Unrestricted admin (same shape as admin/volcanic-agents), password
delivered via Coolify env var NATS_EXTERNAL_APPS_PASSWORD. Doc updated
in both places that enumerate users. Plan file included for the record.
NATS's authorization.users entries don't accept a `token` field
(only `user+password`, `nkey`, or JWT). `token` at the top of the
authorization block is a single global token. NATS was crash-looping
with "unknown field 'token'" at line 20 col 32 of nats-server.conf.
Wire the NATS_VOLCANIC_AGENTS_TOKEN env var through the password
field instead. Env-var name stays the same — semantically the value
is still a bearer token, only the NATS field it's carried in changes.
CLAUDE.md and credentials.local.json updated accordingly.
Coolify's compose executor rewrites relative bind mounts to a persistent
app dir with no source file, causing docker to auto-create the mount
target as a directory and fail with "not a directory". Delivering the
config through configs.content instead avoids the rewrite entirely and
lets Docker Compose substitute NATS_USER/NATS_PASSWORD at parse time.
Configures a single NATS 2.10 service exposing a WebSocket listener on
:8080 (no_tls; Traefik terminates TLS at nats.volcanic.tes.gd) with
env-driven username/password auth and a persisted JetStream store.