runtime: connect with a sealed, scoped credential over pinned amqps (ADR 0048) #2

Closed
jschoubben wants to merge 2 commits from events/module-credential into events/adr-0047-alignment
2 changed files with 10 additions and 2 deletions
Showing only changes of commit bf5339cec2 - Show all commits
+5 -2
View File
@@ -24,11 +24,14 @@ interface Reply {
error?: string;
}
/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL and the
* fingerprint of the certificate the broker must present. A plain string is a bootstrap URL. */
/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL, the fingerprint
* of the certificate the broker must present, and the node and module the account is scoped to (so
* the runtime names its queue as the mesh did). A plain string is a bootstrap URL. */
export interface Credential {
url: string;
fingerprint?: string;
node?: string;
module?: string;
}
/**
+5
View File
@@ -40,6 +40,11 @@ async function connectBroker(): Promise<Broker> {
console.error(`mesh-tools: ${file} carries no url — it is not a broker credential`);
process.exit(1);
}
// The mesh scoped this account to a node and module; take the runtime's identity from the
// credential so its queue and the events it emits match what the mesh authorised, no matter
// what the environment says.
if (credential.node) process.env.MESH_NODE = credential.node;
if (credential.module) process.env.MESH_MODULE = credential.module;
return connectAmqp(credential, { assumeExchanges: true });
}
const url = process.env.MESH_BROKER_URL;