Documentation
¶
Overview ¶
package for logicing client and server code
Index ¶
- Constants
- Variables
- func AddEgressInfoToPeerByAccess(node, targetNode *models.Node, eli []schema.Egress, acls []models.Acl, ...)
- func AddHook(ifaceToAdd interface{})
- func AddSSOStateCleanupHook()
- func AddStaticNodestoList(nodes []models.Node) []models.Node
- func AddStatusToNodes(nodes []models.Node, statusCall bool) (nodesWithStatus []models.Node)
- func AllDomainAnsFromEgress(e schema.Egress) []string
- func AllocateUniquePoolFromFallback(pool *net.IPNet, newPrefixLen int, allocated map[string]struct{}, seed string) string
- func AllocateUniqueVNATPool(network *schema.Network) error
- func ApplyConfiguredDomainsToEgress(e *schema.Egress, domains []string)
- func ApplyEgressPresetToEgressReq(req *models.EgressReq) error
- func AssignVirtualNATDefaults(network *schema.Network, vpnCIDR string)
- func AssociateNodeToHost(n *models.Node, h *schema.Host) error
- func AutoUpdateEnabled() bool
- func CheckEndpoint(endpoint string) bool
- func CheckHostPorts(h *schema.Host) (changed bool)
- func CheckIfFileExists(filePath string) bool
- func CheckTagGroupPolicy(srcMap, dstMap map[string]struct{}, node, peer models.Node, ...) bool
- func CheckZombies(_node *schema.Node)
- func CleanExpiredSSOStates() error
- func CleanVersion(raw string) string
- func CleanupOtherExtclients(extclient *models.ExtClient) error
- func ClearEgressDomainAns(e *schema.Egress)
- func CompareIfaceSlices(a, b []schema.Iface) bool
- func CompareMaps[K comparable, V any](a, b map[K]V) bool
- func ConfiguredDomainsForEgress(e schema.Egress) []string
- func ContainsCIDR(net1, net2 string) bool
- func ContinueIfUserMatch(next http.Handler) http.HandlerFunc
- func ContinueIfUserMatchOrAdmin(next http.Handler) http.HandlerFunc
- func ConvAclTagToValueMap(acltags []models.AclPolicyTag) map[string]struct{}
- func ConvHostPassToHash(hostPass string) string
- func ConvertModelsNodeToSchemaNode(node *models.Node) *schema.Node
- func ConvertSchemaNodeToApiNode(_node *schema.Node) *models.ApiNode
- func ConvertSchemaNodeToModelsNode(_node *schema.Node) *models.Node
- func CreateDNS(entry models.DNSEntry) (models.DNSEntry, error)
- func CreateDefaultAclNetworkPolicies(netID schema.NetworkID)
- func CreateEgressGateway(gateway models.EgressGatewayRequest) (models.Node, error)
- func CreateEnrollmentKey(uses int, expiration time.Time, networks, tags []string, groups []models.TagID, ...) (*models.EnrollmentKey, error)
- func CreateFallbackNameserver(networkID string) error
- func CreateHost(h *schema.Host) error
- func CreateJWT(uuid string, macAddress string, network string) (response string, err error)
- func CreateNetwork(_network *schema.Network) error
- func CreatePreAuthToken(username string) (string, error)
- func CreateSuperAdmin(u *schema.User) error
- func CreateUser(_user *schema.User) error
- func CreateUserAccessJwtToken(username string, role schema.UserRoleID, d time.Time, tokenID string) (response string, err error)
- func CreateUserJWT(username string, role schema.UserRoleID, appName string) (response string, err error)
- func DeTokenize(b64Token string) (*models.EnrollmentKey, error)
- func DeleteAcl(a models.Acl) error
- func DeleteDNS(domain string, network string) error
- func DeleteEgressGateway(network, nodeid string) (models.Node, error)
- func DeleteEnrollmentKey(value string, force bool) error
- func DeleteExpiredNodes(ctx context.Context)
- func DeleteExtClient(network string, clientid string, isUpdate bool) error
- func DeleteExtClientAndCleanup(extClient models.ExtClient) error
- func DeleteGatewayExtClients(gatewayID string, networkName string) error
- func DeleteIngressGateway(nodeid string) (models.Node, []models.ExtClient, error)
- func DeleteNetwork(network string, force bool, done chan struct{}) error
- func DeleteNetworkDNS(network string) error
- func DeleteNetworkPolicies(netId schema.NetworkID)
- func DeleteNode(node *models.Node, purge bool) error
- func DeleteNodeByID(node *models.Node) error
- func DeletePendingUser(username string) error
- func DeleteRelay(network, nodeid string) ([]models.Node, models.Node, error)
- func DeleteUser(user string) error
- func DeleteUserInvite(email string) error
- func DeleteUserSettings(userID string) error
- func DisassociateAllNodesFromHost(hostIDStr string) error
- func DisplaceAutoRelayedNodes(nodeID string) []models.Node
- func DissasociateNodeFromHost(n *models.Node, h *schema.Host) error
- func DoesHostExistInTheNetworkAlready(h *schema.Host, network *schema.Network) bool
- func DoesNodeHaveAccessToEgress(node *models.Node, e *schema.Egress, acls []models.Acl) bool
- func DoesUserHaveAccessToEgress(user *schema.User, e *schema.Egress, acls []models.Acl) bool
- func DomainAnsForDomain(e schema.Egress, domain string) []string
- func DomainAnsMapFromEgress(e schema.Egress) map[string][]string
- func EgressDNs(network string) (entries []models.DNSEntry)
- func EgressDomainsEqual(a, b []string) bool
- func EnterpriseCheck(ctx context.Context, wg *sync.WaitGroup)
- func FetchAuthSecret() (string, error)
- func FetchJWTSecret() (string, error)
- func FetchPassValue(newValue string) (string, error)
- func FetchTelemetryData() telemetryData
- func FetchTelemetryRecord() (models.Telemetry, error)
- func FileExists(f string) bool
- func FilterOutIPs(ips []string, filters map[string]bool) []string
- func FlattenDomainAnsMap(m map[string][]string) []string
- func FlushNodeCheckins()
- func FormatError(err error, errType ApiErrorType) models.ErrorResponse
- func GenerateNodeName(network string) (string, error)
- func GenerateOTPAuthURLSignature(url string) string
- func GetAcl(aID string) (models.Acl, error)
- func GetAclRuleForInetGw(targetnode models.Node) (rules map[string]models.AclRule)
- func GetAclRulesForNode(targetnodeI *models.Node) (rules map[string]models.AclRule)
- func GetAllDNS() ([]models.DNSEntry, error)
- func GetAllEnrollmentKeys() ([]models.EnrollmentKey, error)
- func GetAllExtClients() ([]models.ExtClient, error)
- func GetAllExtClientsWithStatus(status schema.NodeStatus) ([]models.ExtClient, error)
- func GetAllHostsAPI(hosts []schema.Host) []models.ApiHost
- func GetAllHostsWithStatus(status schema.NodeStatus) ([]schema.Host, error)
- func GetAllNodes() ([]models.Node, error)
- func GetAllNodesAPI(nodes []models.Node) []models.ApiNode
- func GetAllNodesAPIWithLocation(nodes []models.Node) []models.ApiNode
- func GetAllRsrcIDForRsrc(rsrc schema.RsrcType) schema.RsrcID
- func GetAllowedEmailDomains() string
- func GetAllowedIPs(node, peer *models.Node, metrics *models.Metrics) []net.IPNet
- func GetAllowedIpForInetNodeClient(node, peer *models.Node) []net.IPNet
- func GetAllowedIpsForRelayed(relayed, relay *models.Node) (allowedIPs []net.IPNet)
- func GetAuthProviderInfo(settings models.ServerSettings) (pi []string)
- func GetAzureTenant() string
- func GetCachedHostPeerUpdate(hostID string) (models.HostPeerUpdate, bool)
- func GetClientIP(r *http.Request) string
- func GetCurrentServerUsage() (limits models.Usage)
- func GetCustomDNS(network string) ([]models.DNSEntry, error)
- func GetDNS(network string) ([]models.DNSEntry, error)
- func GetDNSEntryNum(domain string, network string) (int, error)
- func GetDefaultDomain() string
- func GetDefaultEnrollmentKeyForNetwork(network string) (models.EnrollmentKey, error)
- func GetDefaultHosts() []schema.Host
- func GetDefaultPolicy(netID schema.NetworkID, ruleType models.AclPolicyType) (models.Acl, error)
- func GetEgressDefaultAllowAllFwRule(node models.Node) (models.AclRule, bool)
- func GetEgressDomainNSForNode(node *models.Node) (returnNsLi []models.Nameserver)
- func GetEgressDomainsByAccessForUser(user *schema.User, network schema.NetworkID) (domains []string)
- func GetEgressIPs(peer *models.Node) []net.IPNet
- func GetEgressPresetByID(id string) (models.EgressPresetApp, bool)
- func GetEgressRanges(netID schema.NetworkID) (map[string][]string, map[string]struct{}, error)
- func GetEgressRangesOnNetwork(client *models.ExtClient) ([]string, error)
- func GetEgressRulesForNode(targetnode models.Node) (rules map[string]models.AclRule)
- func GetEmaiSenderPassword() string
- func GetEnrollmentKey(value string) (key models.EnrollmentKey, err error)
- func GetExtClient(clientid string, network string) (models.ExtClient, error)
- func GetExtClientByName(ID string) (models.ExtClient, error)
- func GetExtClientsByID(nodeid, network string) ([]models.ExtClient, error)
- func GetExtPeers(node, peer *models.Node, addressIdentityMap map[string]models.PeerIdentity) ([]wgtypes.PeerConfig, []models.IDandAddr, []models.EgressNetworkRoutes, error)
- func GetExtclientAllowedIPs(client models.ExtClient) (allowedIPs []string)
- func GetExtclientDNS() []models.DNSEntry
- func GetFwRulesOnIngressGateway(node models.Node) (rules []models.FwRule)
- func GetGwDNS(node *models.Node) string
- func GetHostByNodeID(id string) *schema.Host
- func GetHostNetworks(hostID string) []string
- func GetHostNodes(host *schema.Host) []models.Node
- func GetHostPeerInfo(host *schema.Host) (models.HostPeerInfo, error)
- func GetIDPSyncInterval() time.Duration
- func GetIngressGwUsers(node models.Node) (models.IngressGwUsers, error)
- func GetJwtValidityDuration() time.Duration
- func GetJwtValidityDurationForClients() time.Duration
- func GetManageDNS() bool
- func GetMetricInterval() string
- func GetMetricIntervalInMinutes() time.Duration
- func GetMetricsPort() int
- func GetNetworkExtClients(network string) ([]models.ExtClient, error)
- func GetNetworkNetworkCIDR4(network *schema.Network) *net.IPNet
- func GetNetworkNetworkCIDR6(network *schema.Network) *net.IPNet
- func GetNetworkNodes(network string) ([]models.Node, error)
- func GetNetworkNodesMemory(allNodes []models.Node, network string) []models.Node
- func GetNetworkNonServerNodeCount(networkName string) (int, error)
