Each controller takes every reply under its own preset’s inbox, _INBOX.cluster-controller.>, _INBOX.auth-controller.>, _INBOX.jetstream-controller.>, and each controller preset allows its own inbox and no other. In a subject, * is one token the controller fills in, such as a server ID, an account public key, or a stream or consumer name.

Cluster controller #

Connects as the system account user a NatsCluster names in auth.systemCredentials. Preset: cluster-controller.

SubjectUseCode
$SYS.REQ.SERVER.PING.STATSZLists the servers of the NATS cluster.internal/sysobs
$SYS.REQ.SERVER.PING.JSZReads every account’s streams, consumers and the meta group, for Settled.internal/sysobs
$SYS.REQ.SERVER.PING.GATEWAYZReads each server’s gateway connections, for GatewaysConnected.internal/sysobs
$SYS.REQ.SERVER.PING.LEAFZReads each server’s leaf connections, for LeafnodesConnected.internal/sysobs
$SYS.REQ.SERVER.*.VARZReads the configuration a server has loaded, by server ID.internal/sysobs
$SYS.REQ.SERVER.*.RELOADReloads a server’s configuration, by server ID.internal/sysobs
$JS.API.SERVER.EVACUATEMoves a server’s JetStream assets off it before it is removed.internal/sysobs
$JS.API.META.LEADER.STEPDOWNMoves the meta leader off a server being removed.internal/sysobs
$JS.API.SERVER.REMOVERemoves a server from the JetStream meta group.internal/sysobs

Auth controller #

Connects through the NatsConnection its --system-connection flag names, as a user of a NatsOperator’s system account. Preset: auth-controller.

SubjectUseCode
$SYS.REQ.SERVER.PING.STATSZLists the servers that should answer the requests below.internal/authctl
$SYS.REQ.CLAIMS.UPDATEPushes an account JWT to every resolver.internal/authctl
$SYS.REQ.CLAIMS.DELETEDeletes accounts from every Full resolver.internal/authctl
$SYS.REQ.ACCOUNT.*.CLAIMS.LOOKUPReads the JWT the resolvers hold for an account, by account public key.internal/authctl
$SYS.REQ.SERVER.PING.CONNZFinds a revoked user’s connections.internal/authctl
$SYS.REQ.SERVER.*.KICKDisconnects one of them, by server ID.internal/authctl

JetStream controller, as a system account user #

Connects through the NatsConnection a NatsSystemBalancer or NatsClusterEvacuation names in connectionRef, as a system account user. Preset: jetstream-controller.

SubjectUseCode
$SYS.REQ.SERVER.PING.STATSZLists the servers of the NATS cluster and their tags.internal/sysobs
$SYS.REQ.SERVER.PING.JSZReads every account’s streams and consumers, with their leaders and replicas, and asks the meta leader which servers it counts offline, for a NatsClusterEvacuation.internal/sysobs, internal/balancectl
$SYS.REQ.SERVER.*.JSZAsks the server a balancer’s connection reaches, by server ID, whether it is in the same NATS system as a NatsClusterEvacuation’s connection.internal/balancectl
acc.*.$JS.API.STREAM.LEADER.STEPDOWN.*Moves a stream leader through the account’s jetstream-stepdown export, and probes whether the system account imports it.internal/balance, internal/balancectl
acc.*.$JS.API.CONSUMER.LEADER.STEPDOWN.*.*Moves a consumer leader the same way.internal/balance, internal/balancectl
$JS.API.ACCOUNT.STREAM.MOVE.*.*Moves a stream’s copies off a server, or onto servers carrying an evacuation’s tags.internal/balance
$JS.API.ACCOUNT.STREAM.CANCEL_MOVE.*.*Rolls back the moves in progress when an unfinished NatsClusterEvacuation is deleted.internal/balance

JetStream controller, as an account user #

Connects through the NatsConnection a NatsStream, NatsConsumer, NatsKeyValue, NatsObjectStore or NatsBalancer names in connectionRef, as a user of the account that owns the resources. No preset grants these subjects: the user’s permissions must allow them and a subscription to _INBOX.jetstream-controller.>, or the user sets none.

