Skip to content

feat: add safe NATS/JetStream ops service surface #46

Description

@rodaddy

Goal

Add or refine a safe NATS/JetStream mcp2cli ops surface for fleet event/status inspection and approved dev publishing.

Context

mcp2cli already has issue #18 for NATS/JetStream mode for MCP tool requests and receipts. This issue is narrower: give agents a safe operational interface for inspecting NATS/JetStream state and publishing only to approved development/status subjects.

Work

  • Decide whether this is a child of feat: add NATS/JetStream mode for MCP tool requests and receipts #18 or a separate service surface.
  • Provide read-only tools first:
    • connection/status check;
    • server info;
    • stream list/info;
    • consumer list/info;
    • subject sample with bounded limits.
  • Add gated publish only for approved dev/test/status subjects.
  • Document subject conventions for agent/fleet events.
  • Fail closed on missing credentials, unknown subjects, or production publish without explicit approval.
  • Ensure secrets come from existing mcp2cli/Vaultwarden patterns.

Acceptance Criteria

  • The issue links to or updates feat: add NATS/JetStream mode for MCP tool requests and receipts #18 to avoid duplicate NATS direction.
  • Agents can inspect NATS health and stream metadata without SSH.
  • Any publish tool is deny-by-default and limited to approved subjects.
  • No credentials or message payload secrets are logged.
  • Docs explain when NATS is the right layer versus MonkeyProof/A2A/Herdr.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions