Skip to main content
Version: v3.9.0

Message bus

The MessageBus group appears only when the Controller reports that NATS is enabled. If the group is missing, this cluster has no message-bus pages.

The pages show NATS operators, accounts, and users that the platform has issued. Application and microservice detail panels link to the NATS rules under Access control. Those rules are the policy. These pages are the issued credentials. See Message bus.

PageAddressPage heading
Operators/#/messagebus/operatorsNATS Operators
Accounts/#/messagebus/accountsNATS Accounts
Users/#/messagebus/usersNATS Users

Operators​

NATS operators

This page is not a table. It shows the operator the hub is using:

  • Operator name
  • Public Key
  • Operator JWT, a copyable block, with the decoded JWT claims
  • NATS Hub, the hub description as JSON

The YAML dropzone is on the page. Operator rotation is not offered in the console.

Accounts​

NATS accounts

ColumnWhat it shows
NameAccount name. Click to open the detail panel.
Public KeyAccount public key
Application IDApplication this account belongs to
SystemSystem account flag
Leaf SystemLeaf-system flag

Ensure Account By Application opens Ensure NATS Account:

  • Application Name, placeholder my-application
  • NATS Account Rule (optional)
  • Cancel or Ensure

Use this when an application should have a NATS account and you want the platform to create it from an account rule. Account rules are declared in NATS account rules.

The YAML dropzone accepts NATS account material the uploader knows how to deploy. Account-rule YAML is more often uploaded from Access Control. A successful upload there refreshes these lists when you have them open.

Account detail panel​

Account detail

The panel repeats Name, Public Key, Application ID, System, and Leaf System, then a JWT section you can copy.

The header icon on this panel is . Edit and Delete are not offered here. Account lifecycle goes through Ensure and through rule changes under Access Control.

Users​

NATS users

NATS users are loaded per application, because a cluster can have many of them. User policy is declared in NATS user rules.

Filters and buttons​

  • Applications (multi-select) for Load Users chooses which applications to query.
  • Scope toggles: All Apps, User Apps, System Apps.
  • Load Users fetches users for the current selection.
  • Refresh Data reloads.
  • Create User opens the create-user dialog.
  • Create MQTT Bearer opens the MQTT bearer dialog.
ColumnWhat it shows
ApplicationApplication name
NameUser name. Click to open the detail panel.
Public KeyUser public key
MQTT BearerWhether this user is an MQTT bearer
Microservice UUIDMicroservice this user is bound to, when it is a microservice user

Create dialogs​

Create user and create MQTT bearer ask for:

  • An application (picker, with the same app filters)
  • A name
  • expiresIn
  • natsRule, which NATS user rule to apply

User detail panel​

NATS user detail

Fields: Application, Name, Public Key, MQTT Bearer, then JWT.

Creds. Fetch Creds loads the credential file. Until you do, the panel says No creds loaded. The loaded creds are shown in a masked block.

Actions. Delete User, or Delete MQTT Bearer when the row is a bearer. Both ask you to confirm.

The YAML dropzone is on the list. The header icon on the detail panel is . Delete lives in the Actions section of the panel.

Group 3See anything wrong with the document? Help us improve it!