Every module moved onto the bus by the rollout was issued on the old one, so none had a consumer waiting; and the grant named a push delivery a runtime's client never binds, while the pull it does make — asking about its consumer, asking it for messages — was refused. The consumers a module's declarations imply are now raised whenever the bus is, and the grant is the pull.
57 lines
3.3 KiB
Plaintext
57 lines
3.3 KiB
Plaintext
# Composed by the mesh controller. Do not edit: the next composition overwrites it.
|
|
# Accounts and permissions are derived from what each module declares and nothing
|
|
# else (novox/hq ADR 0043, design 29 §2).
|
|
|
|
port: 4222
|
|
http: 127.0.0.1:8222
|
|
|
|
tls {
|
|
cert_file: "/tls/tls.crt"
|
|
key_file: "/tls/tls.key"
|
|
ca_file: "/tls/ca.crt"
|
|
}
|
|
|
|
jetstream {
|
|
store_dir: "/data"
|
|
}
|
|
|
|
# The mesh's users, composed by the controller. Do not edit: the next
|
|
# composition overwrites it. Permissions are derived from what each module
|
|
# declares and nothing else (novox/hq ADR 0043, design 29 §2).
|
|
|
|
accounts {
|
|
MESH {
|
|
jetstream: enabled
|
|
users = [
|
|
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
|
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.control.>", "mesh.mod.*.tool.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>"] }
|
|
subscribe: { allow: ["$JS.API.>", "_DELIVER.controller", "_DELIVER.controller.>", "_INBOX.controller.>", "mesh.control.>", "mesh.mod.gitea.event.pull.merged", "mesh.mod.mesh-catalog.event.catching-up", "mesh.mod.mesh-catalog.event.upgraded", "mesh.seat.mesh-build-machine.event.built"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "enrol.one", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
|
publish: { allow: ["mesh.control.enrol"] }
|
|
subscribe: { allow: ["_INBOX.enrol.one.>"] }
|
|
} }
|
|
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
|
publish: { allow: ["$JS.ACK.NODES.one.>", "$JS.API.CONSUMER.INFO.NODES.one", "mesh.control.one.>"] }
|
|
subscribe: { allow: ["_DELIVER.one", "_INBOX.node.one.>", "mesh.node.one.declare"] }
|
|
} }
|
|
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "$JS.ACK.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker.>", "$JS.API.CONSUMER.INFO.EVENTS.one_telegram", "$JS.API.CONSUMER.INFO.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.one_telegram", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
|
subscribe: { allow: ["_DELIVER.SEAT_TELEGRAM_SENDER_worker", "_INBOX.one.telegram.>", "mesh.mod.telegram.tool.>", "mesh.seat.telegram-sender.accept.send"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>", "$JS.API.CONSUMER.INFO.EVENTS.two_audit", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.two_audit"] }
|
|
subscribe: { allow: ["_INBOX.two.audit.>", "mesh.mod.audit.tool.>", "mesh.mod.shop.event.order.placed"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "two.shop", password: "$2a$11$ssssssssssssssssssssss", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "$JS.API.CONSUMER.INFO.EVENTS.two_shop", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.two_shop", "mesh.mod.shop.event.order.placed", "mesh.seat.telegram-sender.accept.send"] }
|
|
subscribe: { allow: ["_INBOX.two.shop.>", "mesh.mod.shop.tool.>"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
]
|
|
}
|
|
}
|