gateway

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 27 Imported by: 0

Documentation

Overview

Package gateway implements the internet facing side of the central: enrollment, certificate renewal, edge sessions, result reports and STUN.

Index

Constants

View Source
const MaxMessageBytes = 1 << 20

Max size of any message sent by an edge. MaxMessageBytes bounds every request body.

Variables

This section is empty.

Functions

func TLSConfig

func TLSConfig(ca *pki.CA, hosts []string) (*tls.Config, error)

TLSConfig is the TLS setup of the gateway: TLS 1.3, a server certificate for hosts issued by the CA and renewed in memory, and client certificates optional at TLS level (Enroll has none, the handlers check the others).

Types

type Gateway

type Gateway struct {
	Store    *store.Store
	CA       *pki.CA
	Hub      *fleet.Hub
	Recorder *fleet.Recorder
	Assigner *fleet.Assigner
	ASN      *asn.DB // AS of traceroute hops, may be nil

	CertValidity      time.Duration
	HeartbeatInterval time.Duration
	STUNServer        string // host:port advertised to edges
	STUNInterval      time.Duration
	// contains filtered or unexported fields
}

Gateway serves EdgeService (internet facing).

func (*Gateway) Handler

func (g *Gateway) Handler() http.Handler

Handler requires a known client certificate, except for Enroll.

func (*Gateway) Report

Report stores a batch of results from an authenticated edge.

func (*Gateway) Session

Session runs until the edge leaves, times out or is kicked.

type STUNServer

type STUNServer struct {
	Hub      *fleet.Hub
	Recorder *fleet.Recorder
	// contains filtered or unexported fields
}

STUNServer answers authenticated binding requests only; others get silence.

func (*STUNServer) Serve

func (s *STUNServer) Serve(ctx context.Context, conn net.PacketConn) error

Serve answers on conn until ctx ends.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL