agent

package
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: MIT Imports: 34 Imported by: 0

Documentation

Overview

Package agent は自宅側のエージェント(仕様 7 節)。 認証情報ファイルの鍵と最後の全体状態でトンネルとリスナーを先に立て、その後 stream に繋いで全体状態を受け取る。

Index

Constants

This section is empty.

Variables

View Source
var ErrPinMismatch = errors.New("server certificate does not match the pinned hash")

ErrPinMismatch はサーバ証明書がピンと一致しない。teardown --purge のあとに立て直したサーバか、経路上の 第三者による TLS の終端で起きる。復帰は未使用の WGFT_JOIN による再登録(仕様 5.1 節)。

View Source
var ErrRegisterRejected = errors.New("registration rejected: join string already used or expired, or the name differs")

ErrRegisterRejected は登録が認証で拒否された(トークンが無効、名前違い)。

Functions

func ControlPath

func ControlPath(path string) string

ControlPath は認証情報ファイルに対応する制御ソケットの場所。

func PinnedClient

func PinnedClient(pin [32]byte) *http.Client

PinnedClient は証明書の SHA-256 がピンと一致するときだけ通す HTTP クライアント。 通常の検証(CA、ホスト名、期限)は使わない。IP 直打ちでも DNS 名でも同じ接続文字列が使える。

func PublicKey

func PublicKey(path string) (wgtypes.Key, error)

PublicKey は認証情報ファイルの鍵(なければ生成して保存)の公開鍵を返す。

func Register

func Register(ctx context.Context, j *Join, name string) (permanentToken, address, confirmedName string, err error)

Register は登録 API を呼び、恒久トークン、割り当てアドレス、確定した名前を返す。 name は任意(空なら送らない側に倣ってトークンに紐付いた名前で登録される)。

func RotateKey

func RotateKey(path string) (string, error)

RotateKey は CLI から呼ぶ。稼働中なら制御ソケット経由で、停止中なら認証情報ファイルの鍵と last_state を直接消す。

func Run

func Run(opts Options) error

Run は認証情報ファイルを読み、登録を確かめ、トンネルとリスナーを立て、stream に繋ぎ、シグナルまで動く。

Types

type Join

type Join struct {
	Endpoint string // host:port(エージェント用 API)
	Token    string // 1 回限りの登録トークン
	Pin      [32]byte
	// contains filtered or unexported fields
}

Join は接続文字列 wgft://host:port/token#sha256:<hex> の中身(仕様 5.1 節)。

func ParseJoin

func ParseJoin(s string) (*Join, error)

ParseJoin は接続文字列を解釈する。scheme、ポート、sha256 のピンをすべて要求する。

func (*Join) TokenHash

func (j *Join) TokenHash() string

TokenHash は使用済みトークンの記録用(仕様 5.1 節の復帰経路で比較する)。

type Options

type Options struct {
	// AllowTargets は接続してよい宛先の許可一覧(仕様 7 節、WGFT_AGENT_ALLOW_TARGETS)。
	// nil なら制限せず、vpsd が配るどの宛先へも接続する
	AllowTargets    *allowtargets.List
	CredentialsPath string          // 認証情報ファイル
	Join            string          // 接続文字列(WGFT_JOIN か --join)。初回登録に使う
	Limits          resource.Limits // 同時フロー数のプロセス全体の予算(仕様 7 節)。ゼロ値は既定値
	Name            string          // エージェント名(WGFT_NAME か --name)。任意。接続文字列の発行時の名前に紐付いているので、与えなければトークンに紐付いた名前で登録される
	Version         string          // 起動ログに出す wgft の版(cmd 側の effectiveVersion())。空なら "dev" として出す
}

Options は agent の起動オプション。

Directories

Path Synopsis
Package allowtargets は、エージェントが接続してよい宛先の一覧(設計文書 7 節)。
Package allowtargets は、エージェントが接続してよい宛先の一覧(設計文書 7 節)。
Package credentials はエージェントの認証情報ファイル(agent.json)を扱う(仕様 9 節)。
Package credentials はエージェントの認証情報ファイル(agent.json)を扱う(仕様 9 節)。

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL