Message bus
The Datasance PoT message bus is NATS. This section is how an Edgelet node joins it, and the two policy kinds the Controller signs into JWTs.
NATS must be enabled on the control plane before any of this works. See Control plane.
Mounting credentials into a container stays on NATS access. The system microservice on the node (system-<agentName>/nats, leaf config, upstream servers) stays on NATS fabric. The server binary and reload behavior stay on NATS Server.
Deploy rule documents with potctl deploy -f. There is no apply.
Pieces
| Piece | Role |
|---|---|
| Topology | natsMode on the Edgelet node: leaf, server, or none. The Controller creates the NATS system microservice, certificates, and upstream links. |
| Account rules | NatsAccountRule is account policy. An application binds it with spec.natsConfig.natsRule. The Controller signs an account JWT. |
| User rules | NatsUserRule is user policy. A microservice binds it with spec.natsConfig.natsRule. The Controller signs a user JWT. |
| NATS access | Workload access. Set natsConfig.natsAccess: true on the application, then on the microservice. Credentials, environment variables, and the resolver are on that page. |
Field tables are on Account rule fields and User rule fields.
The static NATS server authorization block (username, password, users) is a different mechanism. The Controller does not emit that block from these kinds.
Console
Live operators, accounts, and users are on Message bus.
Editing the rule objects is on Access control, under NATS Account Rules and NATS User Rules.
Inspect
After workloads with NATS access are deployed:
potctl get nats-accounts
potctl get nats-users
potctl describe nats-account ACCOUNT
potctl describe nats-user APP USER
potctl nats operator describe
| What you see | Where to look |
|---|---|
| No account or user row | The application or microservice does not set natsAccess, or it is not deployed. See NATS access. |
| Publish or subscribe denied | User rule allow and deny lists, and account imports and exports. |
| A rule edit is not visible yet | Update returns immediately. Affected JWTs are reissued in the background. See NATS lifecycle. |
Related
- Topology
- Account rules and User rules
- NATS access
- NATS fabric
- NATS Server
- NATS JWT authentication
- Tutorial: Account export