Fix volcanic-agents user config: token → password
NATS's authorization.users entries don't accept a `token` field (only `user+password`, `nkey`, or JWT). `token` at the top of the authorization block is a single global token. NATS was crash-looping with "unknown field 'token'" at line 20 col 32 of nats-server.conf. Wire the NATS_VOLCANIC_AGENTS_TOKEN env var through the password field instead. Env-var name stays the same — semantically the value is still a bearer token, only the NATS field it's carried in changes. CLAUDE.md and credentials.local.json updated accordingly.
This commit is contained in:
@@ -17,8 +17,8 @@ Coolify's non-secret app config (project/server UUIDs, name, domain) lives in `d
|
|||||||
|
|
||||||
There are two users, both admin (unrestricted publish/subscribe):
|
There are two users, both admin (unrestricted publish/subscribe):
|
||||||
|
|
||||||
- `admin` — user/password auth. Env vars `NATS_USER` / `NATS_PASSWORD` on the Coolify application.
|
- `admin` — env vars `NATS_USER` / `NATS_PASSWORD` on the Coolify application.
|
||||||
- `volcanic-agents` — token auth. Env var `NATS_VOLCANIC_AGENTS_TOKEN` on the Coolify application.
|
- `volcanic-agents` — env var `NATS_VOLCANIC_AGENTS_TOKEN` on the Coolify application. Semantically a bearer token; on the wire it goes through NATS's `password` field (NATS has no per-user `token` field — that's only valid at the top of `authorization` as a single global token).
|
||||||
|
|
||||||
### Local credentials cache
|
### Local credentials cache
|
||||||
|
|
||||||
@@ -29,12 +29,12 @@ A **gitignored** `credentials.local.json` at the repo root mirrors the live valu
|
|||||||
"url": "wss://nats.tes.gd",
|
"url": "wss://nats.tes.gd",
|
||||||
"users": {
|
"users": {
|
||||||
"admin": { "user": "…", "password": "…", "note": "…" },
|
"admin": { "user": "…", "password": "…", "note": "…" },
|
||||||
"volcanic-agents": { "user": "volcanic-agents", "token": "…", "note": "…" }
|
"volcanic-agents": { "user": "volcanic-agents", "password": "…", "note": "…" }
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
Read from it with `jq`, e.g. `jq -r '.users["volcanic-agents"].token' credentials.local.json`. It is **not** the source of truth — Coolify env vars are. Regenerate it from Coolify with the snippet below if it's stale or missing.
|
Read from it with `jq`, e.g. `jq -r '.users["volcanic-agents"].password' credentials.local.json`. It is **not** the source of truth — Coolify env vars are. Regenerate it from Coolify with the snippet below if it's stale or missing.
|
||||||
|
|
||||||
The current live values are printed by:
|
The current live values are printed by:
|
||||||
|
|
||||||
@@ -110,7 +110,7 @@ asyncio.run(main())
|
|||||||
- `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`.
|
- `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`.
|
||||||
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly.
|
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly.
|
||||||
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
||||||
- **Auth**: two users in `authorization.users` — `admin` (user/password from `NATS_USER` / `NATS_PASSWORD`) and `volcanic-agents` (token from `NATS_VOLCANIC_AGENTS_TOKEN`). Both are unrestricted (no `permissions` block → admin). Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
- **Auth**: two users in `authorization.users` — `admin` (password from `NATS_PASSWORD`) and `volcanic-agents` (password from `NATS_VOLCANIC_AGENTS_TOKEN`, semantically a bearer token). Both are unrestricted (no `permissions` block → admin). Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
||||||
|
|
||||||
## Managing / redeploying
|
## Managing / redeploying
|
||||||
|
|
||||||
@@ -135,4 +135,4 @@ To add a second user (e.g. a scoped app account), edit the `authorization.users`
|
|||||||
| `docker-compose.yml` | Single `nats` service, exposes 4222/8080/8222 internally; only 8080 is routed publicly via `SERVICE_FQDN_NATS_8080` + Coolify's `docker_compose_domains`. The NATS config lives inline under `configs.nats-conf.content` (delivered to the container as `/etc/nats/nats-server.conf`) — no separate config file, no bind mount (Coolify's compose executor rewrites relative host paths into a persistent app dir and can't materialise a source file for them). |
|
| `docker-compose.yml` | Single `nats` service, exposes 4222/8080/8222 internally; only 8080 is routed publicly via `SERVICE_FQDN_NATS_8080` + Coolify's `docker_compose_domains`. The NATS config lives inline under `configs.nats-conf.content` (delivered to the container as `/etc/nats/nats-server.conf`) — no separate config file, no bind mount (Coolify's compose executor rewrites relative host paths into a persistent app dir and can't materialise a source file for them). |
|
||||||
| `.gitignore` | Keeps `deploy.json` and `credentials.local.json` out of git. |
|
| `.gitignore` | Keeps `deploy.json` and `credentials.local.json` out of git. |
|
||||||
| `deploy.json` (local only) | Coolify app config used by the `deploying-to-coolify-via-api` skill. |
|
| `deploy.json` (local only) | Coolify app config used by the `deploying-to-coolify-via-api` skill. |
|
||||||
| `credentials.local.json` (local only) | Cached NATS connection details for both users (WS URL, admin user/password, volcanic-agents token). Mirrors the Coolify env vars; regenerate from the API if stale. |
|
| `credentials.local.json` (local only) | Cached NATS connection details for both users (WS URL, admin user/password, volcanic-agents user/password-that-is-a-token). Mirrors the Coolify env vars; regenerate from the API if stale. |
|
||||||
|
|||||||
+1
-1
@@ -40,7 +40,7 @@ configs:
|
|||||||
authorization {
|
authorization {
|
||||||
users = [
|
users = [
|
||||||
{ user: "${NATS_USER}", password: "${NATS_PASSWORD}" },
|
{ user: "${NATS_USER}", password: "${NATS_PASSWORD}" },
|
||||||
{ user: "volcanic-agents", token: "${NATS_VOLCANIC_AGENTS_TOKEN}" }
|
{ user: "volcanic-agents", password: "${NATS_VOLCANIC_AGENTS_TOKEN}" }
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user