NATS Server On Loopback, JetStream On, Round-Tripped

NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.

ansibleMessaging & Streaming

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify

Documentation

nats-server

NATS server from the upstream release tarball (sha256-verified), as a hardened system service on loopback with JetStream persistence under its own data directory and the configuration checked by nats-server -t before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No package, so the checksum is the whole story. EL 10 carries no nats-server; NATS ships a release with a checksum file beside it. The role downloads both and has Ansible's get_url refuse the asset unless its SHA-256 is the one in the vendor's file, then installs the binaries as root's in /usr/local/bin, pinned by nats_server_version.

A service account, a hardened unit, a loopback listener. nats-server is a system user with no shell that owns the data directory and nothing else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and ProtectSystem=strict. The listener is 127.0.0.1:4222 by default, for a proxy that authenticates or a client on the same host; the live test reads the listening sockets and expects loopback only.

A message, round-tripped without a client. No NATS client is installed by the role, so the live test speaks the protocol over /dev/tcp: one session subscribes to a subject, publishes to it, and must read its own MSG back. That is the broker doing its work, not a port answering. The monitoring endpoint on 8222 is loopback too; the live test reads the version from /varz and the JetStream store from /jsz.

No accounts by default. A single-host broker on loopback has one implicit account and no authentication; accounts, users, TLS and clustering go in nats_server_extra_config, appended verbatim in nats-server's own syntax and checked by the same -t before the file lands. The cluster port (6222) is not opened.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules