The tool runtime's client on NATS, behind the unchanged contract

Task 3.6 of novox/hq ADR 0116. A module is still written against request,
handle, publish, subscribe, close; only what is underneath changes. main.ts
still selects the AMQP client — steps 1 to 4 leave every node on AMQP, so
this ships beside it and is selected at the rollout.

Round-tripped against a real server (test/roundtrip.mjs): a tool answered
across two connections, a throwing handler reaching the caller as an error
rather than a timeout, an event delivered once with its key, body, node and
event id intact, and an event landing under its emitter's own namespace.

Three things the compiler and the server corrected:

- the envelope's field is `key`, not `type`, and the payload is `env.body`
  with metadata in headers — not the whole envelope re-encoded. An
  implementation that nested the envelope would pass all its own tests and
  agree with nobody, which is what the conformance suite exists to stop.
- the NATS client's TLS options are PEM strings with no verify hook, so the
  AMQP client's `checkServerIdentity: () => undefined` has no equivalent.
  The fingerprint check still happens and is still the guarantee, but the
  bus's certificate must now carry a SAN matching the address nodes dial.
  That is a constraint on the mesh's certificates, recorded where it bites.
- a durable consumer is bound, never created: a module's account cannot
  reach the JetStream API, and a runtime creating its own would be a module
  choosing its own delivery semantics.
This commit is contained in:
2026-09-26 23:29:17 +02:00
parent 6b380b67e0
commit c1517c39a0
3 changed files with 400 additions and 1 deletions
+2 -1
View File
@@ -12,7 +12,8 @@
},
"dependencies": {
"@novox/mesh-sdk": "^0.1.0",
"amqplib": "^0.10.9"
"amqplib": "^0.10.9",
"nats": "^2.29.0"
},
"devDependencies": {
"@types/amqplib": "^0.10.8",