Announce only on the subjects the grants allow (hq ADR 0197)
Both runtimes subscribed $SRV.<verb>.> as a wildcard; the grants allow the bare question and the service's own name and instance. The bus refused the wildcard, and the TypeScript runtime treats a refused subscription as fatal, so every per-module container crash-looped after the image rolled. They now subscribe exactly $SRV.<verb>, $SRV.<verb>.<name> and $SRV.<verb>.<name>.<id>.
This commit is contained in:
@@ -127,8 +127,13 @@ export function announce(broker: RuntimeBroker, s: Service, current: () => Endpo
|
||||
return sc.encode(JSON.stringify(v));
|
||||
};
|
||||
const stops: (() => void)[] = [];
|
||||
// Exactly the questions asked of every service and of this one by name and instance — what the
|
||||
// grants allow (novox/hq ADR 0197). A wildcard is refused by the bus, and a refused subscription
|
||||
// ends a runtime: on 2026-10-03 it crash-looped every container that announced itself.
|
||||
for (const verb of ["PING", "INFO", "STATS"]) {
|
||||
for (const subject of [`$SRV.${verb}`, `$SRV.${verb}.>`]) stops.push(broker.raw!(subject, (subj) => answer(subj)));
|
||||
for (const subject of [`$SRV.${verb}`, `$SRV.${verb}.${s.name}`, `$SRV.${verb}.${s.name}.${s.id}`]) {
|
||||
stops.push(broker.raw!(subject, (subj) => answer(subj)));
|
||||
}
|
||||
}
|
||||
return () => stops.forEach((stop) => stop());
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user