Add third NATS user 'external-apps' for external application connections
Unrestricted admin (same shape as admin/volcanic-agents), password delivered via Coolify env var NATS_EXTERNAL_APPS_PASSWORD. Doc updated in both places that enumerate users. Plan file included for the record.
This commit is contained in:
@@ -15,10 +15,11 @@ Coolify's non-secret app config (project/server UUIDs, name, domain) lives in `d
|
||||
|
||||
## Connection details (for agents managing this NATS)
|
||||
|
||||
There are two users, both admin (unrestricted publish/subscribe):
|
||||
There are three users, all admin (unrestricted publish/subscribe):
|
||||
|
||||
- `admin` — env vars `NATS_USER` / `NATS_PASSWORD` on the Coolify application.
|
||||
- `volcanic-agents` — env var `NATS_VOLCANIC_AGENTS_TOKEN` on the Coolify application. Semantically a bearer token; on the wire it goes through NATS's `password` field (NATS has no per-user `token` field — that's only valid at the top of `authorization` as a single global token).
|
||||
- `external-apps` — env var `NATS_EXTERNAL_APPS_PASSWORD` on the Coolify application. Intended for third-party / external application connections. Password-style credential (random string, framed as a password rather than a bearer token). Unrestricted for now; scope down if we ever need to isolate external callers from internal traffic.
|
||||
|
||||
### Local credentials cache
|
||||
|
||||
@@ -110,7 +111,7 @@ asyncio.run(main())
|
||||
- `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`.
|
||||
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly.
|
||||
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
||||
- **Auth**: two users in `authorization.users` — `admin` (password from `NATS_PASSWORD`) and `volcanic-agents` (password from `NATS_VOLCANIC_AGENTS_TOKEN`, semantically a bearer token). Both are unrestricted (no `permissions` block → admin). Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
||||
- **Auth**: three users in `authorization.users` — `admin` (password from `NATS_PASSWORD`), `volcanic-agents` (password from `NATS_VOLCANIC_AGENTS_TOKEN`, semantically a bearer token), and `external-apps` (password from `NATS_EXTERNAL_APPS_PASSWORD`, for third-party callers). All three are unrestricted (no `permissions` block → admin). Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
||||
|
||||
## Managing / redeploying
|
||||
|
||||
|
||||
Reference in New Issue
Block a user