Describe the bus on its own terms
Comments framed the new bus by what it replaces — a comparison in almost every explanation, which reads as though NATS were a variant of the old thing rather than the mesh's nervous system. Removed throughout, and OverAMQP becomes OverCurrent: the seam's two sides are the bus the mesh runs on today and the one being built, not two protocols. What remains is the client library's own package name, which is its name.
This commit is contained in:
+9
-13
@@ -1,19 +1,15 @@
|
||||
// Composing the bus's own configuration.
|
||||
//
|
||||
// On AMQP an account was made by calling the broker's management API (management.go). On NATS it
|
||||
// is *composed*: the controller writes accounts, users and per-subject permissions into one file
|
||||
// the host keeps current, and the server reloads it in place (novox/hq ADR 0106 — never through a
|
||||
// management API; design 25 §4).
|
||||
// An account is *composed*, never called for: the controller writes accounts, users and
|
||||
// per-subject permissions into one file the host keeps current, and the server reloads it in
|
||||
// place (novox/hq ADR 0106 — never through a management API; design 25 §4).
|
||||
//
|
||||
// Everything here is pure. Given the principals, it returns the file's text — so the whole of the
|
||||
// mesh's authority model is testable as strings, with no server, which is what management.go's
|
||||
// `modulePermissions` already did for the half of it that could be.
|
||||
// mesh's authority model is testable as strings, with no server.
|
||||
//
|
||||
// **NATS closes a gap AMQP left open.** management.go records it plainly: LavinMQ has no topic
|
||||
// permissions, so an emitting module is granted the events exchange whole, and ADR 0042's origin
|
||||
// reservation — a module publishes only under its own name — is "stamped by the sdk, not enforced
|
||||
// here". NATS permissions are per subject, so that reservation becomes something the server
|
||||
// refuses rather than something a library promises.
|
||||
// **Permissions are per subject, so a module's own name is the server's to enforce.** ADR 0042
|
||||
// reserves a module's origin — it publishes only under its own name — and here that is a refusal
|
||||
// rather than something a library promises.
|
||||
package broker
|
||||
|
||||
import (
|
||||
@@ -270,8 +266,8 @@ func consumerDurable(p Principal) string {
|
||||
|
||||
// Server is everything the composed file needs that is not a principal.
|
||||
type Server struct {
|
||||
// ClientPort carries TLS itself; there is no plaintext port beside it, which is where this
|
||||
// differs from the AMQP broker's 5671/5672 pair.
|
||||
// ClientPort carries TLS itself. There is no plaintext port beside it: a bus reachable
|
||||
// without TLS is one a module can reach without TLS by mistake.
|
||||
ClientPort int
|
||||
MonitoringPort int
|
||||
TLSCert string
|
||||
|
||||
Reference in New Issue
Block a user