The monitoring account publishes check results and answers execute requests; the core account consumes both. The platform team declares the wiring on the accounts, and the auth controller signs it into both JWTs.

The exporting account #

A stream export and a service export. The service is private: only the accounts it names may import it.

01-exporter.yaml

# The monitoring account publishes check results as a stream and answers
# execute requests as a service. One export is public, one is private.
apiVersion: auth.nats.mikluko.io/v1beta1
kind: NatsAccount
metadata:
  name: monitoring
  namespace: nats-system
spec:
  operatorRef:
    name: demo
  exports:
    - name: check-results
      type: Stream
      subject: "monitoring.results.>"
      # Public (default): any account may import it.
    - name: execute
      type: Service
      subject: "monitoring.execute"
      responseType: Singleton   # Singleton (default) | Stream | Chunked
      # Private exports need an activation token per importer, signed
      # by this account. The auth controller mints one for each account named
      # here; an import from any other account is refused.
      access: Private
      importers:
        - kind: NatsAccount
          name: core
kubectl apply -f https://nats-operator.io/docs/stories/05-account-wiring/01-exporter.yaml

The importing account #

An import names the export it takes. The subject and type come from the exporting account, so the two sides cannot disagree.

01-importer.yaml

# The core account consumes both. An import names the export, not a subject.
apiVersion: auth.nats.mikluko.io/v1beta1
kind: NatsAccount
metadata:
  name: core
  namespace: nats-system
spec:
  operatorRef:
    name: demo
  imports:
    - accountRef:
        kind: NatsAccount
        name: monitoring   # cross-namespace needs a NatsReferenceGrant, as for users
      export: check-results
      # Where it appears in this account; defaults to the exported subject.
      localSubject: "upstream.results.>"
    - accountRef:
        kind: NatsAccount
        name: monitoring
      export: execute
kubectl apply -f https://nats-operator.io/docs/stories/05-account-wiring/01-importer.yaml

01-status-natsaccount-core.yaml

status:
  observedGeneration: 1
  conditions:
    - type: Ready
      status: "True"
      reason: Distributed
    - type: ReferencesResolved
      status: "True"
      reason: AllImportsResolved
  imports:
    - export: monitoring/check-results
      subject: "monitoring.results.>"
      localSubject: "upstream.results.>"
      type: Stream
    - export: monitoring/execute
      subject: "monitoring.execute"
      type: Service
      activation: Signed   # minted from monitoring's importers list
  distribution:
    servers: 3
    current: 3