Announce only on the subjects the grants allow (hq ADR 0197)

Both runtimes subscribed $SRV.<verb>.> as a wildcard; the grants allow the bare question and the
service's own name and instance. The bus refused the wildcard, and the TypeScript runtime treats a
refused subscription as fatal, so every per-module container crash-looped after the image rolled.
They now subscribe exactly $SRV.<verb>, $SRV.<verb>.<name> and $SRV.<verb>.<name>.<id>.
This commit is contained in:
jochen
2026-10-03 22:31:02 +02:00
parent df4f492a72
commit f11ac6441c
2 changed files with 9 additions and 2 deletions
+3 -1
View File
@@ -158,7 +158,9 @@ func Serve(conn *bus.Conn, s Service, current func() []Endpoint) (func(), error)
} }
var stops []func() var stops []func()
for _, verb := range []string{"PING", "INFO", "STATS"} { for _, verb := range []string{"PING", "INFO", "STATS"} {
for _, subject := range []string{"$SRV." + verb, "$SRV." + verb + ".>"} { // Exactly the questions asked of every service and of this one by name and instance — what the
// grants allow (novox/hq ADR 0197). A wildcard is refused by the bus.
for _, subject := range []string{"$SRV." + verb, "$SRV." + verb + "." + s.Name, "$SRV." + verb + "." + s.Name + "." + s.ID} {
stop, err := conn.Raw(subject, answer) stop, err := conn.Raw(subject, answer)
if err != nil { if err != nil {
for _, st := range stops { for _, st := range stops {
+6 -1
View File
@@ -127,8 +127,13 @@ export function announce(broker: RuntimeBroker, s: Service, current: () => Endpo
return sc.encode(JSON.stringify(v)); return sc.encode(JSON.stringify(v));
}; };
const stops: (() => void)[] = []; const stops: (() => void)[] = [];
// Exactly the questions asked of every service and of this one by name and instance — what the
// grants allow (novox/hq ADR 0197). A wildcard is refused by the bus, and a refused subscription
// ends a runtime: on 2026-10-03 it crash-looped every container that announced itself.
for (const verb of ["PING", "INFO", "STATS"]) { for (const verb of ["PING", "INFO", "STATS"]) {
for (const subject of [`$SRV.${verb}`, `$SRV.${verb}.>`]) stops.push(broker.raw!(subject, (subj) => answer(subj))); for (const subject of [`$SRV.${verb}`, `$SRV.${verb}.${s.name}`, `$SRV.${verb}.${s.name}.${s.id}`]) {
stops.push(broker.raw!(subject, (subj) => answer(subj)));
}
} }
return () => stops.forEach((stop) => stop()); return () => stops.forEach((stop) => stop());
} }