Describe the bus on its own terms

Comments framed the new bus by what it replaces — a comparison in almost
every explanation, which reads as though NATS were a variant of the old
thing rather than the mesh's nervous system. Removed throughout, and
OverAMQP becomes OverCurrent: the seam's two sides are the bus the mesh
runs on today and the one being built, not two protocols.

What remains is the client library's own package name, which is its name.
This commit is contained in:
2026-09-26 23:51:00 +02:00
parent 92d87b0082
commit 6c12780abe
5 changed files with 27 additions and 32 deletions
+9 -13
View File
@@ -1,19 +1,15 @@
// Composing the bus's own configuration.
//
// On AMQP an account was made by calling the broker's management API (management.go). On NATS it
// is *composed*: the controller writes accounts, users and per-subject permissions into one file
// the host keeps current, and the server reloads it in place (novox/hq ADR 0106 — never through a
// management API; design 25 §4).
// An account is *composed*, never called for: the controller writes accounts, users and
// per-subject permissions into one file the host keeps current, and the server reloads it in
// place (novox/hq ADR 0106 — never through a management API; design 25 §4).
//
// Everything here is pure. Given the principals, it returns the file's text — so the whole of the
// mesh's authority model is testable as strings, with no server, which is what management.go's
// `modulePermissions` already did for the half of it that could be.
// mesh's authority model is testable as strings, with no server.
//
// **NATS closes a gap AMQP left open.** management.go records it plainly: LavinMQ has no topic
// permissions, so an emitting module is granted the events exchange whole, and ADR 0042's origin
// reservation — a module publishes only under its own name — is "stamped by the sdk, not enforced
// here". NATS permissions are per subject, so that reservation becomes something the server
// refuses rather than something a library promises.
// **Permissions are per subject, so a module's own name is the server's to enforce.** ADR 0042
// reserves a module's origin — it publishes only under its own name — and here that is a refusal
// rather than something a library promises.
package broker
import (
@@ -270,8 +266,8 @@ func consumerDurable(p Principal) string {
// Server is everything the composed file needs that is not a principal.
type Server struct {
// ClientPort carries TLS itself; there is no plaintext port beside it, which is where this
// differs from the AMQP broker's 5671/5672 pair.
// ClientPort carries TLS itself. There is no plaintext port beside it: a bus reachable
// without TLS is one a module can reach without TLS by mistake.
ClientPort int
MonitoringPort int
TLSCert string