Skip to main content

Crate cortexkit_bus_naming

Crate cortexkit_bus_naming 

Source
Expand description

Canonical names, topology limits, and allow-only grants for the NATS plane.

Structs§

AccountNames
Account-derived names. Derivation never normalizes input.
AllowEntry
One permission entry. The model intentionally has no deny variant.
BucketNames
The census KV bucket and its JetStream backing stream.
ConsumerSpec
GoldenFixture
NamingError
A token that cannot be interpolated without changing or broadening identity.
PermissionDocument
RefusedEntry
StreamNames
All six stream names owned by one account.
StreamSpec
TenancyNameError

Enums§

DiscardPolicy
GrantError
LimitError
NamingExemption
Namespaces that are deliberately outside the account-token rule.
NamingRule
Operation
Principal
RootCredentialKind
Families of root keys the operator creates once in the vault by ceremony (ck auth mint-signing-key --id signing:<provider>[:<generation>]).
StreamKind
TokenKind
The identity field being interpolated into a NATS name.

Constants§

CLOSED_NAMING_EXEMPTIONS
The exemption list is closed and deliberately exposed for exhaustive tests.
GIB
HOUR
MIB
PINNED_GOLDEN_FIXTURE

Functions§

bus_permissions
delivery_authority_permissions
The grant for the delivery authority, prefrontal-core alone.
flow_engine_permissions
The grant for the flow engine (basal), issued by its attested module id.
generate_permission_golden
participant_permissions
The grant for every host and module except the delivery authority.
root_credential_id
The vault credential id of a root key: <kind>:<provider>[:<generation>], for example signing:ck-bus-account:1 or signing:msgsig.
shipped_streams
Returns the six normative stream configurations for an account.
system_permissions
The system user’s grant. It publishes claims updates, per-account claims lookups ($SYS.REQ.ACCOUNT.<account>.CLAIMS.LOOKUP, which the revocation check reads back) and the claims list ($SYS.REQ.CLAIMS.LIST, which finds an existing account by name when its id was not recorded, so a lost state file adopts the account instead of creating a second one), kicks, and watches connects; replies to its requests arrive on its own credential-scoped inbox.
validate_account_token
Validates the account-only lexicon [a-z0-9][a-z0-9_]{0,62}.
validate_consumer
Rejects a consumer filter unless every subject it can match is in its stream.
validate_event_version
Parses the version token of an event subject, v{n} with n >= 1.
validate_permission_file
Validates the checked-in line format and its allow-only, whole-token contract.
validate_store_retention
Enforces that the owning store keeps a body at least as long as its stream.
validate_streams
Rejects duplicate streams, malformed filters, and every pair of overlapping filters.
validate_tenancy_name
Checks the account-token rule for one emitted name or a named exemption.
validate_token
Validates the shared identity lexicon [a-z0-9][a-z0-9_-]{0,62}.