- func GetNodeByHostRef(hostid, network string) (node models.Node, err error)
- func GetNodeByID(nodeID string) (models.Node, error)
- func GetNodeCheckInStatus(node *schema.Node) schema.NodeStatus
- func GetNodeDNS(network string) ([]models.DNSEntry, error)
- func GetNodeEgressInfo(targetNode *models.Node, eli []schema.Egress, acls []models.Acl)
- func GetNodesByIDs(ids []string) (map[string]models.Node, error)
- func GetNodesStatusAPI(nodes []models.Node) map[string]models.ApiNodeStatus
- func GetOnboardingStatus(ctx context.Context, username string) (models.OnboardingStatus, error)
- func GetPeerListenPort(host *schema.Host) int
- func GetPeerUpdateForHost(network string, host *schema.Host, allNodes []models.Node, ...) (hostPeerUpdate models.HostPeerUpdate, err error)
- func GetRacRestrictToSingleNetwork() bool
- func GetRecordKey(id string, network string) (string, error)
- func GetRelatedHosts(hostID string) []schema.Host
- func GetReturnUser(username string) (models.ReturnUser, error)
- func GetRunningHooks() []string
- func GetSenderEmail() string
- func GetSenderUser() string
- func GetServerConfig() config.ServerConfig
- func GetServerInfo() models.ServerConfig
- func GetServerSettings() (s models.ServerSettings)
- func GetServerSettingsFromEnv() (s models.ServerSettings)
- func GetSmtpHost() string
- func GetSmtpPort() int
- func GetState(state string) (*models.SsoState, error)
- func GetStaticNodeIps(node models.Node) (ips []net.IP)
- func GetStaticNodesByNetwork(network schema.NetworkID, onlyWg bool) (staticNode []models.Node)
- func GetStunServers() string
- func GetSuperAdmin() (models.ReturnUser, error)
- func GetUserInvite(email string) (*schema.UserInvite, error)
- func GetUserMap() (map[string]schema.User, error)
- func GetUserNameFromToken(authtoken string) (username string, err error)
- func GetUserSettings(userID string) models.UserSettings
- func GetUsers() ([]models.ReturnUser, error)
- func GetVerbosity() int32
- func HasEgressDomainAns(e schema.Egress) bool
- func HasSuperAdmin() (bool, error)
- func HostExists(h *schema.Host) bool
- func IfaceDelta(currentNode *models.Node, newNode *models.Node) bool
- func InitNetworkHooks()
- func InitializeZombies()
- func InsertAcl(a models.Acl) error
- func InvalidateHostPeerCaches()
- func InvalidateServerSettingsCache()
- func IsAWSEgressPreset(presetID string) bool
- func IsAclExists(aclID string) bool
- func IsAddressInCIDR(address net.IP, cidr string) bool
- func IsBase64(s string) bool
- func IsBasicAuthEnabled() bool
- func IsDNSEntryValid(d string) bool
- func IsDomainBasedEgress(e schema.Egress) bool
- func IsEgressAppEgress(e schema.Egress) bool
- func IsEgressDomainPattern(domain string) bool
- func IsEgressInternetGateway(e schema.Egress) bool
- func IsEgressReqInternetGateway(req *models.EgressReq) bool
- func IsEgressRoutingPolicyAllowedForNodes(policy models.Acl, node, peer models.Node) bool
- func IsEndpointDetectionEnabled() bool
- func IsFQDN(domain string) bool
- func IsInternetGw(node models.Node) bool
- func IsMFAEnforced() bool
- func IsNetworkCIDRUnique(cidr4 *net.IPNet, cidr6 *net.IPNet) bool
- func IsNetworkNameUnique(network *schema.Network) (bool, error)
- func IsNodeAllowedToCommunicate(node, peer models.Node, checkDefaultPolicy bool) (bool, []models.Acl)
- func IsNodeAllowedToCommunicateWithAllRsrcs(node models.Node) bool
- func IsOauthUser(user *schema.User) error
- func IsPendingUser(username string) bool
- func IsSlicesEqual(a, b []string) bool
- func IsStateValid(state string) (string, bool)
- func IsStunEnabled() bool
- func IsSyncEnabled() bool
- func IsUserAllowedAccessToExtClient(username string, client models.ExtClient) bool
- func IsValidMatchDomain(s string) bool
- func IsValidVersion(raw string) bool
- func IsVersionCompatible(ver string) bool
- func ListAcls() (acls []models.Acl)
- func ListAclsByNetwork(netID schema.NetworkID) ([]models.Acl, error)
- func ListAllByRoutingNodeWithDomain(egs []schema.Egress, nodeID string) (egWithDomain []models.EgressDomain)
- func ListDevicePolicies(netID schema.NetworkID) []models.Acl
- func ListEgressAcls(eID string) ([]models.Acl, error)
- func ListEgressPresets() []models.EgressPresetApp
- func ListUserPolicies(netID schema.NetworkID) []models.Acl
- func ManageZombies(ctx context.Context)
- func MarkStaleNodesOffline(ctx context.Context)
- func Mask() string
- func MigrateAclPolicies()
- func NetworkExists(name string) (bool, error)
- func NormalizeAndValidateAclEgressIPs(acl *models.Acl) error
- func NormalizeCIDR(address string) (string, error)
- func NormalizeEgressReqDomains(domains []string) ([]string, error)
- func NormalizeIPOrCIDR(value string) (string, error)
- func NormalizeOSName(raw string) string
- func NotifyMetricExportIntervalChanged()
- func NthSubnet(pool *net.IPNet, newPrefixLen int, n int) *net.IPNet
- func OSFamily(osName string) string
- func PopulateAclPolicyTagNames(acls []models.Acl)
- func PreAuthCheck(next http.Handler) http.HandlerFunc
- func PresetYieldsAWSIPRanges(p models.EgressPresetApp) bool
- func RandomString(length int) string
- func RefreshHostPeerInfoCache() ([]schema.Host, []models.Node)
- func RegenerateEnrollmentKeyToken(keyID string) (*models.EnrollmentKey, error)
- func RelayUpdates(currentNode, newNode *models.Node) bool
- func RelayedAllowedIPs(peer, node *models.Node) []net.IPNet
- func RemoveAllFromSlice[T comparable](s []T, val T) []T
- func RemoveHost(h *schema.Host, forceDelete bool) error
- func RemoveNodeFromAclPolicy(node models.Node)
- func RemoveNodeFromEgress(node models.Node)
- func RemoveNodeFromEnrollmentKeys(node *models.Node)
- func RemoveStringSlice(slice []string, i int) []string
- func RemoveTagFromEnrollmentKeys(deletedTagID models.TagID)
- func RequiresProEgressType(e schema.Egress) bool
- func ResetHook(hookID string)
- func ResolveAWSEgressPresetCIDRs(client *http.Client, p models.EgressPresetApp) ([]string, error)
- func RestartHook(hookID string, newInterval time.Duration)
- func RetrievePrivateTrafficKey() ([]byte, error)
- func RetrievePublicTrafficKey() ([]byte, error)
- func ReturnAcceptedResponse(response http.ResponseWriter, request *http.Request, message string)
- func ReturnErrorResponse(response http.ResponseWriter, request *http.Request, ...)
- func ReturnErrorResponseWithJson(response http.ResponseWriter, request *http.Request, msg interface{}, ...)
- func ReturnSuccessResponse(response http.ResponseWriter, request *http.Request, message string)
- func ReturnSuccessResponseWithJson(response http.ResponseWriter, request *http.Request, res interface{}, ...)
- func SaveExtClient(extclient *models.ExtClient) error
- func SaveNetwork(_network *schema.Network) error
- func SecurityCheck(reqAdmin bool, next http.Handler) http.HandlerFunc
- func SetAuthSecret(secret string) error
- func SetCorefile(domains string) error
- func SetDNSOnWgConfig(gwNode *models.Node, extclient *models.ExtClient)
- func SetDefaultGw(node models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate
- func SetDefaultGwForRelayedUpdate(relayed, relay models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate
- func SetEgressDomainAnsForDomain(e *schema.Egress, domain string, ans []string)
- func SetEgressDomainAnsForDomains(e *schema.Egress, domains, ans []string)
- func SetFreeTierForTelemetry(freeTierFlag bool)
- func SetInternetGw(node *models.Node, req models.InetNodeReq)
- func SetJWTSecret()
- func SetNetworkNodesLastModified(networkName string) error
- func SetRelayedNodes(setRelayed bool, relay string, relayed []string) []models.Node
- func SetState(appName, state string) error
- func SetUserDefaults(user *schema.User)
- func SetVerbosity(logLevel int)
- func SortAclEntrys(acls []models.Acl)
- func SortApiHosts(unsortedHosts []models.ApiHost)
- func SortApiNodes(unsortedNodes []models.ApiNode)
- func SortDNSEntrys(unsortedDNSEntrys []models.DNSEntry)
- func SortExtClient(unsortedExtClient []models.ExtClient)
- func SortNetworks(unsortedNetworks []schema.Network)
- func SortUsers(unsortedUsers []models.ReturnUser)
- func StartCPUProfiling() *os.File
- func StartHookManager(ctx context.Context, wg *sync.WaitGroup)
- func StartMemProfiling()
- func StopCPUProfiling(f *os.File)
- func StopHook(hookID string)
- func StoreHostPeerUpdate(hostID string, peerUpdate models.HostPeerUpdate)
- func StoreJWTSecret(privateKey string) error
- func StringDifference(a, b []string) []string
- func StringSliceContains(slice []string, item string) bool
- func SubscribeMetricExportIntervalReset() <-chan struct{}
- func Telemetry() string
- func TimerCheckpoint() error
- func ToReturnUser(user *schema.User) models.ReturnUser
- func ToUserEventLog(user *schema.User) models.UserEventLog
- func ToggleExtClientConnectivity(client *models.ExtClient, enable bool) (models.ExtClient, error)
- func Tokenize(k *models.EnrollmentKey, serverAddr string) error
- func TryToUseEnrollmentKey(k *models.EnrollmentKey) bool
- func UniqueAclPolicyTags(tags []models.AclPolicyTag) []models.AclPolicyTag
- func UniqueIPNetList(ipnets []net.IPNet) []net.IPNet
- func UniqueIPNetStrList(ipnets []string) []string
- func UniquePolicies(items []models.Acl) []models.Acl
- func UniqueStrings(input []string) []string
- func UnlinkNetworkAndTagsFromEnrollmentKeys(network string, delete bool) error
- func UnsetInternetGw(node *models.Node)
- func UpdateAcl(newAcl, acl models.Acl) error
- func UpdateEnrollmentKey(keyId string, updates *models.APIEnrollmentKey) (*models.EnrollmentKey, error)
- func UpdateExtClient(old *models.ExtClient, update *models.CustomExtClient) models.ExtClient
- func UpdateHost(newHost, currentHost *schema.Host)
- func UpdateHostFromClient(newHost, currHost *schema.Host) (isEndpointChanged, sendPeerUpdate bool)
- func UpdateHostNetwork(h *schema.Host, network string, add bool) (*models.Node, error)
- func UpdateHostNode(h *schema.Host, newNode *models.Node) (publishDeletedNodeUpdate, publishPeerUpdate bool, ...)
