Conversation
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The exporter connects to NATS without TLS, so it cannot reach any listener requiring a client certificate - both the shared
nats-systembroker and the edge relay. It has only ever run in dev, where NATS has no TLS. Edge clusters also have no path to a central broker at all.The exporter gains mTLS and publishes to a subject carrying a cluster token, so per-PoP NATS permissions can scope publish access to that cluster's own subjects. An
activity nkey-generatorsubcommand mints per-cluster NKeys from Karmada cluster state and distributes them through ESO. A Kustomize bundle deploys the exporter alongside a local core-NATS relay on edge cells, and a second processor instance consumes the federated stream from the hub while publishing activities back to the shared broker.Test plan
go testevent_exporter_events_published_totalemits its first seriesDepends on #248
Stack: