Skip to content

P2.2/P2.3: MQTT transport sharing the ingest pipeline - #20

Merged
ocularminds merged 1 commit into
masterfrom
p2.2-mqtt-transport
Aug 17, 2026
Merged

ocularminds merged 1 commit into
masterfrom
p2.2-mqtt-transport

Conversation

@ocularminds

Copy link
Copy Markdown
Owner

Roadmap items

P2.3 ✅ (MQTT ingest) + P2.2 ◐ (broker in the one-box compose; hardening documented as deployment policy) — plus the README status refresh requested by the owner.

Design

  • The telemetry pipeline extracted to transport-agnostic ingest.ts — HTTPS POST /telemetry and the MQTT bridge run the identical verification chain (schema → device → freshness → atomic seq claim → Ed25519 → insert → rules).
  • mqtt.ts subscribes proxies/telemetry/+, acks verdicts on proxies/telemetry-ack/<id>; enabled by MQTT_URL. The broker is untrusted by design: the signed envelope + monotonic seq carry the trust, so broker auth (TLS, per-device credentials, topic ACLs) is deployment policy — the mosquitto pilot config says so loudly.
  • README rewritten to platform status: new architecture sketch, Phase 2 feature rows, MQTT config; TELEMETRY.md documents both transports.

Verification

  • 54/54 tests — four new MQTT integration tests against a real in-process broker (aedes v1 via its async createBroker factory, discovered when new Aedes() silently never CONNACKs): accept + store, seq replay over MQTT, tampered signature, malformed-JSON ack. Production npm audit: 0 vulnerabilities with the mqtt dependency.

🤖 Generated with Claude Code

- the telemetry pipeline moves to transport-agnostic src/ingest.ts
  (schema -> device -> freshness -> seq claim -> signature -> insert ->
  rules); the HTTPS route becomes a thin adapter; notifier moves to
  src/notify.ts
- src/mqtt.ts: bridge subscribes proxies/telemetry/+ and publishes
  verdicts on proxies/telemetry-ack/<id>; started when MQTT_URL is set;
  the broker is untrusted by design — the Ed25519 envelope and
  monotonic seq carry the trust
- deploy: eclipse-mosquitto joins the one-box compose with a loudly
  documented pilot config (anonymous on-box; lock-down path in comments)
- README refreshed to platform status (per owner request): new
  architecture sketch, Phase 2 feature rows, layout, MQTT config;
  TELEMETRY.md documents both transports
- tests: 54 — four MQTT integration tests against an in-process aedes
  broker (accept+store, seq replay, tampered signature, malformed JSON
  ack); aedes v1 requires the async createBroker factory

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ocularminds
ocularminds merged commit 441b0f9 into master Aug 17, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant