On 2.10.29 such a consumer was moved past a message now and then without handing it over; the controller's events consumer has seven filters, and a merge on the stream never reached it. The test reproduces the skip on 2.10.29 and keeps the image's release equal to the server it tests.
119 lines
5.0 KiB
JSON
119 lines
5.0 KiB
JSON
{
|
|
"module": "nats",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "mesh-bus",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-broker",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"bus-users": "/var/lib/nats-module/conf/accounts.conf",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [],
|
|
"consumes": [],
|
|
"listens": [
|
|
{
|
|
"name": "bus",
|
|
"port": 4222,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the mesh bus — every link the mesh has, over TLS, reached across the overlay"
|
|
}
|
|
],
|
|
"tools": [
|
|
"nats_server",
|
|
"nats_connections",
|
|
"nats_subscriptions",
|
|
"nats_streams",
|
|
"nats_backlog",
|
|
"nats_buckets",
|
|
"nats_users",
|
|
"nats_user_can"
|
|
],
|
|
"guards": [
|
|
8222
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "jetstream-data",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-broker-nats",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "conf-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/nats-module/conf",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-conf",
|
|
"type": "file",
|
|
"path": "/var/lib/nats-module/conf/nats.conf",
|
|
"content": "# The nats module's own server settings. Declared by the module, because a port, a TLS path\n# and a store directory are properties of the container this module raises: they live in its\n# image and its mounts and change when it does.\n#\n# The mesh writes accounts.conf beside this one and nothing else. A controller that wrote the\n# whole file would have to be kept in step with a Dockerfile it never sees.\n\nport: 4222\n# Monitoring on every interface *inside* the container, so the publish below can reach it; the publish\n# is 127.0.0.1:8222 on the machine, so nothing beyond the machine reaches it, and the module guards 8222\n# too. Bound to the container's own loopback until 2026-10-04, the published port answered nothing\n# (connection reset), and the only way in was `docker exec`.\nhttp: 0.0.0.0:8222\n\n# The mesh's own broker certificate — the one every machine already pins by fingerprint and the\n# controller already trusts (MESH_BROKER_CERTIFICATE). Serving the new bus with it means no\n# machine's pin changes when it moves, and no second certificate exists to be wrong about.\ntls {\n cert_file: \"/tls/tls.crt\"\n key_file: \"/tls/tls.key\"\n}\n\n# **No `verify`, deliberately, and it was `verify: true` until a probe ran this image.** That\n# setting makes the server demand a *client* certificate, and nothing in the mesh presents one: a\n# host pins this server's exact certificate and authenticates with the password the mesh minted\n# (novox/hq ADR 0004, design 25 §4), and so does a module's runtime. With it on, every connection\n# in the mesh is refused at the TLS handshake, before any password is looked at — and the error is\n# \"client didn't provide a certificate\", which reads as a client fault.\n#\n# TLS is still required: a tls block is what makes it required, and verify only decides whether\n# client certificates are checked. What is given up is a second factor the mesh has no machinery\n# to issue or rotate — a certificate per module per node — and what is kept is stronger than a\n# name check in both directions: an exact pin outward, a per-user password inward.\n\njetstream {\n store_dir: \"/data\"\n}\n\n# Every user of the mesh, composed by the controller and rewritten whenever a module is\n# assigned, a node enrols or a person's access changes.\n#\n# **Relative, and in this same directory, because it has to be.** An absolute include path is\n# resolved relative to the including file's directory, not from the root: nats-server given\n# `include /etc/nats/accounts.conf` from /etc/nats-server/nats.conf looks for\n# /etc/nats-server/etc/nats/accounts.conf and refuses to start. Verified against the server.\ninclude accounts.conf\n",
|
|
"mode": "0644"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-broker-nats",
|
|
"ports": [
|
|
"4222:4222",
|
|
"127.0.0.1:8222:8222"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/mesh-broker-nats:/data",
|
|
"/var/lib/nats-module/conf:/etc/nats:ro",
|
|
"${access:tls}:/tls:ro"
|
|
],
|
|
"artifact": "server"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"id": "tls",
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "NATS_BASE",
|
|
"image": "nats@sha256:e4bf19f15fd3218814a4e3c9e0064e1334bd8aa20d5984b9f1a0afd084f8cc00"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
},
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/nats-tools",
|
|
"binary": "nats-tools",
|
|
"loads": [
|
|
"nats-tools"
|
|
],
|
|
"env": {
|
|
"MESH_NATS_MONITOR": "http://127.0.0.1:8222",
|
|
"MESH_NATS_CONTAINER": "mesh-broker-nats",
|
|
"MESH_NATS_USERS_FILE": "/etc/nats/accounts.conf"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|