6 Commits

Author SHA1 Message Date
tes d27fd02866 Add third NATS user 'external-apps' for external application connections
Unrestricted admin (same shape as admin/volcanic-agents), password
delivered via Coolify env var NATS_EXTERNAL_APPS_PASSWORD. Doc updated
in both places that enumerate users. Plan file included for the record.
2026-08-26 16:22:45 +00:00
tes 2f14b6c40a Fix volcanic-agents user config: token → password
NATS's authorization.users entries don't accept a `token` field
(only `user+password`, `nkey`, or JWT). `token` at the top of the
authorization block is a single global token. NATS was crash-looping
with "unknown field 'token'" at line 20 col 32 of nats-server.conf.

Wire the NATS_VOLCANIC_AGENTS_TOKEN env var through the password
field instead. Env-var name stays the same — semantically the value
is still a bearer token, only the NATS field it's carried in changes.
CLAUDE.md and credentials.local.json updated accordingly.
2026-08-26 15:07:47 +00:00
tes 1b069c6682 Add volcanic-agents token user
Second entry in authorization.users with token auth, no permissions
block (so full admin). Token is supplied via NATS_VOLCANIC_AGENTS_TOKEN
Coolify env var and substituted into the inline config at compose parse
time. Local credentials.local.json (gitignored) holds the connection
details for both users.
2026-08-26 07:08:56 +00:00
tes 8d25c22fc6 Only expose 8080 so Traefik routes to WS, not NATS TCP 2026-08-25 10:08:45 +00:00
tes acd37942e9 Inline NATS config via docker-compose configs
Coolify's compose executor rewrites relative bind mounts to a persistent
app dir with no source file, causing docker to auto-create the mount
target as a directory and fail with "not a directory". Delivering the
config through configs.content instead avoids the rewrite entirely and
lets Docker Compose substitute NATS_USER/NATS_PASSWORD at parse time.
2026-08-25 10:07:05 +00:00
tes 49dcf78529 Add NATS-over-WebSocket compose for Coolify
Configures a single NATS 2.10 service exposing a WebSocket listener on
:8080 (no_tls; Traefik terminates TLS at nats.volcanic.tes.gd) with
env-driven username/password auth and a persisted JetStream store.
2026-08-25 09:37:57 +00:00