Task 1.3 of novox/hq ADR 0116. On AMQP an account was an HTTP call; on NATS it is text the controller composes and the server reloads (ADR 0106). Pure, so the mesh's whole authority model is testable as strings. NATS closes a gap management.go recorded rather than hid: LavinMQ has no topic permissions, so an emitter was granted the events exchange whole and ADR 0042's origin reservation was "stamped by the sdk, not enforced here". Per-subject permissions make it the server's refusal. Two things found by composing a real file rather than reading the design: - a scoped inbox leaves a responder unable to reply, because the answer goes to the caller's inbox. allow_responses is the answer — one reply to the subject of a message actually received — and only principals that serve are granted it. Recorded in design 25 §4. - composition must be deterministic: the module's entrypoint reloads on the file's digest, so an order-dependent composer would reload the whole bus on every controller restart. Covered by a test. The golden fixture is the exact text `nats-server -t` accepts, so the syntax is the server's rather than one we invented.
51 lines
2.1 KiB
Plaintext
51 lines
2.1 KiB
Plaintext
# Composed by the mesh controller. Do not edit: the next composition overwrites it.
|
|
# Accounts and permissions are derived from what each module declares and nothing
|
|
# else (novox/hq ADR 0043, design 29 §2).
|
|
|
|
port: 4222
|
|
http: 127.0.0.1:8222
|
|
|
|
tls {
|
|
cert_file: "/tls/tls.crt"
|
|
key_file: "/tls/tls.key"
|
|
ca_file: "/tls/ca.crt"
|
|
verify: true
|
|
}
|
|
|
|
jetstream {
|
|
store_dir: "/data"
|
|
}
|
|
|
|
accounts {
|
|
MESH {
|
|
users = [
|
|
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
|
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.API.>", "mesh.build.>", "mesh.control.>", "mesh.node.>"] }
|
|
subscribe: { allow: ["$JS.API.>", "_INBOX.controller.>", "mesh.build.>", "mesh.control.>"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "enrolment", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
|
publish: { allow: ["mesh.control.enrol"] }
|
|
subscribe: { allow: [] }
|
|
} }
|
|
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
|
publish: { allow: ["$JS.ACK.NODES.one.>", "mesh.control.one.>"] }
|
|
subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] }
|
|
} }
|
|
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "mesh.seat.telegram-sender.delivered", "mesh.seat.telegram-sender.failed"] }
|
|
subscribe: { allow: ["_INBOX.one.telegram.>", "mesh.mod.telegram.tool.status", "mesh.seat.telegram-sender.send"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>"] }
|
|
subscribe: { allow: ["_INBOX.two.audit.>", "mesh.mod.shop.order.placed"] }
|
|
} }
|
|
{ user: "two.shop", password: "$2a$11$ssssssssssssssssssssss", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "mesh.mod.shop.order.placed", "mesh.seat.telegram-sender.send"] }
|
|
subscribe: { allow: ["_INBOX.two.shop.>"] }
|
|
} }
|
|
]
|
|
}
|
|
}
|