NATS Server On Loopback, JetStream On, Round-Tripped
NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
nats-server
NATS server from the upstream release tarball (sha256-verified), as a
hardened system service on loopback with JetStream persistence under its own
data directory and the configuration checked by nats-server -t before it
lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
nats-server; NATS ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the asset unless its
SHA-256 is the one in the vendor's file, then installs the binaries as
root's in /usr/local/bin, pinned by nats_server_version.
A service account, a hardened unit, a loopback listener. nats-server
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:4222 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
A message, round-tripped without a client. No NATS client is
installed by the role, so the live test speaks the protocol over
/dev/tcp: one session subscribes to a subject, publishes to it, and must
read its own MSG back. That is the broker doing its work, not a port
answering. The monitoring endpoint on 8222 is loopback too; the live test
reads the version from /varz and the JetStream store from /jsz.
No accounts by default. A single-host broker on loopback has one
implicit account and no authentication; accounts, users, TLS and
clustering go in nats_server_extra_config, appended verbatim in
nats-server's own syntax and checked by the same -t before the file
lands. The cluster port (6222) is not opened.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-mosquitto-broker
Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.
ansible-postfix-null-client
Postfix as a send-only relay: no local delivery (a stock install spools root's mail on the box), one smarthost, TLS required rather than opportunistic, SASL credentials in a root-only lmdb map, local recipients rewritten to a real mailbox. Original role, live-tested on Rocky Linux 10.
ansible-ntfy
ntfy from the upstream release (sha256-verified) as a hardened system service on loopback with a message cache, a user database and deny-all as the default access. The live test sees an anonymous publish and a wrong password refused, creates a user with ntfy's own command, publishes a message and reads it back from the topic. Original role, live-tested on Rocky Linux 10.