feat(mesh): NATS token auth (WARDEN_NATS_TOKEN) for token-mode servers #13
No reviewers
Labels
No labels
correctness
coverage
milestone:M4
polish
security
tech-debt
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
public/warden!13
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/nats-token-auth"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds NATS token auth so warden can connect to a server in
authorization { token }mode — e.g. the SGMjmz-nats(token-only). The prior path supported only user/password, so warden literally could not connect to a token-mode bus; this unblocks warden ingesting mesh findings there (incl. from the statustree-sgm sensor).Change
make_nats_conn(..., token=)→opts["token"]; token takes precedence over user/password.mesh_settings_from_envreadsWARDEN_NATS_TOKEN/WARDEN_NATS_TOKEN_FILEintosettings.nats_token(file preferred / never logged; env var accepted for parity, wins if both set).spine) and sensor/actuator (roles) connect paths.docs/mesh.mdenv table updated.Tests — +7 (config env/file/precedence; connect-opts token + precedence over user/pass + user/pass fallback when no token). Full suite 910 passed, 1 skipped; ruff clean.
Follows #12 (sgm-detectkit). No behavior change when the token vars are unset.
🤖 Generated with Claude Code
make_nats_conn gains a `token` param (opts["token"]), and mesh_settings_from_env reads WARDEN_NATS_TOKEN / WARDEN_NATS_TOKEN_FILE into settings.nats_token, threaded through the orchestrator (spine) and sensor/actuator (roles) connect paths. Token takes precedence over user/password; the file form is preferred (never logged), the plain env var accepted for parity with servers that read the token from env. Enables warden to connect to a NATS server in `authorization { token }` mode (e.g. the SGM jmz-nats), which the prior user/password-only path could not. +7 tests (config env/file/precedence; connect opts token + precedence + userpass fallback). Full suite 910 passed, 1 skipped. docs/mesh.md env table updated. Co-Authored-By: Claude Opus 4.8 <[email protected]> Claude-Session: https://claude.ai/code/session_01MJZ2jTLqJxnc31UhrbNcyu