central

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 24 Imported by: 0

Documentation

Overview

Package central is the composition root of the central: it reads the configuration, builds every part and serves the three listeners (edge gateway, STUN, API and UI). Behaviour lives in the packages below it.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Run

func Run(ctx context.Context, cfg Config) error

Run wires the central together and serves until ctx ends or a part fails.

Types

type Config

type Config struct {
	DataDir     string // holds the CA
	DatabaseURL string

	GatewayListen string // e.g. ":8443"
	STUNListen    string // e.g. ":3478"
	AdminListen   string // e.g. "127.0.0.1:8080"

	// Gateway URL as seen by edges.
	PublicURL string
	// Extra names or IPs for the server certificate.
	ExtraHosts []string
	// STUN address as seen by edges (default: PublicURL host).
	STUNPublic string

	// ASN database in MaxMind DB format, optional.
	ASNPath string

	EdgeCertValidity  time.Duration
	HeartbeatInterval time.Duration
	STUNInterval      time.Duration

	UI      http.Handler // serves the web UI on every path the API does not use
	Version string       // sent in the User-Agent of webhooks

	// Bearer token of GET /metrics (Prometheus). Empty: no endpoint.
	MetricsToken string
	// Password of the "grafana" SQL login, read-only on the grafana views.
	// Empty: the login is left as it is.
	GrafanaPassword string

	// Webhooks may target private or local addresses. Off: the central
	// could otherwise be used to reach its own network.
	WebhookAllowPrivate bool

	// Reverse proxies in front of the admin API, as addresses or prefixes:
	// their X-Forwarded-For gives the client address, for login throttling
	// and the audit log. Empty: the connection address is the client.
	TrustedProxies []string

	// Session cookie without the Secure flag, for plain HTTP outside
	// localhost. Never in production.
	InsecureCookie bool
}

Directories

Path Synopsis
Package alerting turns rules into alerts and alerts into signed webhooks.
Package alerting turns rules into alerts and alerts into signed webhooks.
Package api implements the API used by the UI: edges, targets, results, traceroutes, data lifecycle, accounts and alerting.
Package api implements the API used by the UI: edges, targets, results, traceroutes, data lifecycle, accounts and alerting.
Package asn looks up the autonomous system of an address in a MaxMind DB file (DB-IP ASN Lite or GeoLite2-ASN).
Package asn looks up the autonomous system of an address in a MaxMind DB file (DB-IP ASN Lite or GeoLite2-ASN).
Package audit records every change made through the admin API.
Package audit records every change made through the admin API.
Package auth handles UI accounts: password login and cookie sessions.
Package auth handles UI accounts: password login and cookie sessions.
Package enroll owns the enrollment token: its format, how it is made and read back, and the command an operator runs on a new edge.
Package enroll owns the enrollment token: its format, how it is made and read back, and the command an operator runs on a new edge.
Package export writes measurements as CSV, for archives and spreadsheets.
Package export writes measurements as CSV, for archives and spreadsheets.
Package fleet holds the live state of the edges: sessions, assignments and observed addresses.
Package fleet holds the live state of the edges: sessions, assignments and observed addresses.
Package gateway implements the internet facing side of the central: enrollment, certificate renewal, edge sessions, result reports and STUN.
Package gateway implements the internet facing side of the central: enrollment, certificate renewal, edge sessions, result reports and STUN.
Package realip recovers the client address behind a reverse proxy.
Package realip recovers the client address behind a reverse proxy.
Package secrets seals values kept in the database, the webhook signing secrets, with a key stored next to the CA: a copy of the database alone is not enough to forge signatures.
Package secrets seals values kept in the database, the webhook signing secrets, with a key stored next to the CA: a copy of the database alone is not enough to forge signatures.
Package store keeps everything the central knows in PostgreSQL with TimescaleDB.
Package store keeps everything the central knows in PostgreSQL with TimescaleDB.
storetest
Package storetest gives tests a fresh database, created from NETPROBE_TEST_DATABASE_URL and dropped at the end.
Package storetest gives tests a fresh database, created from NETPROBE_TEST_DATABASE_URL and dropped at the end.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL