feat(mesh): NATS token auth (WARDEN_NATS_TOKEN) for token-mode servers #13

Merged
jmz merged 1 commit from feat/nats-token-auth into main 2026-09-12 13:43:32 +00:00
Owner

Adds NATS token auth so warden can connect to a server in authorization { token } mode — e.g. the SGM jmz-nats (token-only). The prior path supported only user/password, so warden literally could not connect to a token-mode bus; this unblocks warden ingesting mesh findings there (incl. from the statustree-sgm sensor).

Change

  • make_nats_conn(..., token=) → opts["token"]; token takes precedence over user/password.
  • mesh_settings_from_env reads WARDEN_NATS_TOKEN / WARDEN_NATS_TOKEN_FILE into settings.nats_token (file preferred / never logged; env var accepted for parity, wins if both set).
  • Threaded through the orchestrator (spine) and sensor/actuator (roles) connect paths.
  • docs/mesh.md env table updated.

Tests — +7 (config env/file/precedence; connect-opts token + precedence over user/pass + user/pass fallback when no token). Full suite 910 passed, 1 skipped; ruff clean.

Follows #12 (sgm-detectkit). No behavior change when the token vars are unset.

🤖 Generated with Claude Code

Adds **NATS token auth** so warden can connect to a server in `authorization { token }` mode — e.g. the SGM `jmz-nats` (token-only). The prior path supported only user/password, so warden literally could not connect to a token-mode bus; this unblocks warden ingesting mesh findings there (incl. from the statustree-sgm sensor). **Change** - `make_nats_conn(..., token=)` → `opts["token"]`; token takes precedence over user/password. - `mesh_settings_from_env` reads `WARDEN_NATS_TOKEN` / `WARDEN_NATS_TOKEN_FILE` into `settings.nats_token` (file preferred / never logged; env var accepted for parity, wins if both set). - Threaded through the orchestrator (`spine`) and sensor/actuator (`roles`) connect paths. - `docs/mesh.md` env table updated. **Tests** — +7 (config env/file/precedence; connect-opts token + precedence over user/pass + user/pass fallback when no token). Full suite **910 passed, 1 skipped**; ruff clean. Follows #12 (sgm-detectkit). No behavior change when the token vars are unset. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
make_nats_conn gains a `token` param (opts["token"]), and mesh_settings_from_env
reads WARDEN_NATS_TOKEN / WARDEN_NATS_TOKEN_FILE into settings.nats_token, threaded
through the orchestrator (spine) and sensor/actuator (roles) connect paths. Token
takes precedence over user/password; the file form is preferred (never logged),
the plain env var accepted for parity with servers that read the token from env.

Enables warden to connect to a NATS server in `authorization { token }` mode
(e.g. the SGM jmz-nats), which the prior user/password-only path could not.

+7 tests (config env/file/precedence; connect opts token + precedence + userpass
fallback). Full suite 910 passed, 1 skipped. docs/mesh.md env table updated.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01MJZ2jTLqJxnc31UhrbNcyu
jmz merged commit 8fb0988fbe into main 2026-09-12 13:43:32 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
public/warden!13
No description provided.