Skip to main content
Version: v3.9.0

Message bus

The Datasance PoT message bus is NATS. This section is how an Edgelet node joins it, and the two policy kinds the Controller signs into JWTs.

NATS must be enabled on the control plane before any of this works. See Control plane.

Mounting credentials into a container stays on NATS access. The system microservice on the node (system-<agentName>/nats, leaf config, upstream servers) stays on NATS fabric. The server binary and reload behavior stay on NATS Server.

Deploy rule documents with potctl deploy -f. There is no apply.

Pieces​

PieceRole
TopologynatsMode on the Edgelet node: leaf, server, or none. The Controller creates the NATS system microservice, certificates, and upstream links.
Account rulesNatsAccountRule is account policy. An application binds it with spec.natsConfig.natsRule. The Controller signs an account JWT.
User rulesNatsUserRule is user policy. A microservice binds it with spec.natsConfig.natsRule. The Controller signs a user JWT.
NATS accessWorkload access. Set natsConfig.natsAccess: true on the application, then on the microservice. Credentials, environment variables, and the resolver are on that page.

Field tables are on Account rule fields and User rule fields.

The static NATS server authorization block (username, password, users) is a different mechanism. The Controller does not emit that block from these kinds.

Console​

Live operators, accounts, and users are on Message bus.

Editing the rule objects is on Access control, under NATS Account Rules and NATS User Rules.

Inspect​

After workloads with NATS access are deployed:

potctl get nats-accounts
potctl get nats-users
potctl describe nats-account ACCOUNT
potctl describe nats-user APP USER
potctl nats operator describe
What you seeWhere to look
No account or user rowThe application or microservice does not set natsAccess, or it is not deployed. See NATS access.
Publish or subscribe deniedUser rule allow and deny lists, and account imports and exports.
A rule edit is not visible yetUpdate returns immediately. Affected JWTs are reissued in the background. See NATS lifecycle.
Group 3See anything wrong with the document? Help us improve it!