Commit Graph

14 Commits

Author SHA1 Message Date
tes 9e1c097f2e Document two Coolify gotchas hit while adding the external-apps user
- docker_compose_domains regresses to defaults on some deploys because
  the stored value lacks the 'name' field; recovery is a PATCH with the
  array form followed by a redeploy.
- The 'nats' npm package cannot connect over wss:// from Node; use
  'nats.ws' + 'ws' polyfill instead.
2026-08-26 18:09:57 +00:00
tes d27fd02866 Add third NATS user 'external-apps' for external application connections
Unrestricted admin (same shape as admin/volcanic-agents), password
delivered via Coolify env var NATS_EXTERNAL_APPS_PASSWORD. Doc updated
in both places that enumerate users. Plan file included for the record.
2026-08-26 16:22:45 +00:00
tes 84ed07fdec Add design doc for NATS external-apps user 2026-08-26 16:05:44 +00:00
tes c1573a2b95 Document NATS per-user token gotcha and Coolify deploy-status vs runtime-health distinction 2026-08-26 15:19:21 +00:00
tes 2f14b6c40a Fix volcanic-agents user config: token → password
NATS's authorization.users entries don't accept a `token` field
(only `user+password`, `nkey`, or JWT). `token` at the top of the
authorization block is a single global token. NATS was crash-looping
with "unknown field 'token'" at line 20 col 32 of nats-server.conf.

Wire the NATS_VOLCANIC_AGENTS_TOKEN env var through the password
field instead. Env-var name stays the same — semantically the value
is still a bearer token, only the NATS field it's carried in changes.
CLAUDE.md and credentials.local.json updated accordingly.
2026-08-26 15:07:47 +00:00
tes 6d91fdbfb1 Document volcanic-agents user and local credentials cache in CLAUDE.md 2026-08-26 07:12:09 +00:00
tes 1b069c6682 Add volcanic-agents token user
Second entry in authorization.users with token auth, no permissions
block (so full admin). Token is supplied via NATS_VOLCANIC_AGENTS_TOKEN
Coolify env var and substituted into the inline config at compose parse
time. Local credentials.local.json (gitignored) holds the connection
details for both users.
2026-08-26 07:08:56 +00:00
tes 69033acd74 Add C# NATS-over-WebSocket example (core + JetStream replay) 2026-08-25 14:43:55 +00:00
tes 1f42637fcf Add nats.ws smoke test (connect, pub/sub, req/rep, JetStream) 2026-08-25 10:39:22 +00:00
tes 8d25c22fc6 Only expose 8080 so Traefik routes to WS, not NATS TCP 2026-08-25 10:08:45 +00:00
tes acd37942e9 Inline NATS config via docker-compose configs
Coolify's compose executor rewrites relative bind mounts to a persistent
app dir with no source file, causing docker to auto-create the mount
target as a directory and fail with "not a directory". Delivering the
config through configs.content instead avoids the rewrite entirely and
lets Docker Compose substitute NATS_USER/NATS_PASSWORD at parse time.
2026-08-25 10:07:05 +00:00
tes f9a999d6bd Change public WS domain to nats.tes.gd 2026-08-25 09:42:11 +00:00
tes 49dcf78529 Add NATS-over-WebSocket compose for Coolify
Configures a single NATS 2.10 service exposing a WebSocket listener on
:8080 (no_tls; Traefik terminates TLS at nats.volcanic.tes.gd) with
env-driven username/password auth and a persisted JetStream store.
2026-08-25 09:37:57 +00:00
tes 964e506eb2 Initial commit 2026-08-25 08:56:26 +00:00