The controller may publish the memberships it issues
The server refused every membership the controller published after a push (2026-10-01, Permissions Violation for Publish to mesh.assignment.<node>.<module>): the controller's own grant named the control, node and JetStream subjects and not the assignments it alone issues (hq ADR 0160). Broker golden regenerated; one line differs.
This commit is contained in:
@@ -173,8 +173,10 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
||||
switch p.Kind {
|
||||
case KindController:
|
||||
// The controller owns the mesh's own traffic and the streams. It is the only writer of
|
||||
// stream definitions (design 25 §3), so it alone reaches the JetStream API.
|
||||
pub = []string{"mesh.control.>", "mesh.node.>", "$JS.API.>"}
|
||||
// stream definitions (design 25 §3), so it alone reaches the JetStream API — and it alone
|
||||
// issues memberships (novox/hq ADR 0160), which it publishes into the assignments stream
|
||||
// after each push; refused by the server on 2026-10-01 until this line named them.
|
||||
pub = []string{"mesh.control.>", "mesh.node.>", "mesh.assignment.>", "$JS.API.>"}
|
||||
// **And where its consumers deliver.** A push consumer delivers on `_DELIVER.<its name>`,
|
||||
// and a client bound to it subscribes exactly that; the server refused it for every
|
||||
// principal the first time one bound a consumer (2026-09-28). Each kind below is granted
|
||||
|
||||
Reference in New Issue
Block a user