swarm-queue-client: install aws-lc-rs as the process rustls provider
rustls is built with both `ring` (async-nats's `ring` feature) and
`aws-lc-rs` (reqwest's `rustls` feature), so it cannot pick a
process-level default by itself. Since the queue started requiring TLS
(1d261b3f), async-nats builds its config with `ClientConfig::builder()`,
which panics without an installed default. The panic kills the async-nats
connector task, and every queue client (swarm-controller, hive-c0re, all
hive-agents) has sat in `Pending` since the 2026-09-25 23:04Z deploy.
Add `swarm_queue_client::install_crypto_provider()`, which installs
aws-lc-rs and ignores the "already installed" error. It is called first in
`main` of every binary that links async-nats: hive-agent, hive-c0re,
swarm-controller, swarm-nats-auth. `connect()` also calls it, so a new
binary that dials through this crate is covered without remembering to.
aws-lc-rs because reqwest already falls back to it when no default is
installed, so HTTPS in these processes keeps its current provider. The
other rustls users in the tree reach it only through reqwest, which never
panics here.
Closes #4738
This commit is contained in:
parent
386741d38f
commit
0f58cdbde2
8 changed files with 34 additions and 0 deletions
|
|
@ -254,6 +254,13 @@ async-nats = { version = "0.50", default-features = false, features = [
|
|||
"nkeys",
|
||||
"ring",
|
||||
] }
|
||||
# Named only to install the process-wide provider (`swarm-queue-client`'s
|
||||
# `install_crypto_provider`). `aws-lc-rs` is the provider reqwest already
|
||||
# falls back to, so installing it leaves every HTTPS client unchanged.
|
||||
rustls = { version = "0.23", default-features = false, features = [
|
||||
"aws-lc-rs",
|
||||
"std",
|
||||
] }
|
||||
data-encoding = "2"
|
||||
# The nkey *format* - ed25519 + base32 + CRC16. The primitives are already in
|
||||
# the tree; the format is not, and hand-rolling a key format on an auth path
|
||||
|
|
|
|||
Loading…
Reference in a new issue