- func UpdateNetwork(currentNetwork, newNetwork *schema.Network) error
- func UpdateNode(currentNode *models.Node, newNode *models.Node) error
- func UpdateNodeCheckin(nodeID string) error
- func UpdateRelayNodes(relay string, oldNodes []string, newNodes []string) []models.Node
- func UpdateRelayed(currentNode, newNode *models.Node)
- func UpdateUser(userchange, _user *schema.User) (*schema.User, error)
- func UpsertAcl(acl models.Acl) error
- func UpsertHost(h *schema.Host) error
- func UpsertNetwork(_network *schema.Network) error
- func UpsertNode(newNode *models.Node) error
- func UpsertServerSettings(s models.ServerSettings) error
- func UpsertUser(_user schema.User) error
- func UpsertUserSettings(userID string, userSettings models.UserSettings) error
- func UserPermissions(reqAdmin bool, token string) (string, error)
- func ValidateAndApproveUserInvite(email, code string) error
- func ValidateCreateAclReq(req models.Acl) error
- func ValidateDNSCreate(entry models.DNSEntry) error
- func ValidateDNSUpdate(change models.DNSEntry, entry models.DNSEntry) error
- func ValidateDomain(domain string) bool
- func ValidateEgressAppNATMode(e schema.Egress) error
- func ValidateEgressCIDR(network *schema.Network, cidr string) error
- func ValidateEgressGateway(gateway models.EgressGatewayRequest) error
- func ValidateEgressProOnlyFeatures(e schema.Egress) error
- func ValidateEgressRange(netID string, ranges []string) error
- func ValidateEgressReqProLimits(req *models.EgressReq) error
- func ValidateInetGwReq(node *schema.Node, req models.InetNodeReq, update bool) error
- func ValidateNetwork(network *schema.Network, isUpdate bool) error
- func ValidateNewSettings(req models.ServerSettings) error
- func ValidateParams(nodeid, netid string) (models.Node, error)
- func ValidateRelay(relay models.RelayRequest, update bool) error
- func ValidateUser(user *schema.User) error
- func VerifyAuthRequest(authRequest models.UserAuthParams, appName string) (string, error)
- func VerifyHostToken(tokenString string) (hostID string, mac string, network string, err error)
- func VerifyOTPAuthURL(url, signature string) bool
- func VerifyUserToken(tokenString string) (username string, issuperadmin, isadmin bool, err error)
- func VersionLessThan(v1, v2 string) (bool, error)
- func WrapHook(hook func() error) models.HookFunc
- type ApiErrorType
- type GlobalNs
- type MetricsMonitor
- type OSInfo
- type ServerSyncType
Constants ¶
const ( DashboardApp = "dashboard" NetclientApp = "netclient" NetmakerDesktopApp = "netmaker-desktop" )
const ( FallbackVNATPool = "198.18.0.0/15" VNATPoolPrefixLen = 22 DefaultSitePrefixV4 = 24 CgnatCIDR = "100.64.0.0/10" )
const ( MasterUser = "masteradministrator" Forbidden_Msg = "forbidden" Forbidden_Err = models.Error(Forbidden_Msg) )
const ( // ZOMBIE_TIMEOUT - timeout in hours for checking zombie status ZOMBIE_TIMEOUT = 6 // ZOMBIE_DELETE_TIME - timeout in minutes for zombie node deletion ZOMBIE_DELETE_TIME = 10 )
const (
GooglePublicNameserverName = "Google Public DNS"
)
const KUBERNETES_LISTEN_PORT = 31821
KUBERNETES_LISTEN_PORT - starting port for Kubernetes in order to use NodePort range
const KUBERNETES_SERVER_MTU = 1024
KUBERNETES_SERVER_MTU - ideal mtu for kubernetes deployments right now
const MinVersion = "v0.17.0"
const StaleStatusCheckInterval = 5 * time.Minute
StaleStatusCheckInterval - how often MarkStaleNodesOffline scans the nodes table looking for nodes whose last check-in is older than models.LastCheckInThreshold.
Variables ¶
var ( CreateDefaultTags = func(netID schema.NetworkID) {} DeleteAllNetworkTags = func(networkID schema.NetworkID) {} IsUserAllowedToCommunicate = func(userName string, peer models.Node) (bool, []models.Acl) { return false, []models.Acl{} } RemoveUserFromAclPolicy = func(userName string) {} EnsureDefaultUserGroupNetworkPolicies = func(old, new *schema.UserGroup) error { return nil } GetGroupNetworksMap = func(group *schema.UserGroup) (map[schema.NetworkID]schema.Network, error) { return nil, nil } )
var ( IPv4Network = "0.0.0.0/0" IPv6Network = "::/0" )
var ( // ErrHostExists error indicating that host exists when trying to create new host ErrHostExists error = errors.New("host already exists") // ErrInvalidHostID ErrInvalidHostID error = errors.New("invalid host id") )
var ( // ResetAutoRelay - function to reset autorelayed peers on this node ResetAutoRelay = func(autoRelayNode *models.Node) error { return nil } // ResetAutoRelayedPeer - removes relayed peers for node ResetAutoRelayedPeer = func(failedOverNode *models.Node) error { return nil } // GetAutoRelayPeerIps - gets autorelay peerips GetAutoRelayPeerIps = func(peer, node *models.Node) []net.IPNet { return []net.IPNet{} } // SetAutoRelay - sets autorelay flag on the node SetAutoRelay = func(node *models.Node) { node.IsAutoRelay = false } )
var ( FreeTier = false // DefaultTrialEndDate - is a placeholder date for not applicable trial end dates DefaultTrialEndDate, _ = time.Parse("2006-Jan-02", "2021-Apr-01") GetTrialEndDate = func() (time.Time, error) { return DefaultTrialEndDate, nil } )
var ( ErrInvalidJwtValidityDuration = errors.New("invalid jwt validity duration") ErrFlowLogsNotSupported = errors.New("flow logs not supported") ErrInvalidIPDetectionInterval = errors.New("invalid ip detection interval (must be greater than or equal to 15s)") )
var AddGlobalGroupOnRoleUpgrade = func(oldRole, newRole schema.UserRoleID, groups map[schema.UserGroupID]struct{}) {
}
var AddGlobalNetRolesToAdmins = func(u *schema.User) {}
var AdminPermissionTemplate = schema.UserRole{ ID: schema.AdminRole, Default: true, FullAccess: true, }
var AssignVirtualRangeToEgress = func(nw *schema.Network, eg *schema.Egress) error { return nil }
var CanUserCreateNetwork = func(ctx context.Context, username string) bool { return true }
var CheckIfAnyPolicyisUniDirectional = func(targetNode models.Node, acls []models.Acl) bool { return false }
var CheckJITAccess = func(string, string) (bool, *schema.JITGrant, error) { return true, nil, nil }
var CheckPostureViolations = func(d models.PostureCheckDeviceInfo, network schema.NetworkID) (v []models.Violation, level schema.Severity) { return []models.Violation{}, schema.SeverityUnknown }
var CleanupGwsMigration = func() {}
var CreateDefaultNetworkRolesAndGroups = func(netID schema.NetworkID) {}
var CreateDefaultUserPolicies = func(netID schema.NetworkID) { if netID.String() == "" { return } if !IsAclExists(fmt.Sprintf("%s.%s", netID, "all-users")) { defaultUserAcl := models.Acl{ ID: fmt.Sprintf("%s.%s", netID, "all-users"), Default: true, Name: "All Users", MetaData: "This policy gives access to everything in the network for an user", NetworkID: netID, Proto: models.ALL, ServiceType: models.Any, Port: []string{}, RuleType: models.UserPolicy, Src: []models.AclPolicyTag{ { ID: models.UserAclID, Value: "*", }, }, Dst: []models.AclPolicyTag{{ ID: models.NodeTagID, Value: "*", }}, AllowedDirection: models.TrafficDirectionUni, Enabled: true, CreatedBy: "auto", CreatedAt: time.Now().UTC(), } InsertAcl(defaultUserAcl) } }
var DeleteMetrics = func(string) error { return nil }
var DeleteNetworkRoles = func(netID string) {}
var DeleteNodeMetricsFromPeers = func(string) {}
var (
DeleteNodesCh = make(chan *models.Node, 100)
)
var DeleteRole = func(r schema.UserRoleID, force bool) error { return nil }
var EmailInit = func() {}
var EnrollmentErrors = struct { InvalidCreate error NoKeyFound error InvalidKey error NoUsesRemaining error FailedToTokenize error FailedToDeTokenize error }{ InvalidCreate: fmt.Errorf("failed to create enrollment key. paramters invalid"), NoKeyFound: fmt.Errorf("no enrollmentkey found"), InvalidKey: fmt.Errorf("invalid key provided"), NoUsesRemaining: fmt.Errorf("no uses remaining"), FailedToTokenize: fmt.Errorf("failed to tokenize"), FailedToDeTokenize: fmt.Errorf("failed to detokenize"), }
EnrollmentErrors - struct for holding EnrollmentKey error messages
var EnterpriseCheckFuncs []func(ctx context.Context, wg *sync.WaitGroup)
EnterpriseCheckFuncs - can be set to run functions for EE
var ErrEgressProOnlyFeature = errors.New("domain and app egress require Netmaker Pro")
ErrEgressProOnlyFeature is returned when domain or app egress is used on Community Edition.
var ErrUnknownEgressPreset = errors.New("unknown egress preset_id")
ErrUnknownEgressPreset is returned when preset_id does not match the catalog.
var ErrVirtualNATNotForEgressApps = errors.New("virtual NAT is not supported for egress apps")
ErrVirtualNATNotForEgressApps is returned when virtual NAT is requested for a preset egress app.
var FilterNetworksByRole = func(allnetworks []schema.Network, user *schema.User) []schema.Network {
return allnetworks
}
var GetDeploymentMode = func() string {
return "self-hosted"
}
var GetEgressUserRulesForNode = func(targetnode *models.Node, rules map[string]models.AclRule) map[string]models.AclRule { return rules }
var GetFeatureFlags = func() models.FeatureFlags { return models.FeatureFlags{} }
var GetFilteredNodesByUserAccess = func(user *schema.User, nodes []models.Node) (filteredNodes []models.Node) {
return
}
var GetFwRulesForNodeAndPeerOnGw = getFwRulesForNodeAndPeerOnGw
var GetFwRulesForUserNodesOnGw = func(node models.Node, nodes []models.Node) (rules []models.FwRule) { return }
var GetMetrics = func(string) (*models.Metrics, error) { var metrics models.Metrics return &metrics, nil }
var GetNameserversForHost = getNameserversForHost
var GetNameserversForNode = getNameserversForNode
var GetNodeStatus = getNodeCheckInStatus
var GetPostureCheckDeviceInfoByNode = func(node *models.Node) (d models.PostureCheckDeviceInfo) {
return
}
var GetTagMapWithNodesByNetwork = getTagMapWithNodesByNetwork
var GetUserAclRulesForNode = func(targetnode *models.Node, rules map[string]models.AclRule) map[string]models.AclRule { return rules }
var GetUserGroup = func(groupId schema.UserGroupID) (userGrps schema.UserGroup, err error) { return }
var GlobalNsList = map[string]GlobalNs{ "Google": { ID: "Google", IPs: []string{ "8.8.8.8", "8.8.4.4", "2001:4860:4860::8888", "2001:4860:4860::8844", }, }, "Cloudflare": { ID: "Cloudflare", IPs: []string{ "1.1.1.1", "1.0.0.1", "2606:4700:4700::1111", "2606:4700:4700::1001", }, }, "Quad9": { ID: "Quad9", IPs: []string{ "9.9.9.9", "149.112.112.112", "2620:fe::fe", "2620:fe::9", }, }, }
var GlobalPermissionsCheck = func(username string, r *http.Request) error { return nil }
var HookCommandCh = make(chan models.HookCommand, 10)
HookCommandCh - channel to send commands to hooks (reset/stop)
var HookManagerCh = make(chan models.HookDetails, 3)
HookManagerCh - channel to add any new hooks
var InitialiseRoles = userRolesInit
var IntialiseGroups = func() {}
var IsAclPolicyValid = func(acl models.Acl) (err error) { if acl.AllowedDirection == models.TrafficDirectionUni { return errors.New("uni traffic flow not allowed on CE") } switch acl.RuleType { case models.DevicePolicy: for _, srcI := range acl.Src { if srcI.Value == "*" { continue } if srcI.ID == models.NodeTagID && srcI.Value == fmt.Sprintf("%s.%s", acl.NetworkID.String(), models.GwTagName) { continue } if err = checkIfAclTagisValid(acl, srcI, true); err != nil { return err } } for _, dstI := range acl.Dst { if dstI.Value == "*" { continue } if dstI.ID == models.NodeTagID && dstI.Value == fmt.Sprintf("%s.%s", acl.NetworkID.String(), models.GwTagName) { continue } if err = checkIfAclTagisValid(acl, dstI, false); err != nil { return } } default: return errors.New("unknown acl policy type " + string(acl.RuleType)) } if err := NormalizeAndValidateAclEgressIPs(&acl); err != nil { return err } return nil }
var IsGroupsValid = func(groups map[schema.UserGroupID]struct{}) error { return nil }
var IsOAuthConfigured = func() bool { return false }
var IsPeerAllowed = func(node, peer models.Node, checkDefaultPolicy bool) bool { var nodeId, peerId string if node.IsStatic { nodeId = node.StaticNode.ClientID node = node.StaticNode.ConvertToStaticNode() } else { nodeId = node.ID.String() } if peer.IsStatic { peerId = peer.StaticNode.ClientID peer = peer.StaticNode.ConvertToStaticNode() } else { peerId = peer.ID.String() } peerTags := make(map[models.TagID]struct{}) nodeTags := make(map[models.TagID]struct{}) nodeTags[models.TagID(nodeId)] = struct{}{} peerTags[models.TagID(peerId)] = struct{}{} if peer.IsGw { peerTags[models.TagID(fmt.Sprintf("%s.%s", peer.Network, models.GwTagName))] = struct{}{} } if node.IsGw { nodeTags[models.TagID(fmt.Sprintf("%s.%s", node.Network, models.GwTagName))] = struct{}{} } if checkDefaultPolicy { defaultPolicy, err := GetDefaultPolicy(schema.NetworkID(node.Network), models.DevicePolicy) if err == nil { if defaultPolicy.Enabled { return true } } } policies := ListDevicePolicies(schema.NetworkID(peer.Network)) srcMap := make(map[string]struct{}) dstMap := make(map[string]struct{}) defer func() { srcMap = nil dstMap = nil }() for _, policy := range policies { if !policy.Enabled { continue } if IsEgressRoutingPolicyAllowedForNodes(policy, node, peer) { return true } srcMap = ConvAclTagToValueMap(policy.Src) dstMap = ConvAclTagToValueMap(policy.Dst) for _, dst := range policy.Dst { if dst.ID == models.EgressID { e := schema.Egress{ID: dst.Value} err := e.Get(db.WithContext(context.TODO())) if err == nil && e.Status { for nodeID := range e.Nodes { dstMap[nodeID] = struct{}{} } } } } if CheckTagGroupPolicy(srcMap, dstMap, node, peer, nodeTags, peerTags) { return true } } return false }
var LogEvent = func(a *models.Event) {}
var NetworkHook models.HookFunc = func(params ...interface{}) error { networks, err := (&schema.Network{}).ListAll(db.WithContext(context.TODO())) if err != nil { return err } allNodes, err := GetAllNodes() if err != nil { return err } for _, network := range networks { if !network.AutoRemove || network.AutoRemoveThreshold == 0 { continue } nodes := GetNetworkNodesMemory(allNodes, network.Name) for _, node := range nodes { if !node.Connected { continue } exists := false for _, tagI := range network.AutoRemoveTags { if tagI == "*" { exists = true break } if _, ok := node.Tags[models.TagID(tagI)]; ok { exists = true break } } if !exists { continue } if time.Since(node.LastCheckIn) > time.Duration(network.AutoRemoveThreshold)*time.Minute { if err := DeleteNode(&node, true); err != nil { continue } node.PendingDelete = true node.Action = schema.NODE_DELETE DeleteNodesCh <- &node host := &schema.Host{ID: node.HostID} if err := host.Get(db.WithContext(context.TODO())); err == nil && len(host.Nodes) == 0 { (&schema.Host{ID: host.ID}).Delete(db.WithContext(context.TODO())) } } } } return nil }
var NetworkPermissionsCheck = func(username string, r *http.Request) error { return nil }
var PlatformRoleRequiresGroupEnforcement = func(role schema.UserRoleID) bool { return false }
var PublishServerSync func(syncType ServerSyncType)
PublishServerSync is set by the mq package at startup to broadcast sync signals to peer servers in HA mode. The callback avoids a circular import (logic -> mq).
var ResetAuthProvider = func() {}
var ResetIDPSyncHook = func() {}
var ServerSettingsDBKey = "server_cfg"
var SetPeerMetricsDisconnected = func(string) {}
var SettingsMutex = &sync.RWMutex{}
var StartFlowCleanupLoop = func() {}
var StopFlowCleanupLoop = func() {}
var StripGroupsOnRoleDowngrade = func(oldRole, newRole schema.UserRoleID, groups map[schema.UserGroupID]struct{}) {
}
var SuperAdminPermissionTemplate = schema.UserRole{ ID: schema.SuperAdminRole, Default: true, FullAccess: true, }
Pre-Define Permission Templates for default Roles
var SyncFromIDP = func() error { return nil }
var TriggerCollectMetrics = func(hostID, nodeID, reason string) {}
TriggerCollectMetrics - asks the client to push metrics now. Overridden in Pro. reason is a short label (e.g. "join", "reconnect", "checkin_recovered") used for logging.
var UpdateUserGwAccess = func(currentUser, changeUser *schema.User) {}
var UserHasGlobalNetworksAdminMembership = func(user *schema.User) bool { return false }
var UserHasNetworkGroupAccess = func(user *schema.User, networkID string) bool { return false }
var ValidateEgressReq = validateEgressReq
var ValidateNameserverReq = validateNameserverReq
Functions ¶
func AddEgressInfoToPeerByAccess ¶ added in v0.99.0
func AddHook ¶
func AddHook(ifaceToAdd interface{})
AddHook - adds a hook function to run every 24hrs
func AddSSOStateCleanupHook ¶ added in v1.5.1
func AddSSOStateCleanupHook()
AddSSOStateCleanupHook registers a periodic cleanup of expired SSO states
func AddStaticNodestoList ¶ added in v0.26.0
func AddStatusToNodes ¶ added in v0.30.0
func AllDomainAnsFromEgress ¶ added in v1.6.0
AllDomainAnsFromEgress returns the flattened union of per-domain answers (ACL/routing).
func AllocateUniquePoolFromFallback ¶ added in v1.5.1
func AllocateUniquePoolFromFallback(pool *net.IPNet, newPrefixLen int, allocated map[string]struct{}, seed string) string
AllocateUniquePoolFromFallback allocates a unique subnet of the given prefix length from the fallback pool, skipping any subnets already present in the allocated map.
func AllocateUniqueVNATPool ¶ added in v1.5.1
AllocateUniqueVNATPool allocates a unique Virtual NAT pool for a network, ensuring it doesn't conflict with pools already assigned to other networks.
func ApplyConfiguredDomainsToEgress ¶ added in v1.6.0
ApplyConfiguredDomainsToEgress sets Domains on the egress record.
func ApplyEgressPresetToEgressReq ¶ added in v1.6.0
ApplyEgressPresetToEgressReq merges catalog defaults into req. Rules: explicit non-empty name, description, and domains in req override preset. PresetID must already be a known id.
func AssignVirtualNATDefaults ¶ added in v1.5.1
AssignVirtualNATDefaults determines safe defaults based on VPN CIDR
func AssociateNodeToHost ¶
AssociateNodeToHost - associates a node with a host and persists both.
func AutoUpdateEnabled ¶ added in v0.99.0
func AutoUpdateEnabled() bool
AutoUpdateEnabled returns a boolean indicating whether netclient auto update is enabled or disabled default is enabled
func CheckEndpoint ¶
CheckEndpoint - checks if an endpoint is valid
func CheckHostPorts ¶
CheckHostPort checks host endpoints to ensures that hosts on the same server with the same endpoint have different listen ports in the case of 64535 hosts or more with same endpoint, ports will not be changed
func CheckIfFileExists ¶
CheckIfFileExists - checks if file exists or not in the given path
func CheckTagGroupPolicy ¶ added in v0.99.0
func CheckZombies ¶
CheckZombies - checks if new node has same hostid as existing node if so, existing node is added to zombie node quarantine list also cleans up nodes past their expiration date
func CleanExpiredSSOStates ¶ added in v1.5.1
func CleanExpiredSSOStates() error
CleanExpiredSSOStates removes expired SSO state entries from the database to prevent unbounded table growth that degrades FetchRecord performance.
func CleanVersion ¶ added in v1.4.0
CleanVersion normalizes a version string safely for storage. - removes "v" or "V" prefix - trims whitespace - strips invalid trailing characters - preserves semver, prerelease, and build metadata
func CleanupOtherExtclients ¶ added in v1.5.1
CleanupOtherExtclients cleans up other clients owned by the same use for the same device and network.
func ClearEgressDomainAns ¶ added in v1.6.0
ClearEgressDomainAns clears per-domain answers.
func CompareIfaceSlices ¶ added in v1.1.0
CompareIfaceSlices compares two slices of Iface for deep equality (order-sensitive)
func CompareMaps ¶ added in v0.99.0
func CompareMaps[K comparable, V any](a, b map[K]V) bool
Compare any two maps with any key and value types
func ConfiguredDomainsForEgress ¶ added in v1.6.0
ConfiguredDomainsForEgress returns the user-configured hostname list from e.Domains (JSON). It does not read the legacy DB column "domain" (singular); that is migrated once in migrateEgressDomains.
func ContainsCIDR ¶ added in v0.24.3
func ContinueIfUserMatch ¶
func ContinueIfUserMatch(next http.Handler) http.HandlerFunc
func ContinueIfUserMatchOrAdmin ¶ added in v1.6.0
func ContinueIfUserMatchOrAdmin(next http.Handler) http.HandlerFunc
func ConvAclTagToValueMap ¶ added in v0.99.0
func ConvAclTagToValueMap(acltags []models.AclPolicyTag) map[string]struct{}
func ConvHostPassToHash ¶
ConvHostPassToHash - converts password to md5 hash
func ConvertModelsNodeToSchemaNode ¶ added in v1.6.0
func ConvertSchemaNodeToApiNode ¶ added in v1.6.0
func ConvertSchemaNodeToModelsNode ¶ added in v1.6.0
func CreateDefaultAclNetworkPolicies ¶ added in v0.26.0
CreateDefaultAclNetworkPolicies - create default acl network policies
func CreateEgressGateway ¶
func CreateEgressGateway(gateway models.EgressGatewayRequest) (models.Node, error)
CreateEgressGateway - creates an egress gateway
func CreateEnrollmentKey ¶
func CreateEnrollmentKey(uses int, expiration time.Time, networks, tags []string, groups []models.TagID, unlimited bool, relay uuid.UUID, defaultKey, autoEgress, autoAssignGw bool) (*models.EnrollmentKey, error)
CreateEnrollmentKey - creates a new enrollment key in db
func CreateFallbackNameserver ¶ added in v1.4.0
func CreateNetwork ¶
CreateNetwork - creates a network in database
func CreatePreAuthToken ¶ added in v1.0.0
CreatePreAuthToken generate a jwt token to be used as intermediate token after primary-factor authentication but before secondary-factor authentication.
func CreateSuperAdmin ¶
CreateSuperAdmin - creates an super admin user
func CreateUserAccessJwtToken ¶ added in v0.99.0
func CreateUserAccessJwtToken(username string, role schema.UserRoleID, d time.Time, tokenID string) (response string, err error)
CreateUserJWT - creates a user jwt token
func CreateUserJWT ¶
func CreateUserJWT(username string, role schema.UserRoleID, appName string) (response string, err error)
CreateUserJWT - creates a user jwt token
func DeTokenize ¶
func DeTokenize(b64Token string) (*models.EnrollmentKey, error)
DeTokenize - detokenizes a base64 encoded string and finds the associated enrollment key
func DeleteEgressGateway ¶
DeleteEgressGateway - deletes egress from node
func DeleteEnrollmentKey ¶
DeleteEnrollmentKey - delete's a given enrollment key by value
func DeleteExpiredNodes ¶
DeleteExpiredNodes - goroutine which deletes nodes which are expired
func DeleteExtClient ¶
DeleteExtClient - deletes an existing ext client
func DeleteExtClientAndCleanup ¶ added in v0.24.1
DeleteExtClientAndCleanup - deletes an existing ext client and update ACLs
func DeleteGatewayExtClients ¶
DeleteGatewayExtClients - deletes ext clients based on gateway (mac) of ingress node and network
func DeleteIngressGateway ¶
DeleteIngressGateway - deletes an ingress gateway
func DeleteNetwork ¶
DeleteNetwork - deletes a network
func DeleteNetworkDNS ¶ added in v1.6.0
func DeleteNetworkPolicies ¶ added in v0.90.0
DeleteNetworkPolicies - deletes all default network acl policies
func DeleteNodeByID ¶ added in v0.21.2
DeleteNodeByID - deletes a node from database
func DeletePendingUser ¶ added in v0.24.0
func DeleteRelay ¶ added in v0.90.0
DeleteRelay - deletes a relay
func DeleteUserInvite ¶ added in v0.25.0
func DeleteUserSettings ¶ added in v1.1.0
func DisassociateAllNodesFromHost ¶
DisassociateAllNodesFromHost - deletes all nodes of the host. Performs reference cleanup and directly deletes each node record, bypassing host-association updates since the host itself is being removed.
func DisplaceAutoRelayedNodes ¶ added in v1.5.1
DisplaceAutoRelayedNodes removes auto-assigned nodes from a disconnected gateway and returns the displaced nodes that need re-assignment.
func DissasociateNodeFromHost ¶
DissasociateNodeFromHost - deletes a node and removes from host nodes should be the only way nodes are deleted as of 0.18
func DoesHostExistInTheNetworkAlready ¶ added in v1.6.0
DoesHostExistInTheNetworkAlready checks if the host is in the network already. Must be called before creating the node. TODO: create (*orchestrator.NodeOrchestrator).ValidateCreateNode and move this there.
func DoesNodeHaveAccessToEgress ¶ added in v0.99.0
func DoesUserHaveAccessToEgress ¶ added in v1.1.0
func DomainAnsForDomain ¶ added in v1.6.0
DomainAnsForDomain returns resolved CIDRs for one configured domain.
func DomainAnsMapFromEgress ¶ added in v1.6.0
DomainAnsMapFromEgress returns domain -> resolved CIDRs from domain_ans_by_domain.
func EgressDomainsEqual ¶ added in v1.6.0
EgressDomainsEqual compares two domain lists as sets (order-independent).
func EnterpriseCheck ¶
EnterpriseCheck - Runs enterprise functions if presented
func FetchAuthSecret ¶
FetchAuthSecret - manages secrets for oauth
func FetchJWTSecret ¶
FetchJWTSecret - fetches jwt secret from db
func FetchPassValue ¶ added in v0.25.0
func FetchTelemetryData ¶ added in v0.23.0
func FetchTelemetryData() telemetryData
FetchTelemetryData - fetches telemetry data: count of various object types in DB
func FetchTelemetryRecord ¶ added in v0.23.0
FetchTelemetryRecord - get the existing UUID and Timestamp from the DB
func FilterOutIPs ¶ added in v1.2.0
FilterOutIPs removes ips in the filters map from the ips slice.
func FlattenDomainAnsMap ¶ added in v1.6.0
FlattenDomainAnsMap returns a de-duplicated union of all resolved CIDRs in the map.
func FlushNodeCheckins ¶ added in v1.5.1
func FlushNodeCheckins()
FlushNodeCheckins - writes all buffered check-in updates to the DB in one batch. Called periodically (e.g., every 30s) to avoid per-checkin write lock contention.
func FormatError ¶
func FormatError(err error, errType ApiErrorType) models.ErrorResponse
FormatError - takes ErrorResponse and uses correct code
func GenerateNodeName ¶ added in v0.30.0
func GenerateOTPAuthURLSignature ¶ added in v1.0.0
func GetAclRuleForInetGw ¶ added in v0.99.0
func GetAclRulesForNode ¶ added in v0.30.0
func GetAllEnrollmentKeys ¶
func GetAllEnrollmentKeys() ([]models.EnrollmentKey, error)
GetAllEnrollmentKeys - fetches all enrollment keys from DB
func GetAllExtClients ¶
GetAllExtClients - gets all ext clients from DB
func GetAllExtClientsWithStatus ¶ added in v0.99.0
func GetAllExtClientsWithStatus(status schema.NodeStatus) ([]models.ExtClient, error)
GetAllExtClientsWithStatus - returns all external clients with given status.
func GetAllHostsAPI ¶
GetAllHostsAPI - get's all the hosts in an API usable format
func GetAllHostsWithStatus ¶ added in v0.99.0
func GetAllHostsWithStatus(status schema.NodeStatus) ([]schema.Host, error)
GetAllHostsWithStatus - returns all hosts with at least one node with given status.
func GetAllNodes ¶
GetAllNodes - returns all nodes in the DB
func GetAllNodesAPI ¶
GetAllNodesAPI - get all nodes for api usage
func GetAllNodesAPIWithLocation ¶ added in v1.0.0
GetAllNodesAPI - get all nodes for api usage
func GetAllRsrcIDForRsrc ¶ added in v1.1.0
func GetAllowedEmailDomains ¶ added in v0.99.0
func GetAllowedEmailDomains() string
GetAllowedEmailDomains - gets the allowed email domains for oauth signup
func GetAllowedIPs ¶
GetAllowedIPs - calculates the wireguard allowedip field for a peer of a node based on the peer and node settings
func GetAllowedIpForInetNodeClient ¶ added in v0.23.0
GetAllowedIpForInetNodeClient - get inet cidr for node using a inet gw
func GetAllowedIpsForRelayed ¶
GetAllowedIpsForRelayed - returns the peerConfig for a node relayed by relay
func GetAuthProviderInfo ¶ added in v0.99.0
func GetAuthProviderInfo(settings models.ServerSettings) (pi []string)
GetAuthProviderInfo = gets the oauth provider info
func GetAzureTenant ¶ added in v0.99.0
func GetAzureTenant() string
GetAzureTenant - retrieve the azure tenant ID from env variable or config file
func GetCachedHostPeerUpdate ¶ added in v1.5.1
func GetCachedHostPeerUpdate(hostID string) (models.HostPeerUpdate, bool)
GetCachedHostPeerUpdate - returns a cached HostPeerUpdate if available.
func GetClientIP ¶ added in v1.0.0
func GetCurrentServerUsage ¶ added in v1.2.0
func GetCustomDNS ¶
GetCustomDNS - gets the custom DNS of a network
func GetDNSEntryNum ¶
GetDNSEntryNum - gets which entry the dns was
func GetDefaultDomain ¶ added in v0.99.0
func GetDefaultDomain() string
GetDefaultDomain - get the default domain
func GetDefaultEnrollmentKeyForNetwork ¶ added in v1.6.0
func GetDefaultEnrollmentKeyForNetwork(network string) (models.EnrollmentKey, error)
GetDefaultEnrollmentKeyForNetwork returns the default enrollment key for a network.
func GetDefaultHosts ¶
GetDefaultHosts - retrieve all hosts marked as default from DB
func GetDefaultPolicy ¶ added in v0.26.0
GetDefaultPolicy - fetches default policy in the network by ruleType
func GetEgressDefaultAllowAllFwRule ¶ added in v1.6.0
GetEgressDefaultAllowAllFwRule returns one bidirectional allow from the node's VPN (mesh) CIDR(s) to every egress LAN range this gateway advertises, for default all-resources device+user policies. Netclients use this to install a single mesh → LAN ACCEPT (e.g. 100.64.0.0/16 → 10.104.0.0/20).
func GetEgressDomainNSForNode ¶ added in v1.4.0
func GetEgressDomainNSForNode(node *models.Node) (returnNsLi []models.Nameserver)
func GetEgressDomainsByAccessForUser ¶ added in v1.4.0
func GetEgressPresetByID ¶ added in v1.6.0
func GetEgressPresetByID(id string) (models.EgressPresetApp, bool)
GetEgressPresetByID returns a catalog entry by id.
func GetEgressRanges ¶ added in v0.90.0
func GetEgressRangesOnNetwork ¶
ExtClient.GetEgressRangesOnNetwork - returns the egress ranges on network of ext client
func GetEgressRulesForNode ¶ added in v0.90.0
func GetEmaiSenderPassword ¶ added in v0.99.0
func GetEmaiSenderPassword() string
func GetEnrollmentKey ¶
func GetEnrollmentKey(value string) (key models.EnrollmentKey, err error)
GetEnrollmentKey - fetches a single enrollment key returns nil and error if not found
func GetExtClient ¶
GetExtClient - gets a single ext client on a network
func GetExtClientByName ¶
GetExtClientByName - gets an ext client by name
func GetExtClientsByID ¶
GetExtClientsByID - gets the clients of attached gateway
func GetExtPeers ¶ added in v0.24.2
func GetExtPeers(node, peer *models.Node, addressIdentityMap map[string]models.PeerIdentity) ([]wgtypes.PeerConfig, []models.IDandAddr, []models.EgressNetworkRoutes, error)
func GetExtclientAllowedIPs ¶ added in v0.22.0
func GetExtclientDNS ¶ added in v0.22.0
GetExtclientDNS - gets all extclients dns entries
func GetFwRulesOnIngressGateway ¶ added in v0.26.0
func GetHostByNodeID ¶
GetHostByNodeID - returns a host if found to have a node's ID, else nil
func GetHostNetworks ¶
GetHostNetworks - fetches all the networks
func GetHostNodes ¶
GetHostNodes - fetches all nodes part of the host
func GetHostPeerInfo ¶ added in v0.90.0
func GetHostPeerInfo(host *schema.Host) (models.HostPeerInfo, error)
GetHostPeerInfo - returns cached peer info for a host. Falls back to on-demand computation if the cache is not yet populated.
func GetIDPSyncInterval ¶ added in v0.99.0
GetIDPSyncInterval returns the interval at which the netmaker should sync data from IDP.
func GetIngressGwUsers ¶
func GetIngressGwUsers(node models.Node) (models.IngressGwUsers, error)
GetIngressGwUsers - lists the users having to access to ingressGW
func GetJwtValidityDuration ¶ added in v0.99.0
GetJwtValidityDuration - returns the JWT validity duration in minutes
func GetJwtValidityDurationForClients ¶ added in v1.1.0
GetJwtValidityDurationForClients returns the JWT validity duration in minutes for clients.
func GetManageDNS ¶ added in v0.99.0
func GetManageDNS() bool
GetManageDNS - if manage DNS enabled or not
func GetMetricInterval ¶ added in v0.99.0
func GetMetricInterval() string
GetMetricInterval - get the publish metric interval
func GetMetricIntervalInMinutes ¶ added in v0.99.0
GetMetricIntervalInMinutes returns the publish-to-exporter interval from server settings (dashboard), with fallback to servercfg / env when unset or invalid.
func GetNetworkExtClients ¶
GetNetworkExtClients - gets the ext clients of given network
func GetNetworkNetworkCIDR4 ¶ added in v1.5.1
func GetNetworkNetworkCIDR6 ¶ added in v1.5.1
func GetNetworkNodes ¶
GetNetworkNodes - gets the nodes of a network
func GetNetworkNodesMemory ¶
GetNetworkNodesMemory - gets all nodes belonging to a network from list in memory
func GetNetworkNonServerNodeCount ¶
GetNetworkNonServerNodeCount - get number of network non server nodes
func GetNodeByHostRef ¶ added in v0.21.2
GetNodeByHostRef - gets the node by host id and network
func GetNodeCheckInStatus ¶ added in v0.90.0
func GetNodeCheckInStatus(node *schema.Node) schema.NodeStatus
func GetNodeDNS ¶
GetNodeDNS - gets the DNS of a network node
func GetNodeEgressInfo ¶ added in v0.99.0
func GetNodesByIDs ¶ added in v1.6.0
GetNodesByIDs fetches all nodes whose IDs are in the given slice in a single preloaded query and returns them as a map keyed by node ID. IDs that don't resolve to a node row are simply absent from the result map.
This avoids the N+1 (and N^2) query patterns that arise when callers loop over peer IDs and call GetNodeByID per peer (e.g. status / connectivity checks driven by metrics).
func GetNodesStatusAPI ¶ added in v0.90.0
func GetNodesStatusAPI(nodes []models.Node) map[string]models.ApiNodeStatus
GetNodesStatusAPI - gets nodes status
func GetOnboardingStatus ¶ added in v1.6.0
GetOnboardingStatus reports whether the UI should show the first-network onboarding flow.
func GetPeerListenPort ¶
GetPeerListenPort - given a host, retrieve it's appropriate listening port
func GetPeerUpdateForHost ¶
func GetPeerUpdateForHost(network string, host *schema.Host, allNodes []models.Node, deletedHost *schema.Host, deletedNode *models.Node, deletedClients []models.ExtClient) (hostPeerUpdate models.HostPeerUpdate, err error)
GetPeerUpdateForHost - gets the consolidated peer update for the host from all networks
func GetRacRestrictToSingleNetwork ¶ added in v0.99.0
func GetRacRestrictToSingleNetwork() bool
GetRacRestrictToSingleNetwork - returns whether the feature to allow simultaneous network connections via RAC is enabled
func GetRecordKey ¶
GetRecordKey - get record key depricated
func GetRelatedHosts ¶
GetRelatedHosts - fetches related hosts of a given host
func GetReturnUser ¶
func GetReturnUser(username string) (models.ReturnUser, error)
GetReturnUser - gets a user
func GetRunningHooks ¶ added in v1.4.0
func GetRunningHooks() []string
GetRunningHooks - returns a list of currently running hook IDs
func GetSenderEmail ¶ added in v0.99.0
func GetSenderEmail() string
func GetSenderUser ¶ added in v0.99.0
func GetSenderUser() string
func GetServerConfig ¶ added in v0.99.0
func GetServerConfig() config.ServerConfig
GetServerConfig - gets the server config into memory from file or env
func GetServerInfo ¶ added in v0.99.0
func GetServerInfo() models.ServerConfig
GetServerInfo - gets the server config into memory from file or env
func GetServerSettings ¶ added in v0.99.0
func GetServerSettings() (s models.ServerSettings)
func GetServerSettingsFromEnv ¶ added in v0.99.0
func GetServerSettingsFromEnv() (s models.ServerSettings)
func GetSmtpHost ¶ added in v0.99.0
func GetSmtpHost() string
func GetSmtpPort ¶ added in v0.99.0
func GetSmtpPort() int
func GetStaticNodesByNetwork ¶ added in v0.26.0
func GetStunServers ¶ added in v0.99.0
func GetStunServers() string
func GetSuperAdmin ¶
func GetSuperAdmin() (models.ReturnUser, error)
GetSuperAdmin - fetches superadmin user
func GetUserInvite ¶ added in v0.25.0
func GetUserInvite(email string) (*schema.UserInvite, error)
func GetUserNameFromToken ¶ added in v0.25.0
func GetUserSettings ¶ added in v1.1.0
func GetUserSettings(userID string) models.UserSettings
func GetVerbosity ¶ added in v0.99.0
func GetVerbosity() int32
func HasEgressDomainAns ¶ added in v1.6.0
HasEgressDomainAns is true when at least one resolved CIDR exists for any domain.
func HasSuperAdmin ¶
HasSuperAdmin - checks if server has an superadmin/owner
func HostExists ¶
HostExists - checks if given host already exists
func IfaceDelta ¶
IfaceDelta - checks if the new node causes an interface change
func InitNetworkHooks ¶ added in v1.4.0
func InitNetworkHooks()
func InitializeZombies ¶
func InitializeZombies()
InitializeZombies - populates the zombie quarantine list (should be called from initialization)
func InvalidateHostPeerCaches ¶ added in v1.5.1
func InvalidateHostPeerCaches()
InvalidateHostPeerCaches clears both hostPeerInfoCache and hostPeerUpdateCache so they are rebuilt on next access or refresh.
func InvalidateServerSettingsCache ¶ added in v1.5.1
func InvalidateServerSettingsCache()
InvalidateServerSettingsCache clears the in-memory settings cache so the next GetServerSettings call re-reads from the database.
func IsAWSEgressPreset ¶ added in v1.6.0
IsAWSEgressPreset reports whether presetID refers to an AWS catalog entry.
func IsAclExists ¶ added in v0.26.0
IsAclExists - checks if acl exists
func IsAddressInCIDR ¶
IsAddressInCIDR - util to see if an address is in a cidr or not
func IsBase64 ¶
IsBase64 - checks if a string is in base64 format This is used to validate public keys (make sure they're base64 encoded like all public keys should be).
func IsBasicAuthEnabled ¶ added in v0.99.0
func IsBasicAuthEnabled() bool
IsBasicAuthEnabled - checks if basic auth has been configured to be turned off
func IsDNSEntryValid ¶ added in v0.30.0
IsNetworkNameValid - checks if a netid of a network uses valid characters
func IsDomainBasedEgress ¶ added in v1.6.0
IsDomainBasedEgress is true when this egress has at least one configured logical domain.
func IsEgressAppEgress ¶ added in v1.6.0
IsEgressAppEgress reports whether the egress was created from a catalog preset (egress app).
func IsEgressDomainPattern ¶ added in v1.6.0
IsEgressDomainPattern returns true for a normal FQDN or a single-label wildcard prefix form (*.example.com).
func IsEgressInternetGateway ¶ added in v1.6.0
IsEgressInternetGateway is true when range is "*" (full internet egress).
func IsEgressReqInternetGateway ¶ added in v1.6.0
IsEgressReqInternetGateway is true when the request uses range "*" for internet egress.
func IsEgressRoutingPolicyAllowedForNodes ¶ added in v1.6.0
IsEgressRoutingPolicyAllowedForNodes reports whether `policy` permits a peering relationship (and corresponding mesh peer ACL rule) between `node` and `peer` on either side of an egress<->egress flow. WireGuard peering is inherently bidirectional: even a Uni "src-egress -> dst-egress" policy requires the src-router and dst-router hosts to complete a wg handshake so the tunnel can carry the one-way L4 traffic. The L4 direction (Uni vs Bi) is then enforced downstream by the FORWARD/INPUT rule generators, not at peer-allow time. We therefore accept the policy whenever EITHER side of the pair routes the matching egress, otherwise the dst-side router would never add the src-side router as a peer (callers query symmetrically as (X, Y) and (Y, X)) and the handshake would silently never occur.
func IsEndpointDetectionEnabled ¶ added in v0.99.0
func IsEndpointDetectionEnabled() bool
IsEndpointDetectionEnabled - returns true if endpoint detection enabled
func IsFQDN ¶ added in v1.1.0
IsFQDN checks if the given string is a valid Fully Qualified Domain Name (FQDN)
func IsInternetGw ¶ added in v0.22.0
IsInternetGw - checks if node is acting as internet gw
func IsMFAEnforced ¶ added in v1.0.0
func IsMFAEnforced() bool
IsMFAEnforced returns whether MFA has been enforced.
func IsNetworkCIDRUnique ¶ added in v0.21.2
func IsNetworkNameUnique ¶
IsNetworkNameUnique - checks to see if any other networks have the same name (id)
func IsNodeAllowedToCommunicate ¶ added in v0.26.0
func IsNodeAllowedToCommunicate(node, peer models.Node, checkDefaultPolicy bool) (bool, []models.Acl)
IsNodeAllowedToCommunicate - check node is allowed to communicate with the peer // ADD ALLOWED DIRECTION - 0 => node -> peer, 1 => peer-> node,
func IsNodeAllowedToCommunicateWithAllRsrcs ¶ added in v1.1.0
func IsPendingUser ¶ added in v0.24.0
func IsSlicesEqual ¶ added in v0.22.0
IsSlicesEqual tells whether a and b contain the same elements. A nil argument is equivalent to an empty slice.
func IsStateValid ¶
IsStateValid - checks if given state is valid or not deletes state after call is made to clean up, should only be called once per sign-in
func IsStunEnabled ¶ added in v0.99.0
func IsStunEnabled() bool
IsStunEnabled - returns true if STUN set to on
func IsSyncEnabled ¶ added in v0.99.0
func IsSyncEnabled() bool
IsSyncEnabled returns whether auth provider sync is enabled.
func IsUserAllowedAccessToExtClient ¶
IsUserAllowedAccessToExtClient - checks if user has permission to access extclient
func IsValidMatchDomain ¶ added in v1.1.0
IsValidMatchDomain reports whether s is a valid "match domain". Rules (simple/ASCII):
- "~." is allowed (match all).
- Optional leading "~" allowed (e.g., "~example.com").
- Optional single trailing "." allowed (FQDN form).
- No wildcards "*", no leading ".", no underscores.
- Labels: letters/digits/hyphen (LDH), 1–63 chars, no leading/trailing hyphen.
- Total length (without trailing dot) ≤ 253.
func IsValidVersion ¶ added in v1.4.0
IsValidVersion returns true if the version string can be parsed as semantic version.
func IsVersionCompatible ¶ added in v0.24.1
IsVersionCompatible checks that the version passed is compabtible (>=) with MinVersion
func ListAclsByNetwork ¶ added in v0.30.0
ListAcls - lists all acl policies
func ListAllByRoutingNodeWithDomain ¶ added in v1.1.0
func ListAllByRoutingNodeWithDomain(egs []schema.Egress, nodeID string) (egWithDomain []models.EgressDomain)
func ListDevicePolicies ¶ added in v0.99.0
ListDevicePolicies - lists all device policies in a network
func ListEgressAcls ¶ added in v0.99.0
ListEgressAcls - list egress acl policies
func ListEgressPresets ¶ added in v1.6.0
func ListEgressPresets() []models.EgressPresetApp
ListEgressPresets returns the static egress preset catalog (defensive copy of slice header; entries are values).
func ListUserPolicies ¶ added in v0.26.0
ListUserPolicies - lists all user policies in a network
func ManageZombies ¶
ManageZombies - goroutine which adds/removes/deletes nodes from the zombie node quarantine list
func MarkStaleNodesOffline ¶ added in v1.6.0
MarkStaleNodesOffline runs on a ticker and bulk-updates the status of every node whose last_check_in is older than models.LastCheckInThreshold to schema.OfflineSt. Promotion back to OnlineSt happens in mq.HandleHostCheckin when a node recovers; the metrics-driven path in pro/logic refines the status further on the next metrics message.
Intended to be started once from the master pod.
func MigrateAclPolicies ¶ added in v0.30.0
func MigrateAclPolicies()
func NetworkExists ¶
NetworkExists - check if network exists
func NormalizeAndValidateAclEgressIPs ¶ added in v1.6.0
func NormalizeCIDR ¶
NormalizeCIDR - returns the first address of CIDR
func NormalizeEgressReqDomains ¶ added in v1.6.0
NormalizeEgressReqDomains validates each domain entry (FQDN or *.suffix), lowercases, and deduplicates while preserving input order.
func NormalizeIPOrCIDR ¶ added in v1.6.0
func NormalizeOSName ¶ added in v1.4.0
func NotifyMetricExportIntervalChanged ¶ added in v1.6.0
func NotifyMetricExportIntervalChanged()
NotifyMetricExportIntervalChanged signals mq.Keepalive to reset the metrics export ticker.
func NthSubnet ¶ added in v1.5.1
NthSubnet calculates the nth subnet of a given prefix length within a pool.
func OSFamily ¶ added in v1.4.0
OSFamily returns a normalized OS family string. Examples: "linux-debian", "linux-redhat", "linux-arch", "linux-other", "windows", "darwin"
func PopulateAclPolicyTagNames ¶ added in v1.5.1
PopulateAclPolicyTagNames resolves human-readable names for ACL policy tags
func PreAuthCheck ¶ added in v1.0.0
func PreAuthCheck(next http.Handler) http.HandlerFunc
func PresetYieldsAWSIPRanges ¶ added in v1.6.0
func PresetYieldsAWSIPRanges(p models.EgressPresetApp) bool
PresetYieldsAWSIPRanges reports whether the preset is backed by AWS ip-ranges.json.
func RandomString ¶
RandomString - returns a random string in a charset
func RefreshHostPeerInfoCache ¶ added in v1.5.1
RefreshHostPeerInfoCache - batch pre-computes peer info for all hosts and stores the results in the cache. Returns the fetched hosts and nodes so callers can reuse them without redundant DB queries.
func RegenerateEnrollmentKeyToken ¶ added in v1.6.0
func RegenerateEnrollmentKeyToken(keyID string) (*models.EnrollmentKey, error)
RegenerateEnrollmentKeyToken replaces the enrollment key value, invalidating any previously issued registration tokens while preserving key configuration.
func RelayUpdates ¶
func RemoveAllFromSlice ¶ added in v1.2.0
func RemoveAllFromSlice[T comparable](s []T, val T) []T
RemoveAllFromSlice removes every occurrence of val from s (stable order).
func RemoveHost ¶
RemoveHost - removes a given host from server
func RemoveNodeFromAclPolicy ¶ added in v0.90.0
func RemoveNodeFromEgress ¶ added in v0.99.0
func RemoveNodeFromEnrollmentKeys ¶ added in v1.5.1
func RemoveStringSlice ¶
RemoveStringSlice - removes an element at given index i from a given string slice
func RemoveTagFromEnrollmentKeys ¶ added in v0.26.0
func RequiresProEgressType ¶ added in v1.6.0
RequiresProEgressType reports whether the egress uses domain-based or preset app routing.
func ResetHook ¶ added in v1.4.0
func ResetHook(hookID string)
ResetHook - resets the timer for a hook with the given ID
func ResolveAWSEgressPresetCIDRs ¶ added in v1.6.0
ResolveAWSEgressPresetCIDRs fetches public AWS CIDR data for a supported AWS preset.
func RestartHook ¶ added in v1.4.0
RestartHook - restarts a hook with the given ID (stops and starts again with same configuration) If newInterval is 0, uses the existing interval. Otherwise, uses the new interval.
func RetrievePrivateTrafficKey ¶
RetrievePrivateTrafficKey - retrieves private key of server
func RetrievePublicTrafficKey ¶
RetrievePublicTrafficKey - retrieves public key of server
func ReturnAcceptedResponse ¶ added in v1.5.1
func ReturnAcceptedResponse(response http.ResponseWriter, request *http.Request, message string)
ReturnAcceptedResponse - returns 202 Accepted for async operations
func ReturnErrorResponse ¶
func ReturnErrorResponse(response http.ResponseWriter, request *http.Request, errorMessage models.ErrorResponse)
ReturnErrorResponse - processes error and adds header
func ReturnErrorResponseWithJson ¶ added in v1.4.0
func ReturnErrorResponseWithJson(response http.ResponseWriter, request *http.Request, msg interface{}, errorMessage models.ErrorResponse)
ReturnErrorResponseWithJson - processes error with body and adds header
func ReturnSuccessResponse ¶
func ReturnSuccessResponse(response http.ResponseWriter, request *http.Request, message string)
ReturnSuccessResponse - processes message and adds header
func ReturnSuccessResponseWithJson ¶ added in v0.22.0
func ReturnSuccessResponseWithJson(response http.ResponseWriter, request *http.Request, res interface{}, message string)
ReturnSuccessResponseWithJson - processes message and adds header
func SaveExtClient ¶
SaveExtClient - saves an ext client to database
func SaveNetwork ¶
SaveNetwork - save network struct to database
func SecurityCheck ¶
func SecurityCheck(reqAdmin bool, next http.Handler) http.HandlerFunc
SecurityCheck - Check if user has appropriate permissions
func SetAuthSecret ¶ added in v0.24.0
func SetCorefile ¶
SetCorefile - sets the core file of the system
func SetDNSOnWgConfig ¶ added in v1.1.0
func SetDefaultGw ¶ added in v0.23.0
func SetDefaultGw(node models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate
func SetDefaultGwForRelayedUpdate ¶ added in v0.23.0
func SetDefaultGwForRelayedUpdate(relayed, relay models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate
func SetEgressDomainAnsForDomain ¶ added in v1.6.0
SetEgressDomainAnsForDomain sets resolved CIDRs for a single domain.
func SetEgressDomainAnsForDomains ¶ added in v1.6.0
SetEgressDomainAnsForDomains assigns the same resolved CIDRs to each domain (e.g. static presets).
func SetFreeTierForTelemetry ¶
func SetFreeTierForTelemetry(freeTierFlag bool)
setFreeTierForTelemetry - store free tier flag without having an import cycle when used for telemetry (as the pro package needs the logic package as currently written).
func SetInternetGw ¶ added in v0.22.0
func SetInternetGw(node *models.Node, req models.InetNodeReq)
SetInternetGw - sets the node as internet gw based on flag bool
func SetNetworkNodesLastModified ¶
SetNetworkNodesLastModified - sets the network nodes last modified
func SetRelayedNodes ¶
SetRelayedNodes- sets and saves node as relayed
func SetUserDefaults ¶
SetUserDefaults - sets the defaults of a user to avoid empty fields
func SetVerbosity ¶ added in v0.90.0
func SetVerbosity(logLevel int)
func SortAclEntrys ¶ added in v0.26.0
SortTagEntrys - Sorts slice of Tag entries by their id
func SortApiHosts ¶
SortApiHosts - Sorts slice of ApiHosts by their ID alphabetically with numbers first
func SortApiNodes ¶
SortApiNodes - Sorts slice of ApiNodes by their ID alphabetically with numbers first
func SortDNSEntrys ¶
SortDNSEntrys - Sorts slice of DNSEnteys by their Address alphabetically with numbers first
func SortExtClient ¶
SortExtClient - Sorts slice of ExtClients by their ClientID alphabetically with numbers first
func SortNetworks ¶
SortNetworks - Sorts slice of Networks by their NetID alphabetically with numbers first
func SortUsers ¶
func SortUsers(unsortedUsers []models.ReturnUser)
SortUsers - Sorts slice of Users by username
func StartCPUProfiling ¶ added in v0.26.0
func StartHookManager ¶
StartHookManager - listens on `HookManagerCh` to run any hook and `HookCommandCh` for commands
func StartMemProfiling ¶ added in v0.30.0
func StartMemProfiling()
func StopCPUProfiling ¶ added in v0.26.0
func StopHook ¶ added in v1.4.0
func StopHook(hookID string)
StopHook - stops a hook with the given ID
func StoreHostPeerUpdate ¶ added in v1.5.1
func StoreHostPeerUpdate(hostID string, peerUpdate models.HostPeerUpdate)
StoreHostPeerUpdate - caches a computed HostPeerUpdate for a host. Called as a side-effect of PublishSingleHostPeerUpdate during broadcast.
func StoreJWTSecret ¶
StoreJWTSecret - stores server jwt secret if needed
func StringDifference ¶
StringDifference - returns the elements in `a` that aren't in `b`.
func StringSliceContains ¶
StringSliceContains - sees if a string slice contains a string element
func SubscribeMetricExportIntervalReset ¶ added in v1.6.0
func SubscribeMetricExportIntervalReset() <-chan struct{}
SubscribeMetricExportIntervalReset returns a channel notified when the metric interval setting changes.
func Telemetry ¶ added in v0.99.0
func Telemetry() string
Telemetry - checks if telemetry data should be sent
func TimerCheckpoint ¶
func TimerCheckpoint() error
TimerCheckpoint - Checks if 24 hours has passed since telemetry was last sent. If so, sends telemetry data to posthog
func ToReturnUser ¶
func ToReturnUser(user *schema.User) models.ReturnUser
ToReturnUser - gets a user as a return user
func ToUserEventLog ¶ added in v1.5.1
func ToUserEventLog(user *schema.User) models.UserEventLog
ToUserEventLog - converts a user to an event log entry with resolved group/role names
func ToggleExtClientConnectivity ¶
ToggleExtClientConnectivity - enables or disables an ext client
func Tokenize ¶
func Tokenize(k *models.EnrollmentKey, serverAddr string) error
Tokenize - tokenizes an enrollment key to be used via registration and attaches it to the Token field on the struct
func TryToUseEnrollmentKey ¶
func TryToUseEnrollmentKey(k *models.EnrollmentKey) bool
TryToUseEnrollmentKey - checks first if key can be decremented returns true if it is decremented or isvalid
func UniqueAclPolicyTags ¶ added in v0.99.0
func UniqueAclPolicyTags(tags []models.AclPolicyTag) []models.AclPolicyTag
func UniqueIPNetStrList ¶ added in v0.99.0
UniqueIPNetList deduplicates and sorts a list of CIDR strings.
func UniqueStrings ¶ added in v1.0.0
func UnlinkNetworkAndTagsFromEnrollmentKeys ¶ added in v0.90.0
func UnsetInternetGw ¶ added in v0.23.0
func UpdateEnrollmentKey ¶ added in v0.21.2
func UpdateEnrollmentKey(keyId string, updates *models.APIEnrollmentKey) (*models.EnrollmentKey, error)
UpdateEnrollmentKey - updates an existing enrollment key's associated relay
func UpdateExtClient ¶
UpdateExtClient - updates an ext client with new values
func UpdateHost ¶
UpdateHost - updates host data by field
func UpdateHostFromClient ¶
UpdateHostFromClient - used for updating host on server with update recieved from client
func UpdateHostNetwork ¶
UpdateHostNetwork - adds/deletes host from a network
func UpdateHostNode ¶ added in v1.2.0
func UpdateHostNode(h *schema.Host, newNode *models.Node) (publishDeletedNodeUpdate, publishPeerUpdate bool, displacedGwNodes []models.Node)
UpdateHostNode - handles updates from client nodes
func UpdateNetwork ¶
UpdateNetwork - updates a network with another network's fields
func UpdateNode ¶
UpdateNode - takes a node and updates another node with it's values
func UpdateNodeCheckin ¶
UpdateNodeCheckin - buffers the checkin timestamp in memory when caching is enabled. The actual DB write is deferred to FlushNodeCheckins (every 30s). When caching is disabled (HA mode), writes directly to the DB.
func UpdateRelayNodes ¶ added in v1.2.0
UpdateRelayNodes - updates relay nodes
func UpdateRelayed ¶
UpdateRelayed - updates a relay's relayed nodes, and sends updates to the relayed nodes over MQ
func UpdateUser ¶
UpdateUser - updates a given user
func UpsertHost ¶
UpsertHost - upserts into DB a given host model, does not check for existence*
func UpsertNetwork ¶ added in v1.1.0
func UpsertServerSettings ¶ added in v0.99.0
func UpsertServerSettings(s models.ServerSettings) error
func UpsertUserSettings ¶ added in v1.1.0
func UpsertUserSettings(userID string, userSettings models.UserSettings) error
func UserPermissions ¶
UserPermissions - checks token stuff
func ValidateAndApproveUserInvite ¶ added in v0.25.0
func ValidateCreateAclReq ¶ added in v0.26.0
ValidateCreateAclReq - validates create req for acl
func ValidateDNSCreate ¶
ValidateDNSCreate - checks if an entry is valid
func ValidateDNSUpdate ¶
ValidateDNSUpdate - validates a DNS update
func ValidateDomain ¶ added in v0.99.0
func ValidateEgressAppNATMode ¶ added in v1.6.0
ValidateEgressAppNATMode rejects virtual NAT for preset-based egress apps.
func ValidateEgressCIDR ¶ added in v1.6.0
ValidateEgressCIDR rejects egress ranges that overlap the Netmaker network or loopback space. Empty range and "*" are allowed (domain-only / inet gw).
func ValidateEgressGateway ¶
func ValidateEgressGateway(gateway models.EgressGatewayRequest) error
ValidateEgressGateway - validates the egress gateway model
func ValidateEgressProOnlyFeatures ¶ added in v1.6.0
ValidateEgressProOnlyFeatures rejects domain and app egress on Community Edition.
func ValidateEgressRange ¶ added in v0.24.3
func ValidateEgressReqProLimits ¶ added in v1.6.0
ValidateEgressReqProLimits rejects domain/app fields on the API request before CE builds an egress.
func ValidateInetGwReq ¶ added in v1.0.0
func ValidateNetwork ¶
Validate - validates fields of an network struct
func ValidateNewSettings ¶ added in v0.99.0
func ValidateNewSettings(req models.ServerSettings) error
func ValidateParams ¶ added in v0.23.0
func ValidateRelay ¶ added in v0.24.0
func ValidateRelay(relay models.RelayRequest, update bool) error
ValidateRelay - checks if relay is valid
func ValidateUser ¶
ValidateUser - validates a user model
func VerifyAuthRequest ¶
func VerifyAuthRequest(authRequest models.UserAuthParams, appName string) (string, error)
VerifyAuthRequest - verifies an auth request
func VerifyHostToken ¶
VerifyHostToken - [hosts] Only
func VerifyOTPAuthURL ¶ added in v1.0.0
func VerifyUserToken ¶
VerifyUserToken func will used to Verify the JWT Token while using APIS
func VersionLessThan ¶ added in v0.30.0
VersionLessThan checks if v1 < v2 semantically dev is the latest version
Types ¶
type ApiErrorType ¶ added in v0.99.0
type ApiErrorType string
const ( Internal ApiErrorType = "internal" BadReq ApiErrorType = "badrequest" NotFound ApiErrorType = "notfound" UnAuthorized ApiErrorType = "unauthorized" Forbidden ApiErrorType = "forbidden" )
type MetricsMonitor ¶ added in v1.2.0
type MetricsMonitor struct {
// contains filtered or unexported fields
}
func GetMetricsMonitor ¶ added in v1.2.0
func GetMetricsMonitor() *MetricsMonitor
func (*MetricsMonitor) Start ¶ added in v1.2.0
func (m *MetricsMonitor) Start()
func (*MetricsMonitor) Stop ¶ added in v1.2.0
func (m *MetricsMonitor) Stop()
type OSInfo ¶ added in v1.4.0
type ServerSyncType ¶ added in v1.5.1
type ServerSyncType string
const ( SyncTypeSettings ServerSyncType = "settings" SyncTypePeerUpdate ServerSyncType = "peer_update" SyncTypeIDPSync ServerSyncType = "idp_sync" SyncTypeIDPReset ServerSyncType = "idp_reset" )
Source Files
¶
- acls.go
- auth.go
- clients.go
- dns.go
- egress.go
- egress_domain_ans.go
- egress_presets.go
- egress_presets_aws.go
- egress_presets_catalog.go
- enrollmentkey.go
- errors.go
- extpeers.go
- gateway.go
- hooks.go
- hosts.go
- jit.go
- jwts.go
- metrics.go
- networks.go
- nodes.go
- peers.go
- proc.go
- relay.go
- security.go
- server.go
- serverconf.go
- settings.go
- status.go
- sysinfo.go
- telemetry.go
- timer.go
- traffic.go
- usage.go
- user_mgmt.go
- users.go
- util.go
- version.go
- wireguard.go
- zombie.go