feb917fc6a
Roll the --ws-port + --cors-origins flags (issue uniweb/0001) out to the unibus cluster so the browser-native uniweb client can reach the data plane (nats.ws) and the control plane (CORS) on every node. The WS reuses the data-plane TLS (wss://) and the same origin allowlist. Per-node WS port override (WS_PORT_<NAME>): magnus runs unibus_admin on 127.0.0.1:8480, so the bus WS binds 8485 there to avoid a crash-loop; homer and datardos keep 8480. deploy-cluster.sh also gains DEPLOY_ONLY=<name> for rolling one node at a time. Rolled out and verified 2026-06-13: all three nodes healthy, WS reachable, CORS 204, cluster quorum (R3) intact throughout.
49 lines
1.7 KiB
Desktop File
49 lines
1.7 KiB
Desktop File
[Unit]
|
|
# unibus membershipd — cluster node (issue 0006g).
|
|
#
|
|
# One unit, parameterized per node by /opt/unibus/cluster.env (generated by
|
|
# deploy-cluster.sh): NODE_NAME, ROUTES and the cert paths differ per node, the
|
|
# rest of the posture (enforce + per-subject ACL + TLS + --store kv) is identical
|
|
# on every node, which is the homogeneous posture a secure cluster requires
|
|
# (audit 0008 N1).
|
|
Description=unibus membershipd (cluster node)
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
WorkingDirectory=/opt/unibus
|
|
EnvironmentFile=/opt/unibus/cluster.env
|
|
# The route password comes from a FILE referenced by ${CLUSTER_PASS_FILE}, never
|
|
# from argv (audit 0008 N1-low). The peer --routes carry no userinfo; membershipd
|
|
# injects the credentials from the file/user.
|
|
ExecStart=/opt/unibus/membershipd \
|
|
--bind 0.0.0.0 \
|
|
--bus-auth enforce \
|
|
--http-port ${HTTP_PORT} \
|
|
--nats-port ${NATS_CLIENT_PORT} \
|
|
--tls-cert ${TLS_CERT} \
|
|
--tls-key ${TLS_KEY} \
|
|
--cluster-name ${CLUSTER_NAME} \
|
|
--server-name ${NODE_NAME} \
|
|
--cluster-port ${NATS_ROUTE_PORT} \
|
|
--routes ${ROUTES} \
|
|
--cluster-user ${CLUSTER_USER} \
|
|
--cluster-pass-file ${CLUSTER_PASS_FILE} \
|
|
--route-tls-cert ${ROUTE_TLS_CERT} \
|
|
--route-tls-key ${ROUTE_TLS_KEY} \
|
|
--route-tls-ca ${ROUTE_TLS_CA} \
|
|
--internal-id-file ${INTERNAL_ID_FILE} \
|
|
--store kv \
|
|
--kv-replicas ${KV_REPLICAS} \
|
|
--ws-port ${WS_PORT} \
|
|
--cors-origins ${CORS_ORIGINS}
|
|
# Restart=always (NOT on-failure): a clean SIGTERM exits success, and on-failure
|
|
# would then NOT restart, leaving the node silently dead (see function_tags.md).
|
|
Restart=always
|
|
RestartSec=2
|
|
LimitNOFILE=65536
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|