a plaintext one as the
AMQP broker's 5671/5672 pair did, and the monitoring endpoint on loopback — and a configuration
file the controller composes (accounts, permissions, TLS, JetStream).
**How that file's changes reach the running server, corrected on revision.** First review: the **How that file's changes reach the running server, corrected on revision.** First review: the
earlier draft named `reload-on` as the mechanism, citing the container runtime's own trust file as earlier draft named `reload-on` as the mechanism, citing the container runtime's own trust file as