agent

package
v0.4.109 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 43 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// SocketPathEnvKey names the environment variable that overrides the path
	// of the socket the agent listens on. StartDaemon exports it to the agent
	// subprocess it spawns so that both ends agree on the path.
	SocketPathEnvKey = "FLY_AGENT_SOCKET_PATH"

	// SocketDirEnvKey names the environment variable carrying the private
	// directory an isolated invocation created for its socket and lock
	// files. The agent subprocess removes it on shutdown.
	SocketDirEnvKey = "FLY_AGENT_SOCKET_DIR"

	// IsolatedEnvKey names the environment variable that, when truthy, makes
	// flyctl run its own agent as a subprocess on a randomly generated socket
	// path instead of sharing the background daemon with other invocations.
	// The isolated agent shuts down when the flyctl invocation that started
	// it exits.
	IsolatedEnvKey = "FLY_AGENT_ISOLATED"

	// TokenModeEnvKey names the environment variable that, when set,
	// overrides the wire_guard_token_mode config key: truthy values make
	// the agent provision WireGuard peers inline at the token gateway with
	// the session's macaroons instead of registering them through the API.
	TokenModeEnvKey = "FLY_WIREGUARD_TOKEN_MODE"

	// TokenGatewayEnvKey names the environment variable that overrides the
	// token gateway hostname (wg.DefaultTokenGateway), e.g. to point at a
	// staging gateway.
	TokenGatewayEnvKey = "FLY_WIREGUARD_GATEWAY"
)

Variables

View Source
var (
	ErrNoSuchHost        = errors.New("host was not found in DNS")
	ErrTunnelUnavailable = errors.New("tunnel unavailable")
)
View Source
var ErrAgentNotRunning = errors.New("agent not running")

Functions

func BringUpAgent added in v0.3.171

func BringUpAgent(ctx context.Context, client wireguard.WebClient, app *fly.AppCompact, network string, quiet bool) (*Client, Dialer, error)

func BringUpAgentOrgSlug added in v0.3.225

func BringUpAgentOrgSlug(ctx context.Context, client wireguard.WebClient, orgSlug string, network string, quiet bool) (*Client, Dialer, error)

func DialerWithContext added in v0.0.367

func DialerWithContext(ctx context.Context, dialer Dialer) context.Context

func Isolated added in v0.4.109

func Isolated() bool

Isolated reports whether this invocation runs its own agent subprocess on a private socket instead of sharing the background daemon.

func PathToSocket

func PathToSocket() string

PathToSocket returns the path of the socket the agent listens on: the value of FLY_AGENT_SOCKET_PATH if set, a randomly generated per-process path in isolated mode (exported via FLY_AGENT_SOCKET_PATH so subprocesses inherit it), or fly-agent.sock in the config directory.

func RemoveSocketDir added in v0.4.109

func RemoveSocketDir(dir string) error

RemoveSocketDir removes the private socket directory and the files we put in it: the socket and the agent's and the launcher's lock files. Nothing is removed recursively, so a directory we didn't create (an unexpected FLY_AGENT_SOCKET_DIR) that holds anything else is left alone, with an error saying so.

func SocketDirToRemove added in v0.4.109

func SocketDirToRemove() string

SocketDirToRemove returns the private socket directory this agent should remove on shutdown, or "" when the socket doesn't live in one.

func SocketPathOverride added in v0.4.109

func SocketPathOverride() string

SocketPathOverride returns the socket path when one is in effect, either explicitly via FLY_AGENT_SOCKET_PATH or generated in isolated mode, and the empty string when the default path applies.

func TokenModeEnabled added in v0.4.109

func TokenModeEnabled() bool

TokenModeEnabled reports whether the agent will build tunnels via the token gateway: the wire_guard_token_mode config key, overridden by FLY_WIREGUARD_TOKEN_MODE.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

func DefaultClient

func DefaultClient(ctx context.Context) (*Client, error)

func Dial

func Dial(ctx context.Context, network, addr string) (*Client, error)

func Establish

func Establish(ctx context.Context, apiClient wireguard.WebClient) (*Client, error)

Establish starts the daemon, if necessary, and returns a client to it.

func StartDaemon

func StartDaemon(ctx context.Context) (*Client, error)

func (*Client) ConnectToTunnel

func (c *Client) ConnectToTunnel(ctx context.Context, slug, network string, silent bool) (d Dialer, err error)

ConnectToTunnel is a convenience method for connect to a wireguard tunnel and returning a Dialer. Only suitable for use in the new CLI commands.

func (*Client) Dialer

func (c *Client) Dialer(ctx context.Context, slug, network string) (d Dialer, err error)

Dialer establishes a connection to the wireguard agent and return a dialier for use in subsequent actions, such as running ssh commands or opening proxies

func (*Client) Establish

func (c *Client) Establish(ctx context.Context, slug, network string) (res *EstablishResponse, err error)

func (*Client) Instances

func (c *Client) Instances(ctx context.Context, org, app string) (instances Instances, err error)

func (*Client) Kill

func (c *Client) Kill(ctx context.Context) error

func (*Client) LookupTxt added in v0.1.135

func (c *Client) LookupTxt(ctx context.Context, slug, host string) (records []string, err error)

func (*Client) Ping

func (c *Client) Ping(ctx context.Context) (res PingResponse, err error)

func (*Client) Pinger

func (c *Client) Pinger(ctx context.Context, slug, network string) (p *Pinger, err error)

Pinger creates a Pinger struct. It does this by first ensuring a WireGuard session exists for the specified org, and then opening an additional connection to the agent, which is upgraded to a Pinger connection by sending the "ping6" command. Call "Close" on a Pinger when you're done pinging things.

func (*Client) Probe

func (c *Client) Probe(ctx context.Context, slug, network string) error

func (*Client) Reestablish

func (c *Client) Reestablish(ctx context.Context, slug, network string) (res *EstablishResponse, err error)

func (*Client) Resolve

func (c *Client) Resolve(ctx context.Context, slug, host, network string) (addr string, err error)

func (*Client) WaitForDNS