Documentation
¶
Overview ¶
Package config parses and validates headwire's INI configuration: an Interface section, optional repeated [DERPRegion] sections forming a static DERP map, and repeated Peer sections.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var Dir = "/etc/headwire"
Dir holds NAME.conf files.
Functions ¶
func DecodeKey ¶
DecodeKey parses a base64 32-byte key strictly: exactly 44 characters in canonical encoding.
func EncodeKey ¶
EncodeKey renders 32 raw key bytes in the base64 form used by the config file and `pubkey` output. WireGuard-format configuration and interoperability are why Headwire reads raw keys out of Tailscale's key types, which deprecate that access (SA1019).
Types ¶
type AllowDestination ¶
type AllowDestination struct {
Kind DestinationKind
Prefix netip.Prefix
}
AllowDestination selects any address (the zero value), this node's exact interface addresses, or a single prefix. Parsed selectors have only one kind.
type AllowRule ¶
type AllowRule struct {
Protos []uint8
First, Last uint16
Destination AllowDestination
}
AllowRule admits inbound packets of the listed IP protocols to a port range at Destination. No protocols means every protocol.
type Config ¶
type Config struct {
Interface Interface
// Regions holds the inline [DERPRegion] sections keyed by ID. Nil when
// no regions are configured.
Regions map[int]Region
Peers []Peer
}
Config is a parsed and validated headwire configuration.
func Load ¶
Load parses the file at path. It reports through warn a regular file that other users can access or that someone other than root or the effective user owns.
func LoadName ¶
LoadName loads the file a bare NAME selects and refuses a path. The Apple provider loads it as root for an unprivileged app, so Dir must be owned by root or the effective user and writable by no one else, and Load's warnings are errors.
type DestinationKind ¶
type DestinationKind uint8
const ( DestinationAny DestinationKind = iota DestinationSelf DestinationPrefix )
type Interface ¶
type Interface struct {
PrivateKey key.NodePrivate
Addresses []netip.Prefix
// HomeDERP is the region ID of the node's home DERP region, or 0 if
// the node uses no DERP.
HomeDERP int
// ListenPort 0 requests a random port. MTU 0 uses the engine default.
ListenPort uint16
MTU int
// DNS and DNSSearch split the DNS key: entries that parse as addresses
// are nameservers, the rest are search domains. Both apply system-wide
// while the interface is up.
DNS []netip.Addr
DNSSearch []dnsname.FQDN
// AllowIn is the inbound policy of peers that set none of their own.
// Nil admits everything and is only valid while no peer sets AllowIn.
AllowIn []AllowRule
}
Interface is the Interface section.
type Peer ¶
type Peer struct {
PublicKey key.NodePublic
// DiscoKey is the peer's discovery public key, printed by
// `headwire discokey`. An omitted key identifies an ordinary WireGuard
// peer with a fixed Endpoint.
DiscoKey key.DiscoPublic
AllowedIPs []netip.Prefix
// Endpoint is a fixed host:port probed as a direct candidate, or empty.
// Name resolution is deferred to the engine.
Endpoint string
// HomeDERP is the peer's home DERP region ID, or 0. Such a peer is relayed
// until disco probing of Endpoint or of exchanged candidates finds a
// direct path.
HomeDERP int
// Masquerade4 and Masquerade6 replace the interface address of their
// family as the source of packets sent to this peer, for a peer that
// knows this node by another address. Invalid when unset.
Masquerade4, Masquerade6 netip.Addr
// AllowIn replaces the interface's AllowIn for this peer, which must
// then be set. Nil when unset, empty admits nothing.
AllowIn []AllowRule
}
Peer is one Peer section. A discovery peer may set Endpoint, HomeDERP, both, or neither, and a peer with neither is passive, sendable only after an authenticated inbound packet supplies its address.
func (Peer) WireGuardOnly ¶
WireGuardOnly identifies a peer that speaks neither disco nor DERP.