Compose a bus user only for a module that can read an account
Every assigned module was composed as a bus user, though only one declaring a broker secret can ever be issued an account; the rest were named on every status, plan and push as credentials never minted (137 now), burying the real gaps. Their durable consumers are now derived from what the runtime carries, so nothing they hear changes. The composed file is unchanged: those users had no password and were already left out. Fixes hq issue 195.
This commit is contained in:
@@ -136,6 +136,11 @@ func declaredFor(m catalogue.Manifest, seats map[string]catalogue.SeatDeclaratio
|
||||
State: bucketsOf(m),
|
||||
Reads: m.Reads,
|
||||
}
|
||||
// Whether it can be given an account at all: delivered as its own secret named broker, so one
|
||||
// that declares none has nowhere to read it (novox/hq issue 195).
|
||||
if _, reads := m.OwnSecrets["broker"]; !reads {
|
||||
d.NoAccount = true
|
||||
}
|
||||
for _, c := range m.Claims {
|
||||
// Every seat with a protocol, the mesh's own included. One that says only who does a job is
|
||||
// not here and grants nothing, which is most of them.
|
||||
|
||||
Reference in New Issue
Block a user