lavinmq: a user-facing AMQP provider (vhost-per-login) #15

Merged
jschoubben merged 1 commits from feat/convert-lavinmq into main 2026-09-06 21:21:28 +00:00
Owner

Converts lavinmq into a provider of a user-facing amqp capability — a per-consumer scoped vhost + user, distinct from the mesh's own control-plane broker. provides: amqp, serves {port: 5672}, provisions via lavinmq's HTTP management API (vhost + user + permissions named after the consumer login — the postgres database-per-login analog), admin set by a run-once bootstrap that computes the RabbitMQ password hash (the hash-vs-plaintext wrinkle). Plus a demo amqp-ping consumer that uses ${bound:amqp:as} for both user and vhost (the db-name lesson) and round-trips a message.

Lab-proven green (lavinmq-bed, two-node — the 5672 collision twin of 5432): the consumer gets its scoped vhost, connects, and round-trips. Requires the mesh-control require-only-mint fix.

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

Converts lavinmq into a **provider** of a user-facing `amqp` capability — a per-consumer scoped vhost + user, distinct from the mesh's own control-plane broker. `provides: amqp`, `serves {port: 5672}`, provisions via lavinmq's HTTP management API (vhost + user + permissions named after the consumer login — the postgres database-per-login analog), admin set by a **run-once bootstrap** that computes the RabbitMQ password hash (the hash-vs-plaintext wrinkle). Plus a demo `amqp-ping` consumer that uses `${bound:amqp:as}` for both user and vhost (the db-name lesson) and round-trips a message. Lab-proven green (`lavinmq-bed`, two-node — the 5672 collision twin of 5432): the consumer gets its scoped vhost, connects, and round-trips. Requires the mesh-control require-only-mint fix. https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-06 21:21:17 +00:00
lavinmq becomes a provider of a user-facing amqp interface: a consumer
that requires a message queue is given its OWN broker — a scoped vhost
and user on a lavinmq provider — not an account on the mesh's own
control-plane broker (ADR 0048). Vhost-per-login is the isolation model,
the exact analog of postgres's database-per-login: the provider names a
vhost after the consumer's login and a user with full rights on that
vhost and none elsewhere, so a login is a broker the consumer alone can
reach.

The provider drives lavinmq through its HTTP management API (client.ts,
the module's one impure seam), with a run-once bootstrap that computes
the RabbitMQ-compatible password hash lavinmq's config wants from the
plain admin secret the mesh mints — the value no ${secret:...}
placeholder can produce and the reason the bootstrap exists (ADR 0052).
serves.amqp carries the port so consumers reference ${bound:amqp:port}.

amqp-ping is a demo consumer: it contributes nothing (the vhost is the
login), reads its grant from an env-file the mesh fills, and uses
${bound:amqp:as} for BOTH its username and its vhost — the db-name
lesson applied to AMQP. It speaks AMQP 0-9-1 over a raw socket with no
npm dependency (the way redis speaks RESP) and round-trips one message.
It carries a slug so its identity fits the 20-char backend bound
(ADR 0049).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit cd46d53464 into main 2026-09-06 21:21:28 +00:00
jschoubben deleted branch feat/convert-lavinmq 2026-09-06 21:21:28 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#15