config

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: BSD-3-Clause Imports: 19 Imported by: 0

Documentation

Overview

Package config parses and validates headwire's INI configuration: an Interface section, optional repeated [DERPRegion] sections forming a static DERP map, and repeated Peer sections.

Index

Constants

This section is empty.

Variables

View Source
var Dir = "/etc/headwire"

Dir holds NAME.conf files.

Functions

func DecodeKey

func DecodeKey(s string) (raw [32]byte, err error)

DecodeKey parses a base64 32-byte key strictly: exactly 44 characters in canonical encoding.

func EncodeKey

func EncodeKey(raw [32]byte) string

EncodeKey renders 32 raw key bytes in the base64 form used by the config file and `pubkey` output. WireGuard-format configuration and interoperability are why Headwire reads raw keys out of Tailscale's key types, which deprecate that access (SA1019).

func Path

func Path(arg string) string

Path resolves the NAME | FILE argument: a bare NAME selects Dir/NAME.conf and anything else is a file path.

func Private

func Private(m os.FileMode) bool

Private reports a mode fit for key material: nothing for group or other.

Types

type AllowDestination

type AllowDestination struct {
	Kind   DestinationKind
	Prefix netip.Prefix
}

AllowDestination selects any address (the zero value), this node's exact interface addresses, or a single prefix. Parsed selectors have only one kind.

type AllowRule

type AllowRule struct {
	Protos      []uint8
	First, Last uint16
	Destination AllowDestination
}

AllowRule admits inbound packets of the listed IP protocols to a port range at Destination. No protocols means every protocol.

type Config

type Config struct {
	Interface Interface
	// Regions holds the inline [DERPRegion] sections keyed by ID. Nil when
	// no regions are configured.
	Regions map[int]Region
	Peers   []Peer
}

Config is a parsed and validated headwire configuration.

func Load

func Load(path string, warn func(string)) (*Config, error)

Load parses the file at path. It reports through warn a regular file that other users can access or that someone other than root or the effective user owns.

func LoadName

func LoadName(name string) (*Config, error)

LoadName loads the file a bare NAME selects and refuses a path. The Apple provider loads it as root for an unprivileged app, so Dir must be owned by root or the effective user and writable by no one else, and Load's warnings are errors.

func Parse

func Parse(src []byte) (*Config, error)

Parse parses and validates a headwire configuration.

func (*Config) DERPMap

func (cfg *Config) DERPMap() *tailcfg.DERPMap

DERPMap returns the configured relay regions without public defaults.

type DestinationKind

type DestinationKind uint8
const (
	DestinationAny DestinationKind = iota
	DestinationSelf
	DestinationPrefix
)

type Interface

type Interface struct {
	PrivateKey key.NodePrivate
	Addresses  []netip.Prefix
	// HomeDERP is the region ID of the node's home DERP region, or 0 if
	// the node uses no DERP.
	HomeDERP int
	// ListenPort 0 requests a random port. MTU 0 uses the engine default.
	ListenPort uint16
	MTU        int
	// DNS and DNSSearch split the DNS key: entries that parse as addresses
	// are nameservers, the rest are search domains. Both apply system-wide
	// while the interface is up.
	DNS       []netip.Addr
	DNSSearch []dnsname.FQDN
	// AllowIn is the inbound policy of peers that set none of their own.
	// Nil admits everything and is only valid while no peer sets AllowIn.
	AllowIn []AllowRule
}

Interface is the Interface section.

func (Interface) HasAddress

func (i Interface) HasAddress(addr netip.Addr) bool

HasAddress tests exact interface addresses, not their surrounding subnets.

type Peer

type Peer struct {
	PublicKey key.NodePublic
	// DiscoKey is the peer's discovery public key, printed by
	// `headwire discokey`. An omitted key identifies an ordinary WireGuard
	// peer with a fixed Endpoint.
	DiscoKey     key.DiscoPublic
	AllowedIPs   []netip.Prefix
	PresharedKey [32]byte // zero when unset
	// Endpoint is a fixed host:port probed as a direct candidate, or empty.
	// Name resolution is deferred to the engine.
	Endpoint string
	// HomeDERP is the peer's home DERP region ID, or 0. Such a peer is relayed
	// until disco probing of Endpoint or of exchanged candidates finds a
	// direct path.
	HomeDERP int
	// Masquerade4 and Masquerade6 replace the interface address of their
	// family as the source of packets sent to this peer, for a peer that
	// knows this node by another address. Invalid when unset.
	Masquerade4, Masquerade6 netip.Addr
	// AllowIn replaces the interface's AllowIn for this peer, which must
	// then be set. Nil when unset, empty admits nothing.
	AllowIn []AllowRule
}

Peer is one Peer section. A discovery peer may set Endpoint, HomeDERP, both, or neither, and a peer with neither is passive, sendable only after an authenticated inbound packet supplies its address.

func (Peer) WireGuardOnly

func (p Peer) WireGuardOnly() bool

WireGuardOnly identifies a peer that speaks neither disco nor DERP.

type Region

type Region struct {
	ID    int
	Nodes []string
}

Region is one statically configured DERP region. Nodes contains hostnames in connection preference order. DERP uses TLS on 443 and STUN on 3478.

func (Region) Label

func (r Region) Label() string

Label names the region for status and diagnostics: its ID and node hostnames.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL