A machine moves to the bus its declaration tells it to
Until now a membership — bus address, fingerprint, password — was written once, at enrolment, and nothing ever rewrote it, so a machine already enrolled could not be moved to another bus at all (novox/hq design 28, task 5.2). The mesh now delivers a membership for the new bus as a sealed file in the declaration, like any secret; the host reads it after the declaration has applied, saves it as its identity, and exits cleanly so the service manager restarts it dialling the bus it names. The same path a machine takes after a reboot — so nothing new has to be right for it to work. A membership carries its transport; empty means the bus the mesh ran on before, so nothing written earlier reads as unset.
This commit is contained in:
@@ -76,6 +76,11 @@ type Membership struct {
|
||||
// Not the token's secret: that is spent, and a credential that lives for ever should not be
|
||||
// the same string as one that was meant to be used once.
|
||||
Password string `json:"password"`
|
||||
|
||||
// Transport is which bus this membership is for. Empty is the bus the mesh ran on before
|
||||
// the move — so every membership written before this field existed reads as correct, not as
|
||||
// unset — and "nats" is the one being moved to (novox/hq design 28, task 5.2).
|
||||
Transport string `json:"transport,omitempty"`
|
||||
}
|
||||
|
||||
// Queue is where this node listens. Its account may read this and nothing else.
|
||||
|
||||
Reference in New Issue
Block a user