The monitoring account publishes check results and answers execute requests; the core account consumes both. The platform team declares the wiring on the accounts, and the auth controller signs it into both JWTs.
The exporting account #
A stream export and a service export. The service is private: only the accounts it names may import it.
01-exporter.yaml
# The monitoring account publishes check results as a stream and answers
# execute requests as a service. One export is public, one is private.
apiVersion: auth.nats.mikluko.io/v1beta1
kind: NatsAccount
metadata:
name: monitoring
namespace: nats-system
spec:
operatorRef:
name: demo
exports:
- name: check-results
type: Stream
subject: "monitoring.results.>"
# Public (default): any account may import it.
- name: execute
type: Service
subject: "monitoring.execute"
responseType: Singleton # Singleton (default) | Stream | Chunked
# Private exports need an activation token per importer, signed
# by this account. The auth controller mints one for each account named
# here; an import from any other account is refused.
access: Private
importers:
- kind: NatsAccount
name: core
kubectl apply -f https://nats-operator.io/docs/stories/05-account-wiring/01-exporter.yamlThe importing account #
An import names the export it takes. The subject and type come from the exporting account, so the two sides cannot disagree.
01-importer.yaml
# The core account consumes both. An import names the export, not a subject.
apiVersion: auth.nats.mikluko.io/v1beta1
kind: NatsAccount
metadata:
name: core
namespace: nats-system
spec:
operatorRef:
name: demo
imports:
- accountRef:
kind: NatsAccount
name: monitoring # cross-namespace needs a NatsReferenceGrant, as for users
export: check-results
# Where it appears in this account; defaults to the exported subject.
localSubject: "upstream.results.>"
- accountRef:
kind: NatsAccount
name: monitoring
export: execute
kubectl apply -f https://nats-operator.io/docs/stories/05-account-wiring/01-importer.yaml01-status-natsaccount-core.yaml
status:
observedGeneration: 1
conditions:
- type: Ready
status: "True"
reason: Distributed
- type: ReferencesResolved
status: "True"
reason: AllImportsResolved
imports:
- export: monitoring/check-results
subject: "monitoring.results.>"
localSubject: "upstream.results.>"
type: Stream
- export: monitoring/execute
subject: "monitoring.execute"
type: Service
activation: Signed # minted from monitoring's importers list
distribution:
servers: 3
current: 3