SubjectUseCode
$JS.API.STREAM.INFO.*Reads a stream, or the stream behind a bucket.internal/lifecycle
$JS.API.STREAM.CREATE.*Creates a NatsStream’s stream.internal/lifecycle
$JS.API.STREAM.UPDATE.*Updates it.internal/lifecycle
$JS.API.STREAM.DELETE.*Deletes it.internal/lifecycle
$JS.API.CONSUMER.INFO.*.*Reads a consumer.internal/lifecycle
$JS.API.CONSUMER.CREATE.*.*Creates or updates a NatsConsumer’s consumer.internal/lifecycle
$JS.API.CONSUMER.DELETE.*.*Deletes it.internal/lifecycle
$JS.API.CONSUMER.LIST.*Lists a NatsStream’s consumers while its stream moves to another NATS cluster.internal/streamctl
$JS.API.INFOReads the account’s JetStream limits before a key-value bucket is created or updated.nats.go jetstream
$JS.API.STREAM.CREATE.*Creates the stream behind a NatsKeyValue or NatsObjectStore.nats.go jetstream
$JS.API.STREAM.UPDATE.*Updates it.nats.go jetstream
$JS.API.STREAM.DELETE.*Deletes it.nats.go jetstream
$SYS.REQ.USER.INFOReads the account a NatsBalancer’s connection belongs to.internal/balancectl
$JS.API.STREAM.LISTLists the account’s streams, for a NatsBalancer.nats.go jetstream
$JS.API.STREAM.INFO.*Reads a stream, for a NatsBalancer.nats.go jetstream
$JS.API.CONSUMER.LIST.*Lists a stream’s consumers, for a NatsBalancer.nats.go jetstream
$JS.API.STREAM.LEADER.STEPDOWN.*Moves a stream leader, for a NatsBalancer.internal/balance
$JS.API.CONSUMER.LEADER.STEPDOWN.*.*Moves a consumer leader, for a NatsBalancer.internal/balance
$JS.API.ACCOUNT.STREAM.MOVE.*.*Moves a stream’s copies off a server, for a NatsBalancer.internal/balance

User presets #

A NatsUser with spec.preset gets exactly these claims, and sets neither spec.permissions nor spec.connectionTypes.

auth-controller #

For a system account user.

Publish: $SYS.REQ.CLAIMS.UPDATE, $SYS.REQ.CLAIMS.DELETE, $SYS.REQ.ACCOUNT.*.CLAIMS.LOOKUP, $SYS.REQ.SERVER.PING.STATSZ, $SYS.REQ.SERVER.PING.CONNZ, $SYS.REQ.SERVER.*.KICK.

Subscribe: _INBOX.auth-controller.>.

cluster-controller #

For a system account user.

Publish: $SYS.REQ.SERVER.PING.STATSZ, $SYS.REQ.SERVER.PING.JSZ, $SYS.REQ.SERVER.PING.GATEWAYZ, $SYS.REQ.SERVER.PING.LEAFZ, $SYS.REQ.SERVER.*.VARZ, $SYS.REQ.SERVER.*.RELOAD, $JS.API.SERVER.EVACUATE, $JS.API.SERVER.REMOVE, $JS.API.META.LEADER.STEPDOWN.

Subscribe: _INBOX.cluster-controller.>.

jetstream-controller #

For a system account user.

Publish: $SYS.REQ.SERVER.PING.STATSZ, $SYS.REQ.SERVER.PING.JSZ, $SYS.REQ.SERVER.*.JSZ, $JS.API.ACCOUNT.STREAM.MOVE.*.*, $JS.API.ACCOUNT.STREAM.CANCEL_MOVE.*.*, acc.*.$JS.API.STREAM.LEADER.STEPDOWN.*, acc.*.$JS.API.CONSUMER.LEADER.STEPDOWN.*.*.

Subscribe: _INBOX.jetstream-controller.>.

leafnode #

For a user of any account.

Publish: unrestricted.

Subscribe: unrestricted.

Connection types: LEAFNODE.

readonly #

For a user of an ordinary account.

Publish: $JS.API.INFO, $JS.API.STREAM.NAMES, $JS.API.STREAM.LIST, $JS.API.STREAM.INFO.*, $JS.API.CONSUMER.NAMES.*, $JS.API.CONSUMER.LIST.*, $JS.API.CONSUMER.INFO.*.*.

Subscribe: _INBOX.readonly.>.

Export preset #

jetstream-stepdown #

A NatsAccount export with preset: jetstream-stepdown expands to these service exports, and the auth controller adds the matching import to the system account of the NatsOperator that signs the account, prefixed with acc.<account public key>..

ExportSubjectSystem account imports it as
jetstream-stepdown-stream$JS.API.STREAM.LEADER.STEPDOWN.*acc.*.$JS.API.STREAM.LEADER.STEPDOWN.*
jetstream-stepdown-consumer$JS.API.CONSUMER.LEADER.STEPDOWN.*.*acc.*.$JS.API.CONSUMER.LEADER.STEPDOWN.*.*