logic

package
v1.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 31, 2026 License: Apache-2.0 Imports: 61 Imported by: 6

Documentation

Overview

package for logicing client and server code

Index

Constants

View Source
const (
	DashboardApp       = "dashboard"
	NetclientApp       = "netclient"
	NetmakerDesktopApp = "netmaker-desktop"
)
View Source
const (
	FallbackVNATPool    = "198.18.0.0/15"
	VNATPoolPrefixLen   = 22
	DefaultSitePrefixV4 = 24
	CgnatCIDR           = "100.64.0.0/10"
)
View Source
const (
	MasterUser       = "masteradministrator"
	Forbidden_Msg    = "forbidden"
	Unauthorized_Msg = "unauthorized"
	Unauthorized_Err = models.Error(Unauthorized_Msg)
)
View Source
const (
	// ZOMBIE_TIMEOUT - timeout in hours for checking zombie status
	ZOMBIE_TIMEOUT = 6
	// ZOMBIE_DELETE_TIME - timeout in minutes for zombie node deletion
	ZOMBIE_DELETE_TIME = 10
)
View Source
const DeviceHostIDHeader = "X-Host-ID"
View Source
const (
	GooglePublicNameserverName = "Google Public DNS"
)
View Source
const KUBERNETES_LISTEN_PORT = 31821

KUBERNETES_LISTEN_PORT - starting port for Kubernetes in order to use NodePort range

View Source
const KUBERNETES_SERVER_MTU = 1024

KUBERNETES_SERVER_MTU - ideal mtu for kubernetes deployments right now

View Source
const MinVersion = "v0.17.0"
View Source
const StaleStatusCheckInterval = 5 * time.Minute

StaleStatusCheckInterval - how often MarkStaleNodesOffline scans the nodes table looking for nodes whose last check-in is older than models.LastCheckInThreshold.

Variables

View Source
var (
	CreateDefaultTags = func(ctx context.Context, netID schema.NetworkID) {}

	DeleteAllNetworkTags = func(ctx context.Context, networkID schema.NetworkID) {}

	IsUserAllowedToCommunicate = func(ctx context.Context, userName string, peer models.Node) (bool, []models.Acl) {
		return false, []models.Acl{}
	}

	RemoveUserFromAclPolicy = func(ctx context.Context, userName string) {}

	EnsureDefaultUserGroupNetworkPolicies = func(ctx context.Context, old, new *schema.UserGroup) error {
		return nil
	}

	GetGroupNetworksMap = func(ctx context.Context, group *schema.UserGroup) (map[schema.NetworkID]schema.Network, error) {
		return nil, nil
	}
)
View Source
var (
	// EnrichDeviceNetworksWithJIT adds JIT fields to device network responses (Pro).
	EnrichDeviceNetworksWithJIT = func(ctx context.Context, _ *schema.User, _ []schema.Network, networks []models.DeviceNetwork) []models.DeviceNetwork {
		return networks
	}
	// PublishHostRegistrationUpdates notifies peers after host network join (wired from mq).
	PublishHostRegistrationUpdates = func(ctx context.Context, _ *schema.Host) error { return nil }
	// RequestHostPullUpdate asks a host to pull config (wired from mq).
	RequestHostPullUpdate = func(_ *schema.Host) error { return nil }
	// JoinHostToNetworks adds a host to networks (wired from auth).
	JoinHostToNetworks = func(ctx context.Context, _ models.EnrollmentKey, _ *schema.Host, _ string) {}
	// ProvisionDeviceHostMessaging creates broker credentials for a new device host (wired from mq).
	ProvisionDeviceHostMessaging = func(_ *schema.Host) error { return nil }
	// CleanupDeviceHostForOwnershipTransfer removes prior user network state before host re-bind (wired from mq).
	CleanupDeviceHostForOwnershipTransfer = DefaultCleanupDeviceHostForOwnershipTransfer
)
View Source
var (
	IPv4Network = "0.0.0.0/0"
	IPv6Network = "::/0"
)
View Source
var (
	// ErrHostExists error indicating that host exists when trying to create new host
	ErrHostExists        = errors.New("host already exists")
	ErrInvalidHostID     = errors.New("invalid host id")
	ErrHostLimitExceeded = errors.New("host limit reached for this tenant, please upgrade your license")
)
View Source
var (
	// ResetAutoRelay - function to reset autorelayed peers on this node
	ResetAutoRelay = func(ctx context.Context, autoRelayNode *models.Node) error {
		return nil
	}
	// ResetAutoRelayedPeer - removes relayed peers for node
	ResetAutoRelayedPeer = func(ctx context.Context, failedOverNode *models.Node) error {
		return nil
	}
	// GetAutoRelayPeerIps - gets autorelay peerips
	GetAutoRelayPeerIps = func(ctx context.Context, peer, node *models.Node) []net.IPNet {
		return []net.IPNet{}
	}
	// SetAutoRelay - sets autorelay flag on the node
	SetAutoRelay = func(node *models.Node) {
		node.IsAutoRelay = false
	}
)
View Source
var (
	ErrInvalidJwtValidityDuration = errors.New("invalid jwt validity duration")
	ErrFlowLogsNotSupported       = errors.New("flow logs not supported")
	ErrInvalidIPDetectionInterval = errors.New("invalid ip detection interval (must be greater than or equal to 15s)")
)
View Source
var AddGlobalGroupOnRoleUpgrade = func(oldRole, newRole schema.UserRoleID, groups map[schema.UserGroupID]struct{}) {
}
View Source
var AddGlobalNetRolesToAdmins = func(u *schema.User) {}
View Source
var AdminPermissionTemplate = schema.UserRole{
	ID:                 schema.AdminRole,
	Default:            true,
	TenantGlobalAccess: true,
}
View Source
var AssignVirtualRangeToEgress = func(nw *schema.Network, eg *schema.Egress) error {
	return nil
}
View Source
var CanUserCreateNetwork = func(ctx context.Context, username string) bool { return true }
View Source
var CheckIfAnyPolicyisUniDirectional = func(targetNode models.Node, acls []models.Acl) bool {
	return false
}
View Source
var CheckJITAccess = func(context.Context, string, string) (bool, *schema.JITGrant, error) {
	return true, nil, nil
}
View Source
var CheckPostureViolations = func(ctx context.Context, d models.PostureCheckDeviceInfo, network schema.NetworkID) (v []models.Violation, level schema.Severity) {
	return []models.Violation{}, schema.SeverityUnknown
}
View Source
var CheckPostureViolationsForHost = func(ctx context.Context, host *schema.Host, tags map[models.TagID]struct{}, network schema.NetworkID, skipAutoUpdate bool) ([]models.Violation, schema.Severity) {
	if host == nil {
		return []models.Violation{}, schema.SeverityUnknown
	}
	return CheckPostureViolations(ctx, models.PostureCheckDeviceInfo{
		ClientLocation: host.CountryCode,
		ClientVersion:  host.Version,
		OS:             host.OS,
		OSFamily:       host.OSFamily,
		OSVersion:      host.OSVersion,
		KernelVersion:  host.KernelVersion,
		AutoUpdate:     host.AutoUpdate,
		SkipAutoUpdate: skipAutoUpdate,
		Tags:           tags,
		HostID:         host.ID.String(),
	}, network)
}
View Source
var CheckUIHostReadAccess = func(r *http.Request, host *schema.Host) error {
	return nil
}

CheckUIHostReadAccess verifies a dashboard user may read the given host. Overridden in Pro to enforce network-scoped host access.

View Source
var CleanupGwsMigration = func(ctx context.Context) {}
View Source
var ClientLimitExceeded = func(ctx context.Context) bool {
	return false
}
View Source
var CreateDefaultNetworkRolesAndGroups = func(ctx context.Context, netID schema.NetworkID, username string) {}
View Source
var CreateDefaultUserPolicies = func(ctx context.Context, netID schema.NetworkID) {
	if netID.String() == "" {
		return
	}
	if !IsAclExists(ctx, fmt.Sprintf("%s.%s", netID, "all-users")) {
		defaultUserAcl := models.Acl{
			ID:          fmt.Sprintf("%s.%s", netID, "all-users"),
			Default:     true,
			Name:        "All Users",
			MetaData:    "This policy gives access to everything in the network for an user",
			NetworkID:   netID,
			Proto:       models.ALL,
			ServiceType: models.Any,
			Port:        []string{},
			RuleType:    models.UserPolicy,
			Src: []models.AclPolicyTag{
				{
					ID:    models.UserAclID,
					Value: "*",
				},
			},
			Dst: []models.AclPolicyTag{{
				ID:    models.NodeTagID,
				Value: "*",
			}},
			AllowedDirection: models.TrafficDirectionUni,
			Enabled:          true,
			CreatedBy:        "auto",
			CreatedAt:        time.Now().UTC(),
		}
		InsertAcl(ctx, defaultUserAcl)
	}
}
View Source
var DeleteMetrics = func(context.Context, string) error {
	return nil
}
View Source
var DeleteNetworkRoles = func(ctx context.Context, netID string) {}
View Source
var DeleteNodeMetricsFromPeers = func(context.Context, string) {}
View Source
var (
	DeleteNodesCh = make(chan *models.Node, 100)
)
View Source
var DeleteRole = func(ctx context.Context, r schema.UserRoleID, force bool) error {
	return nil
}
View Source
var EgressLimitExceeded = func(ctx context.Context) bool {
	return false
}
View Source
var EmailInit = func(ctx context.Context) {}
View Source
var EnforceLimits = func(ctx context.Context) bool {
	return false
}
View Source
var EnrollmentErrors = struct {
	InvalidCreate      error
	NoKeyFound         error
	InvalidKey         error
	NoUsesRemaining    error
	FailedToTokenize   error
	FailedToDeTokenize error
}{
	InvalidCreate:      fmt.Errorf("failed to create enrollment key. paramters invalid"),
	NoKeyFound:         fmt.Errorf("no enrollmentkey found"),
	InvalidKey:         fmt.Errorf("invalid key provided"),
	NoUsesRemaining:    fmt.Errorf("no uses remaining"),
	FailedToTokenize:   fmt.Errorf("failed to tokenize"),
	FailedToDeTokenize: fmt.Errorf("failed to detokenize"),
}

EnrollmentErrors - struct for holding EnrollmentKey error messages

View Source
var EnterpriseCheckFuncs []func(ctx context.Context, wg *sync.WaitGroup)

EnterpriseCheckFuncs - can be set to run functions for EE

View Source
var ErrClientLimitExceeded = errors.New("client limit reached for this tenant, please upgrade your license")
View Source
var ErrEgressLimitExceeded = errors.New("egress limit reached for this tenant, please upgrade your license")
View Source
var ErrEgressProOnlyFeature = errors.New("domain and app egress require Netmaker Pro")

ErrEgressProOnlyFeature is returned when domain or app egress is used on Community Edition.

View Source
var ErrIngressLimitExceeded = errors.New("gateway limit reached for this tenant, please upgrade your license")
View Source
var ErrNetworkLimitExceeded = errors.New("network limit reached for this tenant, please upgrade your license")
View Source
var ErrUnknownEgressPreset = errors.New("unknown egress preset_id")

ErrUnknownEgressPreset is returned when preset_id does not match the catalog.

View Source
var ErrUserLimitExceeded = errors.New("user limit reached for this tenant, please upgrade your license")
View Source
var ErrVirtualNATNotForEgressApps = errors.New("virtual NAT is not supported for egress apps")

ErrVirtualNATNotForEgressApps is returned when virtual NAT is requested for a preset egress app.

View Source
var FilterNetworksByRole = func(ctx context.Context, allnetworks []schema.Network, user *schema.User) []schema.Network {
	return allnetworks
}
View Source
var GetDeploymentMode = func() string {

	return "self-hosted"
}
View Source
var GetEgressUserRulesForNode = func(ctx context.Context, targetnode *models.Node,
	rules map[string]models.AclRule) map[string]models.AclRule {
	return rules
}
View Source
var GetFeatureFlags = func(ctx context.Context) models.FeatureFlags {
	return models.FeatureFlags{}
}
View Source
var GetFilteredNodesByUserAccess = func(user *schema.User, nodes []models.Node) (filteredNodes []models.Node) {
	return
}
View Source
var GetFwRulesForNodeAndPeerOnGw = getFwRulesForNodeAndPeerOnGw
View Source
var GetFwRulesForUserNodesOnGw = func(ctx context.Context, node models.Node, nodes []models.Node) (rules []models.FwRule) { return }
View Source
var GetMetrics = func(context.Context, string) (*models.Metrics, error) {
	var metrics models.Metrics
	return &metrics, nil
}
View Source
var GetNameserversForHost = getNameserversForHost
View Source
var GetNameserversForNode = getNameserversForNode
View Source
var GetNodeStatus = func(ctx context.Context, node *models.Node, t bool) {
	getNodeCheckInStatus(node, t)
}
View Source
var GetPostureCheckDeviceInfoByNode = func(ctx context.Context, node *models.Node) (d models.PostureCheckDeviceInfo) {
	return
}
View Source
var GetTagMapWithNodesByNetwork = getTagMapWithNodesByNetwork
View Source
var GetUserAclRulesForNode = func(ctx context.Context, targetnode *models.Node,
	rules map[string]models.AclRule) map[string]models.AclRule {
	return rules
}
View Source
var GetUserGroup = func(ctx context.Context, groupId schema.UserGroupID) (userGrps schema.UserGroup, err error) {
	return
}
View Source
var GlobalNsList = map[string]GlobalNs{
	"Google": {
		ID: "Google",
		IPs: []string{
			"8.8.8.8",
			"8.8.4.4",
			"2001:4860:4860::8888",
			"2001:4860:4860::8844",
		},
	},
	"Cloudflare": {
		ID: "Cloudflare",
		IPs: []string{
			"1.1.1.1",
			"1.0.0.1",
			"2606:4700:4700::1111",
			"2606:4700:4700::1001",
		},
	},
	"Quad9": {
		ID: "Quad9",
		IPs: []string{
			"9.9.9.9",
			"149.112.112.112",
			"2620:fe::fe",
			"2620:fe::9",
		},
	},
}
View Source
var HookCommandCh = make(chan models.HookCommand, 10)

HookCommandCh - channel to send commands to hooks (reset/stop)

View Source
var HookManagerCh = make(chan models.HookDetails, 3)

HookManagerCh - channel to add any new hooks

View Source
var HostLimitExceeded = func(ctx context.Context) bool {
	return false
}
View Source
var IngressLimitExceeded = func(ctx context.Context) bool {
	return false
}
View Source
var InitialiseNetworkRoles = func(ctx context.Context) {}
View Source
var InitialiseRoles = userRolesInit
View Source
var IntialiseGroups = func(ctx context.Context) {}
View Source
var IsAclPolicyValid = func(ctx context.Context, acl models.Acl) (err error) {

	if acl.AllowedDirection == models.TrafficDirectionUni {
		return errors.New("uni traffic flow not allowed on CE")
	}
	switch acl.RuleType {

	case models.DevicePolicy:
		for _, srcI := range acl.Src {
			if srcI.Value == "*" {
				continue
			}
			if srcI.ID == models.NodeTagID && srcI.Value == fmt.Sprintf("%s.%s", acl.NetworkID.String(), models.GwTagName) {
				continue
			}
			if err = checkIfAclTagisValid(ctx, acl, srcI, true); err != nil {
				return err
			}
		}
		for _, dstI := range acl.Dst {

			if dstI.Value == "*" {
				continue
			}
			if dstI.ID == models.NodeTagID && dstI.Value == fmt.Sprintf("%s.%s", acl.NetworkID.String(), models.GwTagName) {
				continue
			}
			if err = checkIfAclTagisValid(ctx, acl, dstI, false); err != nil {
				return
			}
		}
	default:
		return errors.New("unknown acl policy type " + string(acl.RuleType))
	}
	if err := NormalizeAndValidateAclEgressIPs(&acl); err != nil {
		return err
	}
	return nil
}
View Source
var IsMSP = func(ctx context.Context) bool {
	return false
}
View Source
var IsNetworkAdmin = func(ctx context.Context, user *schema.User, networkID string) bool { return false }
View Source
var IsOAuthConfigured = func(context.Context) bool { return false }
View Source
var IsPeerAllowed = func(ctx context.Context, node, peer models.Node, checkDefaultPolicy bool) bool {
	var nodeId, peerId string

	if node.IsStatic {
		nodeId = node.StaticNode.ClientID
		node = models.ConvertToStaticNode(node.StaticNode)
	} else {
		nodeId = node.ID.String()
	}
	if peer.IsStatic {
		peerId = peer.StaticNode.ClientID
		peer = models.ConvertToStaticNode(peer.StaticNode)
	} else {
		peerId = peer.ID.String()
	}

	peerTags := make(map[models.TagID]struct{})
	nodeTags := make(map[models.TagID]struct{})
	nodeTags[models.TagID(nodeId)] = struct{}{}
	peerTags[models.TagID(peerId)] = struct{}{}
	if peer.IsGw {
		peerTags[models.TagID(fmt.Sprintf("%s.%s", peer.Network, models.GwTagName))] = struct{}{}
	}
	if node.IsGw {
		nodeTags[models.TagID(fmt.Sprintf("%s.%s", node.Network, models.GwTagName))] = struct{}{}
	}
	if checkDefaultPolicy {

		defaultPolicy, err := GetDefaultPolicy(ctx, schema.NetworkID(node.Network), models.DevicePolicy)
		if err == nil {
			if defaultPolicy.Enabled {
				return true
			}
		}

	}

	policies := ListDevicePolicies(ctx, schema.NetworkID(peer.Network))
	srcMap := make(map[string]struct{})
	dstMap := make(map[string]struct{})
	defer func() {
		srcMap = nil
		dstMap = nil
	}()
	for _, policy := range policies {
		if !policy.Enabled {
			continue
		}
		if IsEgressRoutingPolicyAllowedForNodes(policy, node, peer) {
			return true
		}

		srcMap = ConvAclTagToValueMap(policy.Src)
		dstMap = ConvAclTagToValueMap(policy.Dst)
		for _, dst := range policy.Dst {
			if dst.ID == models.EgressID {
				e := schema.Egress{ID: dst.Value}
				err := e.Get(ctx)
				if err == nil && e.Status {
					for nodeID := range e.Nodes {
						dstMap[nodeID] = struct{}{}
					}
				}
			}
		}
		if CheckTagGroupPolicy(srcMap, dstMap, node, peer, nodeTags, peerTags) {
			return true
		}

	}
	return false
}
View Source
var IsUserAllowedToJoinNetwork = defaultIsUserAllowedToJoinNetwork

IsUserAllowedToJoinNetwork reports whether username may join the given network. network may be the network name (netid) or UUID. ctx should carry tenant scope so User.Get can load PlatformRoleID and UserGroups from tenant_memberships_v1; if missing, DefaultScope is applied.

View Source
var LoadMetricsIntoCache = func(ctx context.Context) error {
	return nil
}
View Source
var LogEvent = func(ctx context.Context, a *models.Event) {}
View Source
var NetworkHook models.HookFunc = func(params ...interface{}) error {
	if len(params) != 1 {
		return errors.New("invalid number of params")
	}

	tenantID, _ := params[0].(string)
	if len(tenantID) == 0 {
		return errors.New("invalid tenant id")
	}

	ctx := scope.WithContext(db.WithContext(context.TODO()), scope.TenantScope, tenantID)
	networks, err := (&schema.Network{}).ListAll(ctx)
	if err != nil {
		return err
	}
	allNodes, err := GetAllNodes(ctx)
	if err != nil {
		return err
	}
	for _, network := range networks {
		if !network.AutoRemove || network.AutoRemoveThreshold == 0 {
			continue
		}
		nodes := GetNetworkNodesMemory(allNodes, network.Name)
		for _, node := range nodes {
			if !node.Connected {
				continue
			}
			exists := false
			for _, tagI := range network.AutoRemoveTags {
				if tagI == "*" {
					exists = true
					break
				}
				if _, ok := node.Tags[models.TagID(tagI)]; ok {
					exists = true
					break
				}
			}
			if !exists {
				continue
			}
			if time.Since(node.LastCheckIn) > time.Duration(network.AutoRemoveThreshold)*time.Minute {
				if err := DeleteNode(ctx, &node, true); err != nil {
					continue
				}
				node.PendingDelete = true
				node.Action = schema.NODE_DELETE
				DeleteNodesCh <- &node
				host := &schema.Host{ID: node.HostID}
				if err := host.Get(ctx); err == nil && len(host.Nodes) == 0 {
					(&schema.Host{ID: host.ID}).Delete(ctx)
				}
			}
		}
	}
	return nil
}
View Source
var NetworkLimitExceeded = func(ctx context.Context) bool {
	return false
}
View Source
var NetworkPermissionsCheck = func(username string, r *http.Request) error { return nil }
View Source
var OrgAdminPermissionTemplate = schema.UserRole{
	ID:              schema.OrgAdmin,
	Default:         true,
	OrgGlobalAccess: true,
}
View Source
var OrgOwnerPermissionTemplate = schema.UserRole{
	ID:              schema.OrgOwner,
	Default:         true,
	OrgGlobalAccess: true,
}
View Source
var OrgPermissionsCheck = func(username string, r *http.Request) error { return nil }
View Source
var PlatformRoleRequiresGroupEnforcement = func(role schema.UserRoleID) bool { return false }
View Source
var PublishExitClientsFailOpen = func(ctx context.Context, clients []models.Node) {}

PublishExitClientsFailOpen is wired from mq to push fail-open peer updates to exit clients before their routing node is removed from the mesh.

View Source
var PublishPeerUpdateAfterExitNodeChange = func(ctx context.Context) {}

PublishPeerUpdateAfterExitNodeChange notifies peers after exit-node selection changes (wired from mq).

View Source
var PublishServerSync func(ctx context.Context, syncType ServerSyncType)

PublishServerSync is set by the mq package at startup to broadcast sync signals to peer servers in HA mode. The callback avoids a circular import (logic -> mq).

View Source
var ResetAuthProvider = func(context.Context) {}
View Source
var ResetIDPSyncHook = func(context.Context) {}
View Source
var RunPostureChecksForTenant = func(ctx context.Context) error { return nil }
View Source
var SetPeerMetricsDisconnected = func(context.Context, string) {}
View Source
var SettingsMutex = &sync.RWMutex{}
View Source
var StartFlowCleanupLoop = func() {}
View Source
var StopFlowCleanupLoop = func() {}
View Source
var StripGroupsOnRoleDowngrade = func(oldRole, newRole schema.UserRoleID, groups map[schema.UserGroupID]struct{}) {
}
View Source
var SuperAdminPermissionTemplate = schema.UserRole{
	ID:                 schema.SuperAdminRole,
	Default:            true,
	TenantGlobalAccess: true,
}
View Source
var SyncFromIDP = func(context.Context) error { return nil }
View Source
var SyncHostEDRState = func(ctx context.Context, hostID string) error {
	return nil
}

SyncHostEDRState refreshes EDR posture state for a host (no-op in community).

View Source
var SyncHostMDMState = func(ctx context.Context, hostID string) error {
	return nil
}

SyncHostMDMState refreshes MDM posture state for a host (no-op in community).

View Source
var TenantPermissionsCheck = func(username string, r *http.Request) error { return nil }
View Source
var TriggerCollectMetrics = func(hostID, nodeID, reason string) {}

TriggerCollectMetrics - asks the client to push metrics now. Overridden in Pro. reason is a short label (e.g. "join", "reconnect", "checkin_recovered") used for logging.

View Source
var UpdateMetrics = func(context.Context, string, *models.Metrics) error {
	return nil
}
View Source
var UpdateUserGwAccess = func(ctx context.Context, currentUser, changeUser *schema.User) {}
View Source
var UserHasDeviceNetworkWriteAccess = defaultUserHasDeviceNetworkWriteAccess

UserHasDeviceNetworkWriteAccess reports whether the user may mutate device network membership/state (join, leave, exit-node selection). CE defaults to network access; Pro overrides with scope checks that deny read-only roles.

View Source
var UserHasGlobalNetworksAdminMembership = func(user *schema.User) bool { return false }
View Source
var UserHasNetworkGroupAccess = func(ctx context.Context, user *schema.User, networkID string) bool { return false }
View Source
var UserLimitExceeded = func(ctx context.Context) bool {
	return false
}
View Source
var UserSubjectToNetworkJIT = func(context.Context, string, *schema.User) bool {
	return false
}

UserSubjectToNetworkJIT reports whether the user must satisfy JIT for client-app extclient creates on the network (JIT enabled + in unscoped / allowlisted groups).

View Source
var ValidateEgressReq = validateEgressReq
View Source
var ValidateNameserverReq = validateNameserverReq

Functions

func AddEgressInfoToPeerByAccess added in v0.99.0

func AddEgressInfoToPeerByAccess(node, targetNode *models.Node, eli []schema.Egress, acls []models.Acl, isDefaultPolicyActive bool)

func AddHook

func AddHook(ifaceToAdd interface{})

AddHook - adds a hook function to run every 24hrs

func AddSSOStateCleanupHook added in v1.5.1

func AddSSOStateCleanupHook()

AddSSOStateCleanupHook registers a periodic cleanup of expired SSO states

func AddStaticNodestoList added in v0.26.0

func AddStaticNodestoList(ctx context.Context, nodes []models.Node) []models.Node

func AddStatusToNodes added in v0.30.0

func AddStatusToNodes(ctx context.Context, nodes []models.Node, statusCall bool) (nodesWithStatus []models.Node)

func AllDomainAnsFromEgress added in v1.6.0

func AllDomainAnsFromEgress(e schema.Egress) []string

AllDomainAnsFromEgress returns the flattened union of per-domain answers (ACL/routing).

func AllocateUniquePoolFromFallback added in v1.5.1

func AllocateUniquePoolFromFallback(pool *net.IPNet, newPrefixLen int, allocated map[string]struct{}, seed string) string

AllocateUniquePoolFromFallback allocates a unique subnet of the given prefix length from the fallback pool, skipping any subnets already present in the allocated map.

func AllocateUniqueVNATPool added in v1.5.1

func AllocateUniqueVNATPool(ctx context.Context, network *schema.Network) error

AllocateUniqueVNATPool allocates a unique Virtual NAT pool for a network, ensuring it doesn't conflict with pools already assigned to other networks.

func AppendEgressPolicyRange added in v1.7.0

func AppendEgressPolicyRange(e schema.Egress, rangeStr string, v4, v6 *[]net.IPNet)

AppendEgressPolicyRange appends CIDRs for ACL/firewall from an egress. Internet egress stores Range as "*" which is not a CIDR; expand to 0.0.0.0/0 and ::/0 so internet policies actually install destinations on the exit node.

func ApplyConfiguredDomainsToEgress added in v1.6.0

func ApplyConfiguredDomainsToEgress(e *schema.Egress, domains []string)

ApplyConfiguredDomainsToEgress sets Domains on the egress record.

func ApplyEgressPresetToEgressReq added in v1.6.0

func ApplyEgressPresetToEgressReq(req *models.EgressReq) error

ApplyEgressPresetToEgressReq merges catalog defaults into req. Rules: explicit non-empty name, description, and domains in req override preset. PresetID must already be a known id.

func ApplyExtClientInternetEgressSelection added in v1.7.0

func ApplyExtClientInternetEgressSelection(ctx context.Context, client *models.ExtClient, gatewayNodeID string, update *models.CustomExtClient) error

ApplyExtClientInternetEgressSelection resolves use_internet_egress on create/update or validates selected_internet_egress_id. Opt-in is per config file.

Legacy desktop/RAC apps omit use_internet_egress. When those clients connect through a gateway that is also an exit node, the gateway's internet egress is auto-selected so AllowedIPs include 0.0.0.0/0 (previous IsInternetGateway behavior). Dashboard config files (no device_id / remote_access_client_id) remain opt-in only.

func AssignNodeExitNode added in v1.7.0

func AssignNodeExitNode(ctx context.Context, network, nodeID, egressID string, useTcpUplink bool) (*models.DeviceExitNode, error)

AssignNodeExitNode sets or clears the internet egress for a node (admin; no ACL checks). useTcpUplink opts the client into TCP uplink to the exit routing gateway when that gateway has TCP proxy enabled; ignored when clearing the exit.

func AssignVirtualNATDefaults added in v1.5.1

func AssignVirtualNATDefaults(network *schema.Network, vpnCIDR string)

AssignVirtualNATDefaults determines safe defaults based on VPN CIDR

func AssociateNodeToHost

func AssociateNodeToHost(n *models.Node, h *schema.Host) error

AssociateNodeToHost - associates a node with a host and persists both.

func AutoUpdateEnabled added in v0.99.0

func AutoUpdateEnabled(ctx context.Context) bool

AutoUpdateEnabled returns a boolean indicating whether netclient auto update is enabled or disabled default is enabled

func CancelDeviceNetworkJoin added in v1.7.0

func CancelDeviceNetworkJoin(ctx context.Context, user *schema.User, host *schema.Host, networkID string) error

CancelDeviceNetworkJoin removes a pending join approval request without leaving a joined network.

func CheckEndpoint

func CheckEndpoint(endpoint string) bool

CheckEndpoint - checks if an endpoint is valid

func CheckHostPorts

func CheckHostPorts(ctx context.Context, h *schema.Host) (changed bool)

CheckHostPorts checks host endpoints to ensures that hosts on the same server with the same endpoint have different listen ports in the case of 64535 hosts or more with same endpoint, ports will not be changed

func CheckIfFileExists

func CheckIfFileExists(filePath string) bool

CheckIfFileExists - checks if file exists or not in the given path

func CheckTagGroupPolicy added in v0.99.0

func CheckTagGroupPolicy(srcMap, dstMap map[string]struct{}, node, peer models.Node,
	nodeTags, peerTags map[models.TagID]struct{}) bool

func CheckZombies

func CheckZombies(ctx context.Context, _node *schema.Node)

CheckZombies - checks if new node has same hostid as existing node if so, existing node is added to zombie node quarantine list also cleans up nodes past their expiration date

func CleanExpiredSSOStates added in v1.5.1

func CleanExpiredSSOStates() error

CleanExpiredSSOStates removes expired SSO state entries from the database to prevent unbounded table growth that degrades FetchRecord performance.

func CleanVersion added in v1.4.0

func CleanVersion(raw string) string

CleanVersion normalizes a version string safely for storage. - removes "v" or "V" prefix - trims whitespace - strips invalid trailing characters - preserves semver, prerelease, and build metadata

func CleanupOtherExtclients added in v1.5.1

func CleanupOtherExtclients(ctx context.Context, extclient *models.ExtClient) error

CleanupOtherExtclients cleans up other clients owned by the same use for the same device and network.

func ClearEgressDomainAns added in v1.6.0

func ClearEgressDomainAns(e *schema.Egress)

ClearEgressDomainAns clears per-domain answers.

func ClearExitNodeForDisconnect added in v1.7.0

func ClearExitNodeForDisconnect(node *models.Node) (bool, error)

ClearExitNodeForDisconnect clears the node's internet exit selection so a subsequent peer update can remove full-tunnel routes before disconnect. Returns true when a selection was cleared. Callers should sync related fields onto any in-flight node copy (SelectedInternetEgressID, InternetGwID, IsRelayed, RelayedBy) from the updated node.

func ClearNodesSelectedInternetEgress added in v1.7.0

func ClearNodesSelectedInternetEgress(ctx context.Context, egressID, network string)

ClearNodesSelectedInternetEgress clears SelectedInternetEgressID for all nodes that selected this egress.

func CompareIfaceSlices added in v1.1.0

func CompareIfaceSlices(a, b []schema.Iface) bool

CompareIfaceSlices compares two slices of Iface for deep equality (order-sensitive)

func CompareMaps added in v0.99.0

func CompareMaps[K comparable, V any](a, b map[K]V) bool

Compare any two maps with any key and value types

func ConfiguredDomainsForEgress added in v1.6.0

func ConfiguredDomainsForEgress(e schema.Egress) []string

ConfiguredDomainsForEgress returns the user-configured hostname list from e.Domains (JSON). It does not read the legacy DB column "domain" (singular); that is migrated once in migrateEgressDomains.

func ContainsCIDR added in v0.24.3

func ContainsCIDR(net1, net2 string) bool

func ContinueIfUserMatch

func ContinueIfUserMatch(next http.Handler) http.HandlerFunc

func ContinueIfUserMatchOrAdmin added in v1.6.0

func ContinueIfUserMatchOrAdmin(next http.Handler) http.HandlerFunc

func ConvAclTagToValueMap added in v0.99.0

func ConvAclTagToValueMap(acltags []models.AclPolicyTag) map[string]struct{}

func ConvertModelsNodeToSchemaNode added in v1.6.0

func ConvertModelsNodeToSchemaNode(node *models.Node) *schema.Node

func ConvertSchemaNodeToApiNode added in v1.6.0

func ConvertSchemaNodeToApiNode(_node *schema.Node) *models.ApiNode

func ConvertSchemaNodeToModelsNode added in v1.6.0

func ConvertSchemaNodeToModelsNode(_node *schema.Node) *models.Node

func ConvertSchemaNodeToModelsNodeWithContext added in v1.7.0

func ConvertSchemaNodeToModelsNodeWithContext(ctx context.Context, _node *schema.Node) *models.Node

func CreateDNS

func CreateDNS(ctx context.Context, entry models.DNSEntry) (models.DNSEntry, error)

CreateDNS - creates a DNS entry

func CreateDefaultAclNetworkPolicies added in v0.26.0

func CreateDefaultAclNetworkPolicies(ctx context.Context, netID schema.NetworkID)

CreateDefaultAclNetworkPolicies - create default acl network policies

func CreateDefaultNetworkEnrollmentKey added in v1.7.0

func CreateDefaultNetworkEnrollmentKey(ctx context.Context, networkName string) (*schema.EnrollmentKey, error)

CreateDefaultNetworkEnrollmentKey creates an unlimited default enrollment key for a network.

func CreateEgressGateway

func CreateEgressGateway(gateway models.EgressGatewayRequest) (models.Node, error)

CreateEgressGateway - creates an egress gateway

func CreateEnrollmentKey

func CreateEnrollmentKey(ctx context.Context, uses int, expiration time.Time, networks,
	tags []string, groups []models.TagID, unlimited bool, relay uuid.UUID,
	defaultKey, autoEgress, autoAssignGw bool) (*schema.EnrollmentKey, error)

CreateEnrollmentKey - creates a new enrollment key in db

func CreateFallbackNameserver added in v1.4.0

func CreateFallbackNameserver(network *schema.Network) error

func CreateHost

func CreateHost(ctx context.Context, h *schema.Host) error

CreateHost - creates a host if not exist

func CreateInternetEgressForNode added in v1.7.0

func CreateInternetEgressForNode(ctx context.Context, node *models.Node, name, createdBy string) (*schema.Egress, error)

CreateInternetEgressForNode creates an internet-type egress with the given node as routing node.

func CreateJWT

func CreateJWT(uuid string, macAddress string, network string) (response string, err error)

CreateJWT func will used to create the JWT while signing in and signing out

func CreateNetwork

func CreateNetwork(ctx context.Context, _network *schema.Network) error

CreateNetwork - creates a network in database

func CreatePreAuthToken added in v1.0.0

func CreatePreAuthToken(ctx context.Context, username string) (string, error)

CreatePreAuthToken generate a jwt token to be used as intermediate token after primary-factor authentication but before secondary-factor authentication. It carries the same scope as the eventual auth token so that PreAuthCheck can confirm the token was issued for the scope it's being redeemed in.

func CreateUserAccessJwtToken added in v0.99.0

func CreateUserAccessJwtToken(ctx context.Context, username string, d time.Time, tokenID string) (response string, err error)

CreateUserJWT - creates a user jwt token

func CreateUserJWT

func CreateUserJWT(ctx context.Context, username string, appName string) (response string, err error)

CreateUserJWT - creates a user jwt token

func DeTokenize

func DeTokenize(ctx context.Context, b64Token string) (*schema.EnrollmentKey, error)

DeTokenize - detokenizes a base64 encoded string and finds the associated enrollment key

func DefaultCleanupDeviceHostForOwnershipTransfer added in v1.7.0

func DefaultCleanupDeviceHostForOwnershipTransfer(ctx context.Context, host *schema.Host) error

DefaultCleanupDeviceHostForOwnershipTransfer removes pending joins and network nodes from a host.

func DeleteAcl added in v0.26.0

func DeleteAcl(ctx context.Context, a models.Acl) error

DeleteAcl - deletes acl policy

func DeleteDNS

func DeleteDNS(ctx context.Context, domain string, network string) error

DeleteDNS - deletes a DNS entry

func DeleteEgressGateway

func DeleteEgressGateway(network, nodeid string) (models.Node, error)

DeleteEgressGateway - deletes egress from node

func DeleteEnrollmentKey

func DeleteEnrollmentKey(ctx context.Context, value string, force bool) error

DeleteEnrollmentKey - deletes a given enrollment key by value

func DeleteExpiredNodes

func DeleteExpiredNodes(ctx context.Context)

DeleteExpiredNodes - goroutine which deletes nodes which are expired

func DeleteExtClient

func DeleteExtClient(ctx context.Context, network string, clientid string, isUpdate bool) error

DeleteExtClient - deletes an existing ext client

func DeleteExtClientAndCleanup added in v0.24.1

func DeleteExtClientAndCleanup(ctx context.Context, extClient models.ExtClient) error

DeleteExtClientAndCleanup - deletes an existing ext client and update ACLs

func DeleteGatewayExtClients

func DeleteGatewayExtClients(ctx context.Context, gatewayID string, networkName string) error

DeleteGatewayExtClients - deletes ext clients based on gateway (mac) of ingress node and network

func DeleteIngressGateway

func DeleteIngressGateway(ctx context.Context, nodeid string) (models.Node, []models.ExtClient, error)

DeleteIngressGateway - deletes an ingress gateway

func DeleteInternetEgressesForRoutingNode added in v1.7.0

func DeleteInternetEgressesForRoutingNode(ctx context.Context, network, nodeID string)

DeleteInternetEgressesForRoutingNode removes internet egress resources where nodeID is a routing node.

func DeleteNetwork

func DeleteNetwork(ctx context.Context, network string, force bool, done chan struct{}) error

DeleteNetwork - deletes a network

func DeleteNetworkDNS added in v1.6.0

func DeleteNetworkDNS(ctx context.Context, network string) error

func DeleteNetworkPolicies added in v0.90.0

func DeleteNetworkPolicies(ctx context.Context, netId schema.NetworkID)

DeleteNetworkPolicies - deletes all default network acl policies

func DeleteNode

func DeleteNode(ctx context.Context, node *models.Node, purge bool) error

func DeleteNodeByID added in v0.21.2

func DeleteNodeByID(ctx context.Context, node *models.Node) error

DeleteNodeByID - deletes a node from database

func DeleteOrgUser added in v1.7.0

func DeleteOrgUser(ctx context.Context, user *schema.User, forceDeleteConfigs bool, cleanup CleanupUserRefsFunc) error

func DeleteRelay added in v0.90.0

func DeleteRelay(network, nodeid string) ([]models.Node, models.Node, error)

DeleteRelay - deletes a relay

func DeleteTenantUser added in v1.7.0

func DeleteTenantUser(ctx context.Context, user *schema.User, forceDeleteConfigs bool, cleanup CleanupUserRefsFunc) error

func DetachExitRoutingNode added in v1.7.0

func DetachExitRoutingNode(ctx context.Context, node *models.Node) []models.Node

DetachExitRoutingNode prepares a routing node for removal from the network: fails open RelayedBy / IsIGWClient for exit clients (keeps sticky SelectedInternetEgressID), removes the node from internet egress routing maps (egress resource is kept for reassignment), and returns affected clients for an ordered fail-open peer update.

func DisassociateAllNodesFromHost

func DisassociateAllNodesFromHost(ctx context.Context, hostIDStr string) error

DisassociateAllNodesFromHost - deletes all nodes of the host. Performs reference cleanup and directly deletes each node record, bypassing host-association updates since the host itself is being removed.

func DisassociateNodeFromHost added in v1.7.0

func DisassociateNodeFromHost(ctx context.Context, n *models.Node, h *schema.Host) error

DisassociateNodeFromHost - deletes a node and removes from host nodes should be the only way nodes are deleted as of 0.18

func DisplaceAutoRelayedNodes added in v1.5.1

func DisplaceAutoRelayedNodes(nodeID string) []models.Node

DisplaceAutoRelayedNodes removes auto-assigned nodes from a disconnected gateway and returns the displaced nodes that need re-assignment.

func DoesHostExistInTheNetworkAlready added in v1.6.0

func DoesHostExistInTheNetworkAlready(h *schema.Host, network *schema.Network) bool

DoesHostExistInTheNetworkAlready checks if the host is in the network already. Must be called before creating the node. TODO: create (*orchestrator.NodeOrchestrator).ValidateCreateNode and move this there.

func DoesNodeHaveAccessToEgress added in v0.99.0

func DoesNodeHaveAccessToEgress(node *models.Node, e *schema.Egress, acls []models.Acl) bool

func DoesUserHaveAccessToEgress added in v1.1.0

func DoesUserHaveAccessToEgress(user *schema.User, e *schema.Egress, acls []models.Acl) bool

func DomainAnsForDomain added in v1.6.0

func DomainAnsForDomain(e schema.Egress, domain string) []string

DomainAnsForDomain returns resolved CIDRs for one configured domain.

func DomainAnsMapFromEgress added in v1.6.0

func DomainAnsMapFromEgress(e schema.Egress) map[string][]string

DomainAnsMapFromEgress returns domain -> resolved CIDRs from domain_ans_by_domain.

func EgressDNs added in v1.1.0

func EgressDNs(ctx context.Context, network string) (entries []models.DNSEntry)

func EgressDomainsEqual added in v1.6.0

func EgressDomainsEqual(a, b []string) bool

EgressDomainsEqual compares two domain lists as sets (order-independent).

func EnsureHostOwner added in v1.7.0

func EnsureHostOwner(host *schema.Host, username string)

EnsureHostOwner sets OwnerUsername on the host when it is currently empty in the database. Uses a conditional update so concurrent callers cannot overwrite an existing owner.

func EnterpriseCheck

func EnterpriseCheck(ctx context.Context, wg *sync.WaitGroup)

EnterpriseCheck - Runs enterprise functions if presented

func ErrExitClientBlocksAutoRelayRole added in v1.7.0

func ErrExitClientBlocksAutoRelayRole(node *models.Node) error

ErrExitClientBlocksAutoRelayRole returns an error when an exit client tries to act as an auto-relay gateway. Exit routing nodes remain valid auto-relay targets.

func ErrExitNodeBlocksAutoRelay added in v1.7.0

func ErrExitNodeBlocksAutoRelay(node *models.Node) error

ErrExitNodeBlocksAutoRelay returns an error when the node must not be auto-relayed (as victim/peer). Exit clients already have RelayedBy managed by exit selection; exit routing nodes must not be auto-relayed (same as manual relay). Exit routing nodes may still act as auto-relay gateways for other peers.

func ErrExitNodeBlocksGatewayOps added in v1.7.0

func ErrExitNodeBlocksGatewayOps(node *models.Node) error

ErrExitNodeBlocksGatewayOps returns an error when the node must not use GW assign/unassign/auto-assign. Exit clients have RelayedBy managed by exit selection; exit routers cannot be gateway clients.

func ExitClientOverlayIPs added in v1.7.0

func ExitClientOverlayIPs(peer *models.Node, excludeID string) []net.IPNet

ExitClientOverlayIPs returns /32 and /128 overlay addresses for clients in peer.RelayedNodes and peer.InetNodeReq.InetNodeClientIDs, excluding excludeID.

func ExitClientOverlayIPsFromInetClients added in v1.7.0

func ExitClientOverlayIPsFromInetClients(peer *models.Node, excludeID string) []net.IPNet

ExitClientOverlayIPsFromInetClients returns overlay IPs for InetNodeClientIDs that are not already listed in RelayedNodes (RelayedAllowedIPs covers those).

func ExpandEgressRouteRanges added in v1.7.0

func ExpandEgressRouteRanges(e schema.Egress, includeIPv6 bool) []string

ExpandEgressRouteRanges maps an egress resource to concrete CIDR ranges for peer/firewall config. Internet egress expands "*" to 0.0.0.0/0 (and optionally ::/0).

func ExtClientUsesInternetEgress added in v1.7.0

func ExtClientUsesInternetEgress(client models.ExtClient, _ models.Node) bool

ExtClientUsesInternetEgress reports whether the config file should route all traffic via its gateway exit node.

Using the gateway as an exit node is opt-in per client via SelectedInternetEgressID (the "Use gateway as exit node" toggle). It must NOT be forced on just because the gateway happens to be an internet gateway/exit node; clients that did not opt in should not get a full tunnel. Legacy full-tunnel clients are migrated to an explicit SelectedInternetEgressID, so no gateway-level fallback is needed.

func FailOpenAndDetachExitRoutingNode added in v1.7.0

func FailOpenAndDetachExitRoutingNode(ctx context.Context, node *models.Node)

FailOpenAndDetachExitRoutingNode detaches exit routing state for a node about to be removed, then pushes ordered fail-open peer updates to affected clients.

func FetchOAuthSecret added in v1.7.0

func FetchOAuthSecret(ctx context.Context) (string, error)

FetchOAuthSecret fetches secrets for oauth

func FileExists

func FileExists(f string) bool

FileExists - checks if local file exists

func FilterOutIPs added in v1.2.0

func FilterOutIPs(ips []string, filters map[string]bool) []string

FilterOutIPs removes ips in the filters map from the ips slice.

func FindInternetEgressByRoutingNode added in v1.7.0

func FindInternetEgressByRoutingNode(ctx context.Context, network, nodeID string) (*schema.Egress, error)

FindInternetEgressByRoutingNode returns an active internet egress that uses nodeID as a routing node.

func FirstInternetEgressRoutingNodeID added in v1.7.0

func FirstInternetEgressRoutingNodeID(e schema.Egress) string

FirstInternetEgressRoutingNodeID returns a routing node ID from an internet egress.

func FlattenDomainAnsMap added in v1.6.0

func FlattenDomainAnsMap(m map[string][]string) []string

FlattenDomainAnsMap returns a de-duplicated union of all resolved CIDRs in the map.

func FlushNodeCheckins added in v1.5.1

func FlushNodeCheckins()

FlushNodeCheckins - writes all buffered check-in updates to the DB in one batch. Called periodically (e.g., every 30s) to avoid per-checkin write lock contention.

func FormatError

func FormatError(err error, errType ApiErrorType) models.ErrorResponse

FormatError - takes ErrorResponse and uses correct code

func GenerateNodeName added in v0.30.0

func GenerateNodeName(ctx context.Context, network string) (string, error)

func GenerateOTPAuthURLSignature added in v1.0.0

func GenerateOTPAuthURLSignature(url string) string

func GetAcl added in v0.26.0

func GetAcl(ctx context.Context, aID string) (models.Acl, error)

GetAcl - gets acl info by id

func GetAclRuleForInetGw added in v0.99.0

func GetAclRuleForInetGw(targetnode models.Node) (rules map[string]models.AclRule)

func GetAclRulesForNode added in v0.30.0

func GetAclRulesForNode(ctx context.Context, targetnodeI *models.Node) (rules map[string]models.AclRule)

func GetAllDNS

func GetAllDNS(ctx context.Context) ([]models.DNSEntry, error)

GetAllDNS - gets all dns entries

func GetAllEnrollmentKeys

func GetAllEnrollmentKeys(ctx context.Context) ([]schema.EnrollmentKey, error)

GetAllEnrollmentKeys - fetches all enrollment keys from DB

func GetAllExtClients

func GetAllExtClients(ctx context.Context) ([]models.ExtClient, error)

GetAllExtClients - gets all ext clients from DB

func GetAllExtClientsWithStatus added in v0.99.0

func GetAllExtClientsWithStatus(ctx context.Context, status schema.NodeStatus) ([]models.ExtClient, error)

GetAllExtClientsWithStatus - returns all external clients with given status.

func GetAllHostsAPI

func GetAllHostsAPI(hosts []schema.Host) []models.ApiHost

GetAllHostsAPI - get's all the hosts in an API usable format

func GetAllHostsWithStatus added in v0.99.0

func GetAllHostsWithStatus(ctx context.Context, status schema.NodeStatus) ([]schema.Host, error)

GetAllHostsWithStatus - returns all hosts with at least one node with given status.

func GetAllNodes

func GetAllNodes(ctx context.Context) ([]models.Node, error)

GetAllNodes - returns all nodes in the DB

func GetAllNodesAPI

func GetAllNodesAPI(nodes []models.Node) []models.ApiNode

GetAllNodesAPI - get all nodes for api usage

func GetAllNodesAPIWithLocation added in v1.0.0

func GetAllNodesAPIWithLocation(nodes []models.Node) []models.ApiNode

GetAllNodesAPI - get all nodes for api usage

func GetAllRsrcIDForRsrc added in v1.1.0

func GetAllRsrcIDForRsrc(rsrc schema.RsrcType) schema.RsrcID

func GetAllowedEmailDomains added in v0.99.0

func GetAllowedEmailDomains(ctx context.Context) string

GetAllowedEmailDomains - gets the allowed email domains for oauth signup

func GetAllowedIPs

func GetAllowedIPs(ctx context.Context, node, peer *models.Node, metrics *models.Metrics) []net.IPNet

GetAllowedIPs - calculates the wireguard allowedip field for a peer of a node based on the peer and node settings

func GetAllowedIpForInetNodeClient added in v0.23.0

func GetAllowedIpForInetNodeClient(node, peer *models.Node) []net.IPNet

GetAllowedIpForInetNodeClient - get inet cidr for node using a inet gw. Dual-stack is decided from the exit peer host's public endpoints.

func GetAllowedIpsForRelayed

func GetAllowedIpsForRelayed(ctx context.Context, relayed, relay *models.Node) (allowedIPs []net.IPNet)

GetAllowedIpsForRelayed - returns the peerConfig for a node relayed by relay

func GetAuditLogsRetentionPeriodInDays added in v1.7.0

func GetAuditLogsRetentionPeriodInDays(ctx context.Context) int

func GetAuthProviderInfo added in v0.99.0

func GetAuthProviderInfo(settings models.ServerSettings) (pi []string)

GetAuthProviderInfo = gets the oauth provider info

func GetAzureTenant added in v0.99.0

func GetAzureTenant(ctx context.Context) string

GetAzureTenant - retrieve the azure tenant ID from env variable or config file

func GetCachedHostPeerUpdate added in v1.5.1

func GetCachedHostPeerUpdate(ctx context.Context, hostID string) (models.HostPeerUpdate, bool)

GetCachedHostPeerUpdate - returns a cached HostPeerUpdate if available.

func GetClientIP added in v1.0.0

func GetClientIP(r *http.Request) string

func GetCurrentServerUsage added in v1.2.0

func GetCurrentServerUsage(ctx context.Context) (limits models.Usage)

func GetCustomDNS

func GetCustomDNS(ctx context.Context, network string) ([]models.DNSEntry, error)

GetCustomDNS - gets the custom DNS of a network

func GetDNS

func GetDNS(ctx context.Context, network string) ([]models.DNSEntry, error)

GetDNS - gets the DNS of a current network

func GetDNSEntryNum

func GetDNSEntryNum(ctx context.Context, domain string, network string) (int, error)

GetDNSEntryNum - gets which entry the dns was

func GetDefaultDomain added in v0.99.0

func GetDefaultDomain(ctx context.Context) string

GetDefaultDomain - get the default domain

func GetDefaultEnrollmentKeyForNetwork added in v1.6.0

func GetDefaultEnrollmentKeyForNetwork(ctx context.Context, network string) (*schema.EnrollmentKey, error)

GetDefaultEnrollmentKeyForNetwork returns the default enrollment key for a network.

func GetDefaultHosts

func GetDefaultHosts(ctx context.Context) []schema.Host

GetDefaultHosts - retrieve all hosts marked as default from DB

func GetDefaultPolicy added in v0.26.0

func GetDefaultPolicy(ctx context.Context, netID schema.NetworkID, ruleType models.AclPolicyType) (models.Acl, error)

GetDefaultPolicy - fetches default policy in the network by ruleType

func GetDefaultTenantSettings added in v1.7.0

func GetDefaultTenantSettings() models.ServerSettings

func GetDeviceNetworks added in v1.7.0

func GetDeviceNetworks(ctx context.Context, user *schema.User, host *schema.Host) ([]models.DeviceNetwork, error)

GetDeviceNetworks returns networks accessible to the user with join/connection state for the host.

func GetDeviceSelectedExitNode added in v1.7.0

func GetDeviceSelectedExitNode(ctx context.Context, user *schema.User, host *schema.Host, networkID string) (*models.DeviceExitNode, error)

GetDeviceSelectedExitNode returns the currently selected exit node for the device on the network.

func GetEgressDefaultAllowAllFwRule added in v1.6.0

func GetEgressDefaultAllowAllFwRule(node models.Node) (models.AclRule, bool)

GetEgressDefaultAllowAllFwRule returns one bidirectional allow from the node's VPN (mesh) CIDR(s) to every egress LAN range this gateway advertises, for default all-resources device+user policies. Netclients use this to install a single mesh → LAN ACCEPT (e.g. 100.64.0.0/16 → 10.104.0.0/20).

func GetEgressDomainNSForNode added in v1.4.0

func GetEgressDomainNSForNode(ctx context.Context, node *models.Node) (returnNsLi []models.Nameserver)

func GetEgressDomainsByAccessForUser added in v1.4.0

func GetEgressDomainsByAccessForUser(ctx context.Context, user *schema.User, network schema.NetworkID) (domains []string)

func GetEgressIPs

func GetEgressIPs(peer *models.Node) []net.IPNet

func GetEgressPresetByID added in v1.6.0

func GetEgressPresetByID(id string) (models.EgressPresetApp, bool)

GetEgressPresetByID returns a catalog entry by id.

func GetEgressRanges added in v0.90.0

func GetEgressRanges(ctx context.Context, netID schema.NetworkID) (map[string][]string, map[string]struct{}, error)

func GetEgressRangesOnNetwork

func GetEgressRangesOnNetwork(ctx context.Context, client *models.ExtClient) ([]string, error)

ExtClient.GetEgressRangesOnNetwork - returns the egress ranges on network of ext client. Internet egress (0.0.0.0/0, ::/0) is excluded here: full-tunnel is opt-in via SelectedInternetEgressID and is applied only by ExtClientUsesInternetEgress / GetExtclientAllowedIPs (and the matching config-file path).

func GetEgressRulesForNode added in v0.90.0

func GetEgressRulesForNode(ctx context.Context, targetnode models.Node) (rules map[string]models.AclRule)

func GetEmaiSenderPassword added in v0.99.0

func GetEmaiSenderPassword(ctx context.Context) string

func GetEnrollmentKey

func GetEnrollmentKey(ctx context.Context, value string) (*schema.EnrollmentKey, error)

GetEnrollmentKey - fetches a single enrollment key by value

func GetExtClient

func GetExtClient(ctx context.Context, clientid string, network string) (models.ExtClient, error)

GetExtClient - gets a single ext client on a network

func GetExtClientByName

func GetExtClientByName(ctx context.Context, ID string) (models.ExtClient, error)

GetExtClientByName - gets an ext client by name

func GetExtClientsByID

func GetExtClientsByID(ctx context.Context, nodeid, network string) ([]models.ExtClient, error)

GetExtClientsByID - gets the clients of attached gateway

func GetExtPeers added in v0.24.2

func GetExtPeers(ctx context.Context, node, peer *models.Node, addressIdentityMap map[string]models.PeerIdentity) ([]wgtypes.PeerConfig, []models.IDandAddr, []models.EgressNetworkRoutes, error)

func GetExtclientAllowedIPs added in v0.22.0

func GetExtclientAllowedIPs(ctx context.Context, client models.ExtClient) (allowedIPs []string)

func GetExtclientDNS added in v0.22.0

func GetExtclientDNS(ctx context.Context) []models.DNSEntry

GetExtclientDNS - gets all extclients dns entries

func GetFwRulesOnIngressGateway added in v0.26.0

func GetFwRulesOnIngressGateway(ctx context.Context, node models.Node) (rules []models.FwRule)

func GetGwDNS added in v1.1.0

func GetGwDNS(node *models.Node) string

func GetHostNetworks

func GetHostNetworks(ctx context.Context, hostID string) []string

GetHostNetworks - fetches all the networks

func GetHostNodes

func GetHostNodes(host *schema.Host) []models.Node

GetHostNodes - fetches all nodes part of the host

func GetHostPeerInfo added in v0.90.0

func GetHostPeerInfo(ctx context.Context, host *schema.Host) (models.HostPeerInfo, error)

GetHostPeerInfo - returns cached peer info for a host. Falls back to on-demand computation if the cache is not yet populated.

func GetIDPSyncInterval added in v0.99.0

func GetIDPSyncInterval(ctx context.Context) time.Duration

GetIDPSyncInterval returns the interval at which the netmaker should sync data from IDP.

func GetIngressGwUsers

func GetIngressGwUsers(node models.Node) (models.IngressGwUsers, error)

GetIngressGwUsers - lists the users having to access to ingressGW

func GetJwtSecretValue added in v1.7.0

func GetJwtSecretValue() (string, error)

GetJwtSecretValue fetches jwt secret from db

func GetJwtValidityDuration added in v0.99.0

func GetJwtValidityDuration(ctx context.Context) time.Duration

GetJwtValidityDuration - returns the JWT validity duration in minutes

func GetJwtValidityDurationForClients added in v1.1.0

func GetJwtValidityDurationForClients(ctx context.Context) time.Duration

GetJwtValidityDurationForClients returns the JWT validity duration in minutes for clients.

func GetLoginMethodsForUser added in v1.7.0

func GetLoginMethodsForUser(ctx context.Context, username string) ([]models.LoginOption, error)

GetLoginMethodsForUser returns available login options for the given username. Returns an empty slice (not an error) when the user is not found.

func GetManageDNS added in v0.99.0

func GetManageDNS(ctx context.Context) bool

GetManageDNS - if manage DNS enabled or not

func GetMetricInterval added in v0.99.0

func GetMetricInterval(ctx context.Context) string

GetMetricInterval - get the publish metric interval

func GetMetricIntervalInMinutes added in v0.99.0

func GetMetricIntervalInMinutes(ctx context.Context) time.Duration

GetMetricIntervalInMinutes returns the publish-to-exporter interval from server settings (dashboard), with fallback to servercfg / env when unset or invalid.

func GetMetricsPort added in v0.99.0

func GetMetricsPort(ctx context.Context) int

GetMetricsPort - get metrics port

func GetNetworkExtClients

func GetNetworkExtClients(ctx context.Context, network string) ([]models.ExtClient, error)

GetNetworkExtClients - gets the ext clients of given network

func GetNetworkNetworkCIDR4 added in v1.5.1

func GetNetworkNetworkCIDR4(network *schema.Network) *net.IPNet

func GetNetworkNetworkCIDR6 added in v1.5.1

func GetNetworkNetworkCIDR6(network *schema.Network) *net.IPNet

func GetNetworkNodes

func GetNetworkNodes(ctx context.Context, network string) ([]models.Node, error)

GetNetworkNodes - gets the nodes of a network

func GetNetworkNodesMemory

func GetNetworkNodesMemory(allNodes []models.Node, network string) []models.Node

GetNetworkNodesMemory - gets all nodes belonging to a network from list in memory

func GetNetworkNonServerNodeCount

func GetNetworkNonServerNodeCount(ctx context.Context, networkName string) (int, error)

GetNetworkNonServerNodeCount - get number of network non server nodes

func GetNodeByHostRef added in v0.21.2

func GetNodeByHostRef(ctx context.Context, hostid, network string) (node models.Node, err error)

GetNodeByHostRef - gets the node by host id and network

func GetNodeByID

func GetNodeByID(nodeID string) (models.Node, error)

func GetNodeCheckInStatus added in v0.90.0

func GetNodeCheckInStatus(node *schema.Node) schema.NodeStatus

func GetNodeDNS

func GetNodeDNS(ctx context.Context, network string) ([]models.DNSEntry, error)

GetNodeDNS - gets the DNS of a network node

func GetNodeEgressInfo added in v0.99.0

func GetNodeEgressInfo(targetNode *models.Node, eli []schema.Egress, acls []models.Acl)

func GetNodeExitNode added in v1.7.0

func GetNodeExitNode(ctx context.Context, network, nodeID string) (*models.DeviceExitNode, error)

GetNodeExitNode returns the internet egress currently assigned to the node.

func GetNodesByIDs added in v1.6.0

func GetNodesByIDs(ids []string) (map[string]models.Node, error)

GetNodesByIDs fetches all nodes whose IDs are in the given slice in a single preloaded query and returns them as a map keyed by node ID. IDs that don't resolve to a node row are simply absent from the result map.

This avoids the N+1 (and N^2) query patterns that arise when callers loop over peer IDs and call GetNodeByID per peer (e.g. status / connectivity checks driven by metrics).

func GetNodesStatusAPI added in v0.90.0

func GetNodesStatusAPI(nodes []models.Node) map[string]models.ApiNodeStatus

GetNodesStatusAPI - gets nodes status

func GetOnboardingStatus added in v1.6.0

func GetOnboardingStatus(ctx context.Context, username string) (models.OnboardingStatus, error)

GetOnboardingStatus reports whether the UI should show the first-network onboarding flow.

func GetOrgSettings added in v1.7.0

func GetOrgSettings(ctx context.Context) schema.OrganizationSettingsData

GetOrgSettings returns the organization settings for the organization scoped by ctx (resolving through the tenant if ctx is tenant-scoped).

func GetPeerListenPort

func GetPeerListenPort(host *schema.Host) int

GetPeerListenPort - given a host, retrieve it's appropriate listening port

func GetPeerUpdateForHost

func GetPeerUpdateForHost(ctx context.Context, network string, host *schema.Host, allNodes []models.Node, deletedHost *schema.Host, deletedNode *models.Node, deletedClients []models.ExtClient) (hostPeerUpdate models.HostPeerUpdate, err error)

GetPeerUpdateForHost - gets the consolidated peer update for the host from all networks

func GetRacRestrictToSingleNetwork added in v0.99.0

func GetRacRestrictToSingleNetwork(ctx context.Context) bool

GetRacRestrictToSingleNetwork - returns whether the feature to allow simultaneous network connections via RAC is enabled

func GetRecordKey

func GetRecordKey(id string, network string) (string, error)

GetRecordKey - get record key depricated

func GetRunningHooks added in v1.4.0

func GetRunningHooks() []string

GetRunningHooks - returns a list of currently running hook IDs

func GetSelectedInternetEgress added in v1.7.0

func GetSelectedInternetEgress(node *models.Node) (*schema.Egress, error)

GetSelectedInternetEgress returns the internet egress selected by the node, if any and still valid.

func GetSenderEmail added in v0.99.0

func GetSenderEmail(ctx context.Context) string

func GetSenderUser added in v0.99.0

func GetSenderUser(ctx context.Context) string

func GetServerConfig added in v0.99.0

func GetServerConfig(ctx context.Context) config.ServerConfig

GetServerConfig - gets the server config into memory from file or env

func GetServerInfo added in v0.99.0

func GetServerInfo(ctx context.Context) models.ServerConfig

GetServerInfo - gets the server config into memory from file or env

func GetServerSettings added in v0.99.0

func GetServerSettings(ctx context.Context) (s models.ServerSettings)

func GetServerSettingsFromEnv added in v0.99.0

func GetServerSettingsFromEnv() (s models.ServerSettings)

func GetSmtpHost added in v0.99.0

func GetSmtpHost(ctx context.Context) string

func GetSmtpPort added in v0.99.0

func GetSmtpPort(ctx context.Context) int

func GetState

func GetState(state string) (*models.SsoState, error)

GetState - gets an SsoState from DB, if expired returns error

func GetStaticNodeIps added in v0.26.0

func GetStaticNodeIps(ctx context.Context, node models.Node) (ips []net.IP)

func GetStaticNodesByNetwork added in v0.26.0

func GetStaticNodesByNetwork(ctx context.Context, network schema.NetworkID, onlyWg bool) (staticNode []models.Node)

func GetStunServers added in v0.99.0

func GetStunServers(ctx context.Context) string

func GetSuperAdmin

func GetSuperAdmin(ctx context.Context) (models.ReturnUser, error)

GetSuperAdmin - fetches superadmin user

func GetTenantNetworkHookID added in v1.7.0

func GetTenantNetworkHookID(ctx context.Context) string

func GetUserInvite added in v0.25.0

func GetUserInvite(ctx context.Context, email string) (*schema.UserInvite, error)

func GetUserMap added in v0.25.0

func GetUserMap() (map[string]schema.User, error)

func GetUserNameFromToken added in v0.25.0

func GetUserNameFromToken(ctx context.Context, authtoken string) (username string, err error)

func GetUserSettings added in v1.1.0

func GetUserSettings(username string) models.UserSettings

func GetVerbosity added in v0.99.0

func GetVerbosity(ctx context.Context) int32

func HasEgressDomainAns added in v1.6.0

func HasEgressDomainAns(e schema.Egress) bool

HasEgressDomainAns is true when at least one resolved CIDR exists for any domain.

func HostExists

func HostExists(h *schema.Host) bool

HostExists - checks if given host already exists

func IfaceDelta

func IfaceDelta(currentNode *models.Node, newNode *models.Node) bool

IfaceDelta - checks if the new node causes an interface change

func InferEgressType added in v1.7.0

func InferEgressType(req *models.EgressReq) schema.EgressType

InferEgressType derives the egress type from request fields when Type is unset.

func InitNetworkHooks added in v1.4.0

func InitNetworkHooks(ctx context.Context)

func InsertAcl added in v0.26.0

func InsertAcl(ctx context.Context, a models.Acl) error

InsertAcl - creates acl policy

func InternetEgressRanges added in v1.7.0

func InternetEgressRanges(includeIPv6 bool) []string

InternetEgressRanges returns the WireGuard/firewall ranges for an internet egress.

func InternetExitRoutingNodeID added in v1.7.0

func InternetExitRoutingNodeID(node *models.Node) string

InternetExitRoutingNodeID returns the node ID used for full-internet exit. Prefers SelectedInternetEgressID (source of truth). When a selection is set but the egress is unavailable (disabled/missing), returns "" so clients fail open to local internet while keeping the sticky selection — do not fall back to InternetGwID in that case. Legacy InternetGwID is only used when no selection is set.

func InvalidateHostPeerCaches added in v1.5.1

func InvalidateHostPeerCaches(ctx context.Context)

InvalidateHostPeerCaches clears both hostPeerInfoCache and hostPeerUpdateCache so they are rebuilt on next access or refresh.

func InvalidateServerSettingsCache added in v1.5.1

func InvalidateServerSettingsCache(ctx context.Context)

InvalidateServerSettingsCache clears the in-memory settings cache for the tenant scoped by ctx so the next GetServerSettings call re-reads from the database.

func IsAWSEgressPreset added in v1.6.0

func IsAWSEgressPreset(presetID string) bool

IsAWSEgressPreset reports whether presetID refers to an AWS catalog entry.

func IsAclExists added in v0.26.0

func IsAclExists(ctx context.Context, aclID string) bool

IsAclExists - checks if acl exists

func IsAddressInCIDR

func IsAddressInCIDR(address net.IP, cidr string) bool

IsAddressInCIDR - util to see if an address is in a cidr or not

func IsBase64

func IsBase64(s string) bool

IsBase64 - checks if a string is in base64 format This is used to validate public keys (make sure they're base64 encoded like all public keys should be).

func IsBasicAuthEnabled added in v0.99.0

func IsBasicAuthEnabled(ctx context.Context) bool

IsBasicAuthEnabled - checks if basic auth has been configured to be turned off

func IsDNSEntryValid added in v0.30.0

func IsDNSEntryValid(d string) bool

IsNetworkNameValid - checks if a netid of a network uses valid characters

func IsDomainBasedEgress added in v1.6.0

func IsDomainBasedEgress(e schema.Egress) bool

IsDomainBasedEgress is true when this egress has at least one configured logical domain.

func IsEgressAppEgress added in v1.6.0

func IsEgressAppEgress(e schema.Egress) bool

IsEgressAppEgress reports whether the egress was created from a catalog preset (egress app).

func IsEgressDomainPattern added in v1.6.0

func IsEgressDomainPattern(domain string) bool

IsEgressDomainPattern returns true for a normal FQDN or a single-label wildcard prefix form (*.example.com).

func IsEgressInternetGateway added in v1.6.0

func IsEgressInternetGateway(e schema.Egress) bool

IsEgressInternetGateway is true when type is internet or range is "*" (full internet egress).

func IsEgressReqInternetGateway added in v1.6.0

func IsEgressReqInternetGateway(req *models.EgressReq) bool

IsEgressReqInternetGateway is true when the request uses type internet or range "*" for internet egress.

func IsEgressRoutingPolicyAllowedForNodes added in v1.6.0

func IsEgressRoutingPolicyAllowedForNodes(policy models.Acl, node, peer models.Node) bool

IsEgressRoutingPolicyAllowedForNodes reports whether `policy` permits a peering relationship (and corresponding mesh peer ACL rule) between `node` and `peer` on either side of an egress<->egress flow. WireGuard peering is inherently bidirectional: even a Uni "src-egress -> dst-egress" policy requires the src-router and dst-router hosts to complete a wg handshake so the tunnel can carry the one-way L4 traffic. The L4 direction (Uni vs Bi) is then enforced downstream by the FORWARD/INPUT rule generators, not at peer-allow time. We therefore accept the policy whenever EITHER side of the pair routes the matching egress, otherwise the dst-side router would never add the src-side router as a peer (callers query symmetrically as (X, Y) and (Y, X)) and the handshake would silently never occur.

func IsEndpointDetectionEnabled added in v0.99.0

func IsEndpointDetectionEnabled(ctx context.Context) bool

IsEndpointDetectionEnabled - returns true if endpoint detection enabled

func IsFQDN added in v1.1.0

func IsFQDN(domain string) bool

IsFQDN checks if the given string is a valid Fully Qualified Domain Name (FQDN)

func IsIDPUser added in v1.7.0

func IsIDPUser(ctx context.Context, user *schema.User) bool

func IsInternetGw added in v0.22.0

func IsInternetGw(node models.Node) bool

IsInternetGw - checks if node is acting as internet gw (legacy flag or internet egress router)

func IsMFAEnforced added in v1.0.0

func IsMFAEnforced(ctx context.Context) bool

IsMFAEnforced returns whether MFA has been enforced.

func IsNetworkCIDRUnique added in v0.21.2

func IsNetworkCIDRUnique(ctx context.Context, cidr4 *net.IPNet, cidr6 *net.IPNet) bool

func IsNetworkNameUnique

func IsNetworkNameUnique(ctx context.Context, network *schema.Network) (bool, error)

IsNetworkNameUnique - checks to see if any other networks have the same name (id)

func IsNodeAllowedToCommunicate added in v0.26.0

func IsNodeAllowedToCommunicate(ctx context.Context, node, peer models.Node, checkDefaultPolicy bool) (bool, []models.Acl)

IsNodeAllowedToCommunicate - check node is allowed to communicate with the peer // ADD ALLOWED DIRECTION - 0 => node -> peer, 1 => peer-> node,

func IsNodeAllowedToCommunicateWithAllRsrcs added in v1.1.0

func IsNodeAllowedToCommunicateWithAllRsrcs(ctx context.Context, node models.Node) bool

func IsOauthUser added in v0.25.0

func IsOauthUser(ctx context.Context, user *schema.User) error

IsOauthUser - returns

func IsPendingUser added in v0.24.0

func IsPendingUser(ctx context.Context, username string) bool

func IsSlicesEqual added in v0.22.0

func IsSlicesEqual(a, b []string) bool

IsSlicesEqual tells whether a and b contain the same elements. A nil argument is equivalent to an empty slice.

func IsStateValid

func IsStateValid(state string) (string, bool)

IsStateValid - checks if given state is valid or not deletes state after call is made to clean up, should only be called once per sign-in

func IsStunEnabled added in v0.99.0

func IsStunEnabled(ctx context.Context) bool

IsStunEnabled - returns true if STUN set to on

func IsSyncEnabled added in v0.99.0

func IsSyncEnabled(ctx context.Context) bool

IsSyncEnabled returns whether auth provider sync is enabled.

func IsUserAllowedAccessToExtClient

func IsUserAllowedAccessToExtClient(username string, client models.ExtClient) bool

IsUserAllowedAccessToExtClient - checks if user has permission to access extclient

func IsValidMatchDomain added in v1.1.0

func IsValidMatchDomain(s string) bool

IsValidMatchDomain reports whether s is a valid "match domain". Rules (simple/ASCII):

  • "~." is allowed (match all).
  • Optional leading "~" allowed (e.g., "~example.com").
  • Optional single trailing "." allowed (FQDN form).
  • No wildcards "*", no leading ".", no underscores.
  • Labels: letters/digits/hyphen (LDH), 1–63 chars, no leading/trailing hyphen.
  • Total length (without trailing dot) ≤ 253.

func IsValidVersion added in v1.4.0

func IsValidVersion(raw string) bool

IsValidVersion returns true if the version string can be parsed as semantic version.

func IsVersionCompatible added in v0.24.1

func IsVersionCompatible(ver string) bool

IsVersionCompatible checks that the version passed is compabtible (>=) with MinVersion

func JoinDeviceNetwork added in v1.7.0

func JoinDeviceNetwork(ctx context.Context, user *schema.User, host *schema.Host, networkID string) (models.DeviceJoinResult, error)

JoinDeviceNetwork adds the host to a network on behalf of the user.

func LeaveDeviceNetwork added in v1.7.0

func LeaveDeviceNetwork(ctx context.Context, user *schema.User, host *schema.Host, networkID string) error

LeaveDeviceNetwork removes the host from a network or cancels a pending approval request.

func ListAcls added in v0.26.0

func ListAcls(ctx context.Context) (acls []models.Acl)

func ListAclsByNetwork added in v0.30.0

func ListAclsByNetwork(ctx context.Context, netID schema.NetworkID) ([]models.Acl, error)

ListAclsByNetwork lists all acl policies in network

func ListAllByRoutingNodeWithDomain added in v1.1.0

func ListAllByRoutingNodeWithDomain(egs []schema.Egress, nodeID string) (egWithDomain []models.EgressDomain)

func ListDeviceExitNodes added in v1.7.0

func ListDeviceExitNodes(ctx context.Context, user *schema.User, host *schema.Host, networkID string) ([]models.DeviceExitNode, error)

ListDeviceExitNodes returns internet-type egresses in the network the user may select, filtered by ACL when the default device policy is disabled.

func ListDevicePolicies added in v0.99.0

func ListDevicePolicies(ctx context.Context, netID schema.NetworkID) []models.Acl

ListDevicePolicies - lists all device policies in a network

func ListEgressAcls added in v0.99.0

func ListEgressAcls(ctx context.Context, egressID string) ([]models.Acl, error)

func ListEgressPresets added in v1.6.0

func ListEgressPresets() []models.EgressPresetApp

ListEgressPresets returns the static egress preset catalog (defensive copy of slice header; entries are values).

func ListExitClientsForRoutingNode added in v1.7.0

func ListExitClientsForRoutingNode(ctx context.Context, network, routingNodeID string) []models.Node

ListExitClientsForRoutingNode returns mesh nodes using this node as their internet exit, via RelayedIGWClients and/or SelectedInternetEgressID pointing at an egress this node routes.

func ListNodeExitNodes added in v1.7.0

func ListNodeExitNodes(ctx context.Context, network, nodeID string) ([]models.DeviceExitNode, error)

ListNodeExitNodes returns active internet egresses in the network for admin assignment.

func ListNodesBySelectedInternetEgress added in v1.7.0

func ListNodesBySelectedInternetEgress(ctx context.Context, network, egressID string) []models.Node

ListNodesBySelectedInternetEgress returns network nodes that have selected the given egress.

func ListUserPolicies added in v0.26.0

func ListUserPolicies(ctx context.Context, netID schema.NetworkID) []models.Acl

ListUserPolicies - lists all user policies in a network

func ManageZombies

func ManageZombies(ctx context.Context)

ManageZombies - lists tenants and starts a per-tenant zombie-management worker for each.

func MarkStaleNodesOffline added in v1.6.0

func MarkStaleNodesOffline(ctx context.Context)

MarkStaleNodesOffline runs on a ticker and bulk-updates the status of every node whose last_check_in is older than models.LastCheckInThreshold to schema.OfflineSt. Promotion back to OnlineSt happens in mq.HandleHostCheckin when a node recovers; the metrics-driven path in pro/logic refines the status further on the next metrics message.

Intended to be started once from the master pod.

func Mask added in v0.99.0

func Mask() string

func MigrateAclPolicies added in v0.30.0

func MigrateAclPolicies(ctx context.Context)

func ModelsEnrollmentKeyFromSchema added in v1.7.0

func ModelsEnrollmentKeyFromSchema(key schema.EnrollmentKey) models.EnrollmentKey

ModelsEnrollmentKeyFromSchema converts a schema enrollment key to the models type.

func NetworkExists

func NetworkExists(ctx context.Context, name string) (bool, error)

func NodeIsInternetEgressRouter added in v1.7.0

func NodeIsInternetEgressRouter(ctx context.Context, nodeID, network string) bool

NodeIsInternetEgressRouter reports whether the node is a routing node for any active internet egress.

func NormalizeAndValidateAclEgressIPs added in v1.6.0

func NormalizeAndValidateAclEgressIPs(acl *models.Acl) error

func NormalizeCIDR

func NormalizeCIDR(address string) (string, error)

NormalizeCIDR - returns the first address of CIDR

func NormalizeEgressReqDomains added in v1.6.0

func NormalizeEgressReqDomains(domains []string) ([]string, error)

NormalizeEgressReqDomains validates each domain entry (FQDN or *.suffix), lowercases, and deduplicates while preserving input order.

func NormalizeEgressType added in v1.7.0

func NormalizeEgressType(e *schema.Egress)

NormalizeEgressType sets Type from range/domains/preset when empty, and forces internet invariants.

func NormalizeIPOrCIDR added in v1.6.0

func NormalizeIPOrCIDR(value string) (string, error)

func NormalizeOSName added in v1.4.0

func NormalizeOSName(raw string) string

func NotifyMetricExportIntervalChanged added in v1.6.0

func NotifyMetricExportIntervalChanged(ctx context.Context)

NotifyMetricExportIntervalChanged signals mq.Keepalive to reset the metrics export ticker for ctx's tenant.

func NthSubnet added in v1.5.1

func NthSubnet(pool *net.IPNet, newPrefixLen int, n int) *net.IPNet

NthSubnet calculates the nth subnet of a given prefix length within a pool.

func OSFamily added in v1.4.0

func OSFamily(osName string) string

OSFamily returns a normalized OS family string. Examples: "linux-debian", "linux-redhat", "linux-arch", "linux-other", "windows", "darwin"

func PopulateAclPolicyTagNames added in v1.5.1

func PopulateAclPolicyTagNames(ctx context.Context, acls []models.Acl)

PopulateAclPolicyTagNames resolves human-readable names for ACL policy tags

func PreAuthCheck added in v1.0.0

func PreAuthCheck(next http.Handler) http.HandlerFunc

func PresetYieldsAWSIPRanges added in v1.6.0

func PresetYieldsAWSIPRanges(p models.EgressPresetApp) bool

PresetYieldsAWSIPRanges reports whether the preset is backed by AWS ip-ranges.json.

func PruneStaleRelayedClients added in v1.7.0

func PruneStaleRelayedClients(node *models.Node) bool

PruneStaleRelayedClients drops RelayedNodes / InetNodeReq entries that no longer belong on this gateway (missing nodes, or nodes no longer RelayedBy it) and persists when anything changed. Returns true if pruned.

func RandomString

func RandomString(length int) string

RandomString - returns a random string in a charset

func RebindInternetEgressClients added in v1.7.0

func RebindInternetEgressClients(ctx context.Context, e schema.Egress)

RebindInternetEgressClients re-applies exit selection for clients of an internet egress after its routing node set changes (e.g. reassignment to a new node).

func RefreshHostPeerInfoCache added in v1.5.1

func RefreshHostPeerInfoCache(ctx context.Context) ([]schema.Host, []models.Node)

RefreshHostPeerInfoCache - batch pre-computes peer info for all hosts and stores the results in the cache. Returns the fetched hosts and nodes so callers can reuse them without redundant DB queries.

func RegenerateEnrollmentKeyToken added in v1.6.0

func RegenerateEnrollmentKeyToken(ctx context.Context, keyValue string) (*schema.EnrollmentKey, error)

RegenerateEnrollmentKeyToken replaces the enrollment key value, invalidating any previously issued registration tokens while preserving key configuration.

func RegisterDevice added in v1.7.0

func RegisterDevice(ctx context.Context, user *schema.User, newHost *schema.Host) (models.RegisterResponse, error)

RegisterDevice registers or updates a host on behalf of an authenticated user (Desktop/netclient JWT flow).

func RelayUpdates

func RelayUpdates(currentNode, newNode *models.Node) bool

func RelayedAllowedIPs

func RelayedAllowedIPs(ctx context.Context, peer, node *models.Node) []net.IPNet

func RemoveAllFromSlice added in v1.2.0

func RemoveAllFromSlice[T comparable](s []T, val T) []T

RemoveAllFromSlice removes every occurrence of val from s (stable order).

func RemoveHost

func RemoveHost(ctx context.Context, h *schema.Host, forceDelete bool) error

RemoveHost - removes a given host from server

func RemoveNodeFromAclPolicy added in v0.90.0

func RemoveNodeFromAclPolicy(ctx context.Context, node models.Node)

func RemoveNodeFromAllGatewayRelays added in v1.7.0

func RemoveNodeFromAllGatewayRelays(ctx context.Context, networkName, nodeID string)

RemoveNodeFromAllGatewayRelays removes nodeID from RelayedClients / RelayedIGWClients on every node in the network. Used on delete so orphan map keys cannot linger.

func RemoveNodeFromEgress added in v0.99.0

func RemoveNodeFromEgress(node models.Node)

func RemoveNodeFromEnrollmentKeys added in v1.5.1

func RemoveNodeFromEnrollmentKeys(node *models.Node)

func RemoveStringSlice

func RemoveStringSlice(slice []string, i int) []string

RemoveStringSlice - removes an element at given index i from a given string slice

func RemoveTagFromEnrollmentKeys added in v0.26.0

func RemoveTagFromEnrollmentKeys(deletedTagID models.TagID)

func RequiresProEgressType added in v1.6.0

func RequiresProEgressType(e schema.Egress) bool

RequiresProEgressType reports whether the egress uses domain-based or preset app routing.

func ResetHook added in v1.4.0

func ResetHook(hookID string)

ResetHook - resets the timer for a hook with the given ID

func ResolveAWSEgressPresetCIDRs added in v1.6.0

func ResolveAWSEgressPresetCIDRs(client *http.Client, p models.EgressPresetApp) ([]string, error)

ResolveAWSEgressPresetCIDRs fetches public AWS CIDR data for a supported AWS preset.

func ResolveInheritedAuth added in v1.7.0

func ResolveInheritedAuth(ctx context.Context, user *schema.User) error

func ResolveInternetExitRoutingNode added in v1.7.0

func ResolveInternetExitRoutingNode(node *models.Node)

ResolveInternetExitRoutingNode sets node.InternetGwID in-memory from SelectedInternetEgressID for peer-update helpers that still read InternetGwID. Does not persist. When the selected egress is unavailable, clears InternetGwID so fail-open is consistent.

func RestartHook added in v1.4.0

func RestartHook(hookID string, newInterval time.Duration)

RestartHook - restarts a hook with the given ID (stops and starts again with same configuration) If newInterval is 0, uses the existing interval. Otherwise, uses the new interval.

func RetrievePrivateTrafficKey

func RetrievePrivateTrafficKey() ([]byte, error)

RetrievePrivateTrafficKey retrieves private key of server

func RetrievePublicTrafficKey

func RetrievePublicTrafficKey() ([]byte, error)

RetrievePublicTrafficKey retrieves public key of server

func ReturnAcceptedResponse added in v1.5.1

func ReturnAcceptedResponse(response http.ResponseWriter, request *http.Request, message string)

ReturnAcceptedResponse - returns 202 Accepted for async operations

func ReturnErrorResponse

func ReturnErrorResponse(response http.ResponseWriter, request *http.Request, errorMessage models.ErrorResponse)

ReturnErrorResponse - processes error and adds header

func ReturnErrorResponseWithJson added in v1.4.0

func ReturnErrorResponseWithJson(response http.ResponseWriter, request *http.Request, msg interface{}, errorMessage models.ErrorResponse)

ReturnErrorResponseWithJson - processes error with body and adds header

func ReturnSuccessResponse

func ReturnSuccessResponse(response http.ResponseWriter, request *http.Request, message string)

ReturnSuccessResponse - processes message and adds header

func ReturnSuccessResponseWithJson added in v0.22.0

func ReturnSuccessResponseWithJson(response http.ResponseWriter, request *http.Request, res interface{}, message string)

ReturnSuccessResponseWithJson - processes message and adds header

func SanitizeRelayedNodesForUpdate added in v1.7.0

func SanitizeRelayedNodesForUpdate(gatewayID string, requested []string, priorMapKeys map[string]struct{}) []string

SanitizeRelayedNodesForUpdate drops missing / orphan RelayedNodes IDs from a gateway update payload while still allowing genuinely new assignments (node exists, RelayedBy empty, and ID was not already a stale map key).

func SaveExtClient

func SaveExtClient(ctx context.Context, extclient *models.ExtClient) error

SaveExtClient - saves an ext client to database

func SchemaEnrollmentKeyFromModels added in v1.7.0

func SchemaEnrollmentKeyFromModels(key models.EnrollmentKey) *schema.EnrollmentKey

SchemaEnrollmentKeyFromModels converts a models enrollment key to the schema type.

func SecurityCheck

func SecurityCheck(reqAdmin bool, next http.Handler) http.HandlerFunc

SecurityCheck - Check if user has appropriate permissions

func SelectDeviceExitNode added in v1.7.0

func SelectDeviceExitNode(ctx context.Context, user *schema.User, host *schema.Host, networkID, egressID string, useTcpUplink bool) (*models.DeviceExitNode, error)

SelectDeviceExitNode sets or clears the selected internet egress for the device's node on the network. useTcpUplink opts into TCP uplink when the exit routing gateway has TCP proxy enabled.

func SetDNSOnWgConfig added in v1.1.0

func SetDNSOnWgConfig(gwNode *models.Node, extclient *models.ExtClient)

func SetDefaultGw added in v0.23.0

func SetDefaultGw(node models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate

func SetEgressDomainAnsForDomain added in v1.6.0

func SetEgressDomainAnsForDomain(e *schema.Egress, domain string, ans []string)

SetEgressDomainAnsForDomain sets resolved CIDRs for a single domain.

func SetEgressDomainAnsForDomains added in v1.6.0

func SetEgressDomainAnsForDomains(e *schema.Egress, domains, ans []string)

SetEgressDomainAnsForDomains assigns the same resolved CIDRs to each domain (e.g. static presets).

func SetInternetGw added in v0.22.0

func SetInternetGw(node *models.Node, req models.InetNodeReq)

SetInternetGw - sets the node as internet gw based on flag bool

func SetJWTSecret

func SetJWTSecret()

SetJWTSecret - sets the jwt secret on server startup

func SetNetworkNodesLastModified

func SetNetworkNodesLastModified(ctx context.Context, networkName string) error

SetNetworkNodesLastModified - sets the network nodes last modified

func SetNodeSelectedInternetEgress added in v1.7.0

func SetNodeSelectedInternetEgress(node *models.Node, egressID string, useTcpUplink bool) error

SetNodeSelectedInternetEgress sets or clears the node's selected internet egress. Selecting an exit also relays the node through that egress routing node (IsIGWClient), so NAT'd full-tunnel clients remain reachable via the gateway. InternetGwID is not dual-written. useTcpUplink opts the client into TCP uplink when the routing gateway has TCP proxy enabled.

func SetOAuthSecret added in v1.7.0

func SetOAuthSecret(secret string) error

func SetRelayedNodes

func SetRelayedNodes(setRelayed bool, relay string, relayed []string) []models.Node

SetRelayedNodes- sets and saves node as relayed

func SetState

func SetState(scope scope.Scope, scopeID, appName, state string) error

SetState - sets a state with new expiration

func SetVerbosity added in v0.90.0

func SetVerbosity(logLevel int)

func SmtpSkipTlsVerify added in v1.7.0

func SmtpSkipTlsVerify(ctx context.Context) bool

func SoleOrganization added in v1.7.0

func SoleOrganization(ctx context.Context) (*schema.Organization, error)

func SoleTenant added in v1.7.0

func SoleTenant(ctx context.Context) (*schema.Tenant, error)

func SortAclEntrys added in v0.26.0

func SortAclEntrys(acls []models.Acl)

SortTagEntrys - Sorts slice of Tag entries by their id

func SortApiHosts

func SortApiHosts(unsortedHosts []models.ApiHost)

SortApiHosts - Sorts slice of ApiHosts by their ID alphabetically with numbers first

func SortApiNodes

func SortApiNodes(unsortedNodes []models.ApiNode)

SortApiNodes - Sorts slice of ApiNodes by their ID alphabetically with numbers first

func SortDNSEntrys

func SortDNSEntrys(unsortedDNSEntrys []models.DNSEntry)

SortDNSEntrys - Sorts slice of DNSEnteys by their Address alphabetically with numbers first

func SortExtClient

func SortExtClient(unsortedExtClient []models.ExtClient)

SortExtClient - Sorts slice of ExtClients by their ClientID alphabetically with numbers first

func SortNetworks

func SortNetworks(unsortedNetworks []schema.Network)

SortNetworks - Sorts slice of Networks by their NetID alphabetically with numbers first

func SortUsers

func SortUsers(unsortedUsers []models.ReturnUser)

SortUsers - Sorts slice of Users by username

func StartCPUProfiling added in v0.26.0

func StartCPUProfiling() *os.File

func StartHookManager

func StartHookManager(ctx context.Context, wg *sync.WaitGroup)

StartHookManager - listens on `HookManagerCh` to run any hook and `HookCommandCh` for commands

func StartMemProfiling added in v0.30.0

func StartMemProfiling()

func StopCPUProfiling added in v0.26.0

func StopCPUProfiling(f *os.File)

func StopHook added in v1.4.0

func StopHook(hookID string)

StopHook - stops a hook with the given ID

func StoreHostPeerUpdate added in v1.5.1

func StoreHostPeerUpdate(ctx context.Context, hostID string, peerUpdate models.HostPeerUpdate)

StoreHostPeerUpdate - caches a computed HostPeerUpdate for a host. Called as a side-effect of PublishSingleHostPeerUpdate during broadcast.

func StoreJWTSecret

func StoreJWTSecret(privateKey string) error

StoreJWTSecret stores server jwt secret if needed

func StringDifference

func StringDifference(a, b []string) []string

StringDifference - returns the elements in `a` that aren't in `b`.

func StringSliceContains

func StringSliceContains(slice []string, item string) bool

StringSliceContains - sees if a string slice contains a string element

func SubscribeMetricExportIntervalReset added in v1.6.0

func SubscribeMetricExportIntervalReset(ctx context.Context) <-chan struct{}

SubscribeMetricExportIntervalReset returns a channel notified when the metric interval setting changes for ctx's tenant.

func SyncClearedExitNodeFields added in v1.7.0

func SyncClearedExitNodeFields(dst, src *models.Node)

SyncClearedExitNodeFields copies exit/relay fields after ClearExitNodeForDisconnect onto another node object that will be persisted (e.g. the disconnect update payload).

func SyncDevice added in v1.7.0

func SyncDevice(host *schema.Host) error

SyncDevice requests the host to pull latest config via MQ.

func Telemetry added in v0.99.0

func Telemetry(ctx context.Context) string

Telemetry - checks if telemetry data should be sent

func TimerCheckpoint

func TimerCheckpoint() error

TimerCheckpoint - Checks if 24 hours has passed since telemetry was last sent. If so, sends telemetry data to posthog

func ToReturnUser

func ToReturnUser(user *schema.User) models.ReturnUser

ToReturnUser - gets a user as a return user

func ToUserEventLog added in v1.5.1

func ToUserEventLog(ctx context.Context, user *schema.User) models.UserEventLog

ToUserEventLog - converts a user to an event log entry with resolved group/role names

func ToggleExtClientConnectivity

func ToggleExtClientConnectivity(ctx context.Context, client *models.ExtClient, enable bool) (models.ExtClient, error)

ToggleExtClientConnectivity - enables or disables an ext client

func Tokenize

func Tokenize(ctx context.Context, k *schema.EnrollmentKey, serverAddr string) error

Tokenize - tokenizes an enrollment key to be used via registration and attaches it to the Token field on the struct

func TransferDeviceHostOwnership added in v1.7.0

func TransferDeviceHostOwnership(ctx context.Context, host *schema.Host, newOwner string) error

TransferDeviceHostOwnership re-binds a shared desktop host to a new user, cleaning up the prior owner's network state. RegisterDevice does not call this; any API that exposes transfer must enforce admin authorization.

func TryToUseEnrollmentKey

func TryToUseEnrollmentKey(ctx context.Context, k *schema.EnrollmentKey) bool

TryToUseEnrollmentKey - checks first if key can be decremented returns true if it is decremented or isvalid

func UniqueAclPolicyTags added in v0.99.0

func UniqueAclPolicyTags(tags []models.AclPolicyTag) []models.AclPolicyTag

func UniqueIPNetList added in v0.90.0

func UniqueIPNetList(ipnets []net.IPNet) []net.IPNet

func UniqueIPNetStrList added in v0.99.0

func UniqueIPNetStrList(ipnets []string) []string

UniqueIPNetList deduplicates and sorts a list of CIDR strings.

func UniquePolicies added in v0.99.0

func UniquePolicies(items []models.Acl) []models.Acl

func UniqueStrings added in v1.0.0

func UniqueStrings(input []string) []string

func UnlinkNetworkAndTagsFromEnrollmentKeys added in v0.90.0

func UnlinkNetworkAndTagsFromEnrollmentKeys(ctx context.Context, network string, delete bool) error

func UnsetInternetGw added in v0.23.0

func UnsetInternetGw(ctx context.Context, node *models.Node)

func UpdateAcl added in v0.26.0

func UpdateAcl(ctx context.Context, newAcl, acl models.Acl) error

UpdateAcl - updates allowed fields on acls and commits to DB

func UpdateEnrollmentKey added in v0.21.2

func UpdateEnrollmentKey(ctx context.Context, keyValue string, updates *models.APIEnrollmentKey) (*schema.EnrollmentKey, error)

UpdateEnrollmentKey - updates an existing enrollment key's relay and groups

func UpdateExtClient

func UpdateExtClient(old *models.ExtClient, update *models.CustomExtClient) models.ExtClient

UpdateExtClient - updates an ext client with new values

func UpdateHost

func UpdateHost(ctx context.Context, newHost, currentHost *schema.Host)

UpdateHost - updates host data by field

func UpdateHostFromClient

func UpdateHostFromClient(ctx context.Context, newHost, currHost *schema.Host) (isEndpointChanged, sendPeerUpdate bool)

UpdateHostFromClient - used for updating host on server with update recieved from client

func UpdateHostNetwork

func UpdateHostNetwork(h *schema.Host, network string, add bool) (*models.Node, error)

UpdateHostNetwork - adds/deletes host from a network

func UpdateHostNode added in v1.2.0

func UpdateHostNode(ctx context.Context, h *schema.Host, newNode *models.Node) (publishDeletedNodeUpdate, publishPeerUpdate bool, displacedGwNodes []models.Node)

UpdateHostNode - handles updates from client nodes

func UpdateNetwork

func UpdateNetwork(ctx context.Context, currentNetwork, newNetwork *schema.Network) error

UpdateNetwork - updates a network with another network's fields

func UpdateNode

func UpdateNode(currentNode *models.Node, newNode *models.Node) error

UpdateNode - takes a node and updates another node with it's values

func UpdateNodeCheckin

func UpdateNodeCheckin(nodeID string) error

UpdateNodeCheckin - buffers the checkin timestamp in memory when caching is enabled. The actual DB write is deferred to FlushNodeCheckins (every 30s). When caching is disabled (HA mode), writes directly to the DB.

func UpdateRelayNodes added in v1.2.0

func UpdateRelayNodes(relay string, oldNodes []string, newNodes []string) []models.Node

UpdateRelayNodes - updates relay nodes

func UpdateRelayed

func UpdateRelayed(ctx context.Context, currentNode, newNode *models.Node)

UpdateRelayed - updates a relay's relayed nodes, and sends updates to the relayed nodes over MQ

func UpdateUser

func UpdateUser(ctx context.Context, userchange, _user *schema.User) (*schema.User, error)

UpdateUser - updates a given user

func UpsertAcl added in v0.26.0

func UpsertAcl(ctx context.Context, acl models.Acl) error

UpsertAcl - upserts acl

func UpsertNode

func UpsertNode(newNode *models.Node) error

UpsertNode - updates node in the DB

func UpsertServerSettings added in v0.99.0

func UpsertServerSettings(ctx context.Context, s models.ServerSettings) error

func UpsertUser

func UpsertUser(_user schema.User) error

UpsertUser - updates user in the db

func UpsertUserSettings added in v1.1.0

func UpsertUserSettings(username string, userSettings models.UserSettings) error

func UserHasAccessToNetwork added in v1.7.0

func UserHasAccessToNetwork(ctx context.Context, user *schema.User, network string) bool

UserHasAccessToNetwork reports whether the given user (with membership fields already loaded) may access/join the network. Prefer this when the caller already fetched the user under the correct tenant scope.

func ValidateAndApproveUserInvite added in v0.25.0

func ValidateAndApproveUserInvite(ctx context.Context, email, code string) error

func ValidateCreateAclReq added in v0.26.0

func ValidateCreateAclReq(ctx context.Context, req models.Acl) error

ValidateCreateAclReq - validates create req for acl

func ValidateDNSCreate

func ValidateDNSCreate(ctx context.Context, entry models.DNSEntry) error

ValidateDNSCreate - checks if an entry is valid

func ValidateDNSUpdate

func ValidateDNSUpdate(ctx context.Context, change models.DNSEntry, entry models.DNSEntry) error

ValidateDNSUpdate - validates a DNS update

func ValidateDomain added in v0.99.0

func ValidateDomain(domain string) bool

func ValidateEgressAppNATMode added in v1.6.0

func ValidateEgressAppNATMode(e schema.Egress) error

ValidateEgressAppNATMode rejects virtual NAT for preset-based egress apps.

func ValidateEgressCIDR added in v1.6.0

func ValidateEgressCIDR(network *schema.Network, cidr string) error

ValidateEgressCIDR rejects egress ranges that overlap the Netmaker network or loopback space. Empty range and "*" are allowed (domain-only / inet gw).

func ValidateEgressGateway

func ValidateEgressGateway(gateway models.EgressGatewayRequest) error

ValidateEgressGateway - validates the egress gateway model

func ValidateEgressProOnlyFeatures added in v1.6.0

func ValidateEgressProOnlyFeatures(e schema.Egress) error

ValidateEgressProOnlyFeatures rejects domain and app egress on Community Edition.

func ValidateEgressRange added in v0.24.3

func ValidateEgressRange(ctx context.Context, netID string, ranges []string) error

func ValidateEgressReqProLimits added in v1.6.0

func ValidateEgressReqProLimits(req *models.EgressReq) error

ValidateEgressReqProLimits rejects domain/app fields on the API request before CE builds an egress.

func ValidateInetGwReq added in v1.0.0

func ValidateInetGwReq(ctx context.Context, node *schema.Node, req models.InetNodeReq, update bool) error

func ValidateInternetEgressRoutingNode added in v1.7.0

func ValidateInternetEgressRoutingNode(node *models.Node) error

ValidateInternetEgressRoutingNode ensures a routing node can act as an internet exit node.

func ValidateNetwork

func ValidateNetwork(ctx context.Context, network *schema.Network, isUpdate bool) error

Validate - validates fields of an network struct

func ValidateNewSettings added in v0.99.0

func ValidateNewSettings(ctx context.Context, req models.ServerSettings) error

func ValidateParams added in v0.23.0

func ValidateParams(nodeid, netid string) (models.Node, error)

func ValidateRelay added in v0.24.0

func ValidateRelay(ctx context.Context, relay models.RelayRequest, update bool) error

ValidateRelay - checks if relay is valid

func ValidateUser

func ValidateUser(user *schema.User) error

ValidateUser - validates a user model

func VerifyAuthRequest

func VerifyAuthRequest(ctx context.Context, authRequest models.UserAuthParams, appName string) (string, error)

VerifyAuthRequest - verifies an auth request

func VerifyDeviceHostAccess added in v1.7.0

func VerifyDeviceHostAccess(ctx context.Context, username, hostIDStr string) (*schema.Host, error)

VerifyDeviceHostAccess ensures the user may operate on the given host ID.

func VerifyHostToken

func VerifyHostToken(ctx context.Context, tokenString string) (hostID string, mac string, network string, err error)

VerifyHostToken - [hosts] Only

func VerifyOTPAuthURL added in v1.0.0

func VerifyOTPAuthURL(url, signature string) bool

func VerifyUserToken

func VerifyUserToken(ctx context.Context, tokenString string) (username string, issuperadmin, isadmin bool, err error)

VerifyUserToken func will used to Verify the JWT Token while using APIS

func VersionLessThan added in v0.30.0

func VersionLessThan(v1, v2 string) (bool, error)

VersionLessThan checks if v1 < v2 semantically dev is the latest version

func WrapHook added in v1.4.0

func WrapHook(hook func() error) models.HookFunc

WrapHook - wraps a parameterless hook function to be compatible with HookFunc This allows backward compatibility with existing hooks that don't accept parameters

Types

type ApiErrorType added in v0.99.0

type ApiErrorType string
const (
	Internal     ApiErrorType = "internal"
	BadReq       ApiErrorType = "badrequest"
	NotFound     ApiErrorType = "notfound"
	UnAuthorized ApiErrorType = "unauthorized"
	Forbidden    ApiErrorType = "forbidden"
)

type CleanupUserRefsFunc added in v1.7.0

type CleanupUserRefsFunc func(ctx context.Context, username string, forceDeleteConfigs bool)

type GlobalNs added in v1.1.0

type GlobalNs struct {
	ID  string   `json:"id"`
	IPs []string `json:"ips"`
}

type MetricsMonitor added in v1.2.0

type MetricsMonitor struct {
	// contains filtered or unexported fields
}

func GetMetricsMonitor added in v1.2.0

func GetMetricsMonitor(ctx context.Context) *MetricsMonitor

func (*MetricsMonitor) Start added in v1.2.0

func (m *MetricsMonitor) Start()

func (*MetricsMonitor) Stop added in v1.2.0

func (m *MetricsMonitor) Stop()

type OSInfo added in v1.4.0

type OSInfo struct {
	OS            string `json:"os"`             // e.g. "ubuntu", "windows", "macos"
	OSFamily      string `json:"os_family"`      // e.g. "linux-debian", "windows"
	OSVersion     string `json:"os_version"`     // e.g. "22.04", "10.0.22631"
	KernelVersion string `json:"kernel_version"` // e.g. "6.8.0"
}

func GetOSInfo added in v1.4.0

func GetOSInfo() OSInfo

GetOSInfo returns OS, OSFamily, OSVersion and KernelVersion for the current platform.

type ServerSyncType added in v1.5.1

type ServerSyncType string
const (
	SyncTypeSettings   ServerSyncType = "settings"
	SyncTypePeerUpdate ServerSyncType = "peer_update"
	SyncTypeIDPSync    ServerSyncType = "idp_sync"
	SyncTypeIDPReset   ServerSyncType = "idp_reset"
)

Directories

Path Synopsis
pro

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL