NSQ, A Broker And Its Directory, Messages Counted
NSQ (SHA-256 pinned): nsqd and nsqlookupd as two hardened services from one release on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test publishes four messages, sees the topic count them with the channel holding the last, and asks the directory which broker holds the topic. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-nsq?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [NSQ, A Broker And Its Directory, Messages Counted](https://www.iac-bazaar.com/catalog/ansible-nsq?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# NSQ, A Broker And Its Directory, Messages Counted: https://www.iac-bazaar.com/catalog/ansible-nsq (download from your IaC Bazaar account)
```Preview:
Documentation
nsq
NSQ from the upstream release (SHA-256 pinned per architecture): nsqd, the broker, and nsqlookupd, the directory it registers with, as two hardened system services on loopback under one account, with the queue files under /var/lib/nsq. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, and no checksum file to speak of. EL 10 carries no
nsqd, and NSQ publishes the release with nothing beside it. This
role pins the SHA-256 per architecture beside the version, has Ansible's
get_url refuse the asset unless it matches, and installs the binaries
as root's in /usr/local/bin. A new release is a new pair, on purpose.
A service account, a hardened unit, a loopback listener. nsq
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:4151 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
Two units from one release. nsqlookupd is templated, enabled and
started first; nsqd Requires and After it, so a restart of the pair keeps
the order. Both run as nsq with the same hardening, and only nsqd
writes to the data directory.
Proven by messages that were counted. The live test asks the directory for its health, publishes three messages to a topic, creates a channel, publishes a fourth, and reads the broker's statistics until the topic counts four with the channel holding the one message published after it existed. Then it asks the directory which broker holds the topic and expects exactly this one, at its client port.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-kafka
Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.
ansible-gotify
Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.
ansible-postfix-tls
An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.
ansible-mosquitto-broker
Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.
ansible-nats
nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-nats-server
NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.