broker: a generic module account + module issue (ADR 0048) #3
Closed
jschoubben
wants to merge 4 commits from
events/module-broker-account into claude/manifest-events
pull from: events/module-broker-account
merge into: :claude/manifest-events
:main
:fix/an-older-merge-does-not-move-a-source
:fix/a-mirrored-base-is-not-pulled-twice
:fix/a-module-hears-what-it-consumes
:fix/the-controller-may-ask-a-tool
:fix/a-module-serves-its-own-namespace
:fix/the-check-dials-as-the-mesh-does
:fix/an-edge-is-recorded-by-path
:feat/build-edges-are-recorded
:feat/one-bus
:fix/the-controller-follows-what-it-decodes
:feat/a-merge-on-the-forge-builds-what-it-moved
:feat/rollout-hand
:fix/store-seats-keep-their-protocol
:feat/the-build-machine-takes-work-on-nats
:fix/a-principal-may-hear-its-consumer
:fix/the-bus-account-has-jetstream
:fix/the-controller-pins-the-bus-certificate
:feat/the-controller-serves-on-nats
:fix/a-node-may-bind-its-consumer
:fix/mint-leaves-the-control-planes-old-secret-alone
:fix/the-controller-mounts-its-bus-secret
:fix/the-network-map-knows-the-holders
:fix/mint-bare-host-and-again
:fix/mint-finds-the-bus-on-the-hub
:switch/the-controller-speaks-nats
:feat/the-move-mints-and-delivers
:fix/seat-usage-lines
:fix/record-the-standing-holder
:feat/amqp-is-not-a-provision
:feat/seat-handover
:fix/rollout-retires-the-old-broker
:fix/the-store-owns-the-seat-set
:fix/go-126-base
:feat/nats-genesis
:fix/a-taken-tunnel-brings-its-port
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements ADR 0048's control-plane half — a module's broker account, scoped by its manifest.
CreateModuleAccount— permissions are the manifest: readmesh.events+ its own<node>.<module>.eventsqueue if it consumes; writemesh.eventsonly if it emits; nothing else.EnsureEventExchanges— the substrate's exchanges (mesh.events/mesh.rpc/mesh.events.dead+ retention queue), idempotent.EnsureModuleQueue— the substrate pre-declares a consumer's dead-lettered queue, because LavinMQ refuses a non-administrator declaring one; the runtime then passively checks it.module issue <module> --node <m>— looks up emits/consumes, ensures the bus, creates the account, and seals an amqps{url,fingerprint,node,module}as the module's broker own-secret.Scope tested as patterns; every management call verified against a real LavinMQ; the whole flow proven in the lab (mesh-lab: the assigned audit-logger passes 1/1).
Honest limit, recorded in the code: LavinMQ has no topic permissions, so ADR 0047's emit-origin reservation (
module.<self>.*) is stamped by the sdk, not broker-enforced.Stacked on
claude/manifest-events(the emits/consumes fields, PR #2).https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
'module issue <module> --node <m>' looks up the module's emits/consumes from the catalogue, ensures the bus exchanges exist, creates its scoped account (CreateModuleAccount), and seals an amqps {url,fingerprint} to the node as the module's broker own-secret — the same delivery as 'builder issue', now generic. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzFPull request closed