The bus account has JetStream, and the control plane's client has its own inbox
Two refusals the first live connections met. A user in the MESH account was told "JetStream not enabled for account" the first time it bound a consumer: with accounts defined, JetStream is enabled per account, not only globally — the account's setting, which the mesh owns, not the server's block, which it does not. And the control plane's client used a random inbox prefix where it is granted exactly _INBOX.<its user>.>, so the server's first answer could not reach it. The prefix now follows from the user in the URL, for every principal that dials so.
This commit is contained in:
+1
@@ -21,6 +21,7 @@ jetstream {
|
||||
|
||||
accounts {
|
||||
MESH {
|
||||
jetstream: enabled
|
||||
users = [
|
||||
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
||||
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.control.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>"] }
|
||||
|
||||
Reference in New Issue
Block a user