novox/hq issue 146, the layers behind the three already merged.
A new membership says which bus it is for. Empty meant whatever the mesh runs today while two buses existed, and became a refusal the moment one did — an enrolled node came up and reconnected for ever against its own record: this membership is for "", and the mesh's bus is nats.
The enrolling client takes its inboxes where its user may listen. A JetStream publish waits for the stream's acknowledgement on an inbox the client picks, and its default is _INBOX.<random>, which this user may not subscribe to — so the enrolment failed with a permissions violation on a subject nobody had chosen. The permission is _INBOX.enrol.<node>.>, so the client is told to pick its inboxes there.
And the publish carries a message id derived from its own bytes, so the client's own retry is discarded by the stream rather than enrolling the machine twice. That one is not finished — the duplicate survives it. What it costs is in the issue: each enrolment mints a credential, and the machine keeps the answer to the first while the mesh keeps the second.
novox/hq [issue 146](https://git.novox.be/novox/hq), the layers behind the three already merged.
**A new membership says which bus it is for.** Empty meant *whatever the mesh runs today* while two buses existed, and became a refusal the moment one did — an enrolled node came up and reconnected for ever against its own record: *this membership is for "", and the mesh's bus is nats*.
**The enrolling client takes its inboxes where its user may listen.** A JetStream publish waits for the stream's acknowledgement on an inbox the client picks, and its default is `_INBOX.<random>`, which this user may not subscribe to — so the enrolment failed with a permissions violation on a subject nobody had chosen. The permission is `_INBOX.enrol.<node>.>`, so the client is told to pick its inboxes there.
**And the publish carries a message id** derived from its own bytes, so the client's own retry is discarded by the stream rather than enrolling the machine twice. *That one is not finished* — the duplicate survives it. What it costs is in the issue: each enrolment mints a credential, and the machine keeps the answer to the first while the mesh keeps the second.
novox/hq 04-ISSUES/146, the layers behind the three already fixed.
A new membership says which bus it is for. Empty meant 'whatever the mesh runs
today' while two buses existed, and became a refusal the moment one did: an
enrolled node came up and reconnected for ever against its own record.
The enrolling client takes its inboxes in the space its user may listen in. A
JetStream publish waits for the stream's acknowledgement on an inbox the client
picks, and its default is one this user may not subscribe to — so the enrolment
failed with a permissions violation on a subject nobody had chosen.
And the enrolment publish carries a message id, so the client's own retry is
discarded by the stream rather than enrolling the machine twice. That one is
not finished: the duplicate survives it, and the issue says where the trail
stops.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
novox/hq issue 146, the layers behind the three already merged.
A new membership says which bus it is for. Empty meant whatever the mesh runs today while two buses existed, and became a refusal the moment one did — an enrolled node came up and reconnected for ever against its own record: this membership is for "", and the mesh's bus is nats.
The enrolling client takes its inboxes where its user may listen. A JetStream publish waits for the stream's acknowledgement on an inbox the client picks, and its default is
_INBOX.<random>, which this user may not subscribe to — so the enrolment failed with a permissions violation on a subject nobody had chosen. The permission is_INBOX.enrol.<node>.>, so the client is told to pick its inboxes there.And the publish carries a message id derived from its own bytes, so the client's own retry is discarded by the stream rather than enrolling the machine twice. That one is not finished — the duplicate survives it. What it costs is in the issue: each enrolment mints a credential, and the machine keeps the answer to the first while the mesh keeps the second.