Expand description
Canonical names, topology limits, and allow-only grants for the NATS plane.
Structs§
- Account
Names - Account-derived names. Derivation never normalizes input.
- Allow
Entry - One permission entry. The model intentionally has no deny variant.
- Bucket
Names - The census KV bucket and its JetStream backing stream.
- Consumer
Spec - Golden
Fixture - Naming
Error - A token that cannot be interpolated without changing or broadening identity.
- Permission
Document - Refused
Entry - Stream
Names - All six stream names owned by one account.
- Stream
Spec - Tenancy
Name Error
Enums§
- Discard
Policy - Grant
Error - Limit
Error - Naming
Exemption - Namespaces that are deliberately outside the account-token rule.
- Naming
Rule - Operation
- Principal
- Root
Credential Kind - Families of root keys the operator creates once in the vault by ceremony
(
ck auth mint-signing-key --id signing:<provider>[:<generation>]). - Stream
Kind - Token
Kind - The identity field being interpolated into a NATS name.
Constants§
- CLOSED_
NAMING_ EXEMPTIONS - The exemption list is closed and deliberately exposed for exhaustive tests.
- GIB
- HOUR
- MIB
- PINNED_
GOLDEN_ FIXTURE
Functions§
- bus_
permissions - delivery_
authority_ permissions - The grant for the delivery authority, prefrontal-core alone.
- flow_
engine_ permissions - The grant for the flow engine (basal), issued by its attested module id.
- generate_
permission_ golden - participant_
permissions - The grant for every host and module except the delivery authority.
- root_
credential_ id - The vault credential id of a root key:
<kind>:<provider>[:<generation>], for examplesigning:ck-bus-account:1orsigning:msgsig. - shipped_
streams - Returns the six normative stream configurations for an account.
- system_
permissions - The system user’s grant. It publishes claims updates, per-account claims
lookups (
$SYS.REQ.ACCOUNT.<account>.CLAIMS.LOOKUP, which the revocation check reads back) and the claims list ($SYS.REQ.CLAIMS.LIST, which finds an existing account by name when its id was not recorded, so a lost state file adopts the account instead of creating a second one), kicks, and watches connects; replies to its requests arrive on its own credential-scoped inbox. - validate_
account_ token - Validates the account-only lexicon
[a-z0-9][a-z0-9_]{0,62}. - validate_
consumer - Rejects a consumer filter unless every subject it can match is in its stream.
- validate_
event_ version - Parses the version token of an event subject,
v{n}withn >= 1. - validate_
permission_ file - Validates the checked-in line format and its allow-only, whole-token contract.
- validate_
store_ retention - Enforces that the owning store keeps a body at least as long as its stream.
- validate_
streams - Rejects duplicate streams, malformed filters, and every pair of overlapping filters.
- validate_
tenancy_ name - Checks the account-token rule for one emitted name or a named exemption.
- validate_
token - Validates the shared identity lexicon
[a-z0-9][a-z0-9_-]{0,62}.