Skip to content

Make NATS credentials optional for the nats publisher - #34

Merged
Imtiaz246 merged 1 commit into
masterfrom
nats-optional-credentials
Sep 13, 2026
Merged

Imtiaz246 merged 1 commit into
masterfrom
nats-optional-credentials

Conversation

@tamalsaha

Copy link
Copy Markdown

Problem

publisher.natsCredPath was required whenever publisher.type is nats
(validate:"required_if=Type nats"), and factoryPublisher always passed
it straight to nats.UserCredentials(...), even when empty. Pointing
pgoutbox at a NATS deployment with no auth configured at all (a local dev
instance, or a trusted in-cluster NATS with no auth turned on) failed both
config validation and the connection attempt itself, with no way to opt
out short of a local patch.

Fix

  • apis/config.go: drop the required_if=Type nats validation tag on
    NatsCredPath, documented as optional.
  • cmd/pgoutbox/init.go: only pass nats.UserCredentials(...) when
    NatsCredPath is actually set; connect without it otherwise.
  • apis/config_test.go: updated the existing "missing NatsCredPath" case
    to assert success (credential-less mode) instead of the old
    required_if validation error; the existing "with NatsCredPath -
    success" case is unchanged, so a NATS server that does require auth is
    unaffected.

Verification

gofmt -l and gofumpt -l clean, golangci-lint run clean, go build ./... / go vet ./... clean, go test ./... passes. go mod tidy
leaves go.mod/go.sum/vendor/ untouched (no new dependency).

Signed-off-by: Tamal Saha tamal@appscode.com

kodiakhq[bot]
kodiakhq Bot previously approved these changes Sep 13, 2026
NatsCredPath was required whenever publisher.type is nats
(validate:"required_if=Type nats"), and factoryPublisher always
passed it to nats.UserCredentials(...) even when empty -- so pointing
pgoutbox at a NATS deployment with no auth configured at all (the
common case for a local or trusted-network deployment) failed both
config validation and the connection attempt itself, with no way to
opt out.

Drop the required_if tag and only apply nats.UserCredentials when
NatsCredPath is actually set; connect without it otherwise. A NATS
server that does require auth is unaffected: setting NatsCredPath
still works exactly as before.

Signed-off-by: Tamal Saha <tamal@appscode.com>
@Imtiaz246
Imtiaz246 merged commit 5c9836a into master Sep 13, 2026
4 checks passed
@Imtiaz246
Imtiaz246 deleted the nats-optional-credentials branch September 13, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants