A node can join the bus the mesh runs on
novox/hq 04-ISSUES/146, the layers behind the three already fixed. A new membership says which bus it is for. Empty meant 'whatever the mesh runs today' while two buses existed, and became a refusal the moment one did: an enrolled node came up and reconnected for ever against its own record. The enrolling client takes its inboxes in the space its user may listen in. A JetStream publish waits for the stream's acknowledgement on an inbox the client picks, and its default is one this user may not subscribe to — so the enrolment failed with a permissions violation on a subject nobody had chosen. And the enrolment publish carries a message id, so the client's own retry is discarded by the stream rather than enrolling the machine twice. That one is not finished: the duplicate survives it, and the issue says where the trail stops.
This commit is contained in:
@@ -816,6 +816,13 @@ func enrol(ctx context.Context, opts options) error {
|
||||
Fingerprint: firstNonEmpty(reply.Fingerprint, token.Fingerprint),
|
||||
Signer: firstNonEmpty2(reply.Signer, token.Signer),
|
||||
Password: reply.Password,
|
||||
// **Which bus this membership is for, said rather than left empty** (novox/hq
|
||||
// 04-ISSUES/146). The link refuses a membership that names another bus, and an empty name
|
||||
// is not this one's — so a node enrolled without it came up and reconnected for ever
|
||||
// against its own record: "this membership is for \"\", and the mesh's bus is nats". The
|
||||
// reply does not carry it because there is one bus and the host knows which (ADR 0131);
|
||||
// what was missing was writing that down where the link reads it.
|
||||
Transport: link.OnNATS,
|
||||
}
|
||||
if mine.Membership.Password == "" {
|
||||
// The mesh did not replace the token's secret, so it is still this node's broker
|
||||
|
||||
Reference in New Issue
Block a user