2f14b6c40a
NATS's authorization.users entries don't accept a `token` field (only `user+password`, `nkey`, or JWT). `token` at the top of the authorization block is a single global token. NATS was crash-looping with "unknown field 'token'" at line 20 col 32 of nats-server.conf. Wire the NATS_VOLCANIC_AGENTS_TOKEN env var through the password field instead. Env-var name stays the same — semantically the value is still a bearer token, only the NATS field it's carried in changes. CLAUDE.md and credentials.local.json updated accordingly.
49 lines
982 B
YAML
49 lines
982 B
YAML
services:
|
|
nats:
|
|
image: nats:2.10-alpine
|
|
restart: unless-stopped
|
|
command: ["-c", "/etc/nats/nats-server.conf"]
|
|
environment:
|
|
- SERVICE_FQDN_NATS_8080
|
|
configs:
|
|
- source: nats-conf
|
|
target: /etc/nats/nats-server.conf
|
|
volumes:
|
|
- nats-data:/data
|
|
expose:
|
|
- "8080"
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
|
|
configs:
|
|
nats-conf:
|
|
content: |
|
|
server_name: "nats-volcanic"
|
|
|
|
port: 4222
|
|
http_port: 8222
|
|
|
|
jetstream {
|
|
store_dir: "/data"
|
|
max_memory_store: 256MB
|
|
max_file_store: 4GB
|
|
}
|
|
|
|
websocket {
|
|
port: 8080
|
|
no_tls: true
|
|
}
|
|
|
|
authorization {
|
|
users = [
|
|
{ user: "${NATS_USER}", password: "${NATS_PASSWORD}" },
|
|
{ user: "volcanic-agents", password: "${NATS_VOLCANIC_AGENTS_TOKEN}" }
|
|
]
|
|
}
|
|
|
|
volumes:
|
|
nats-data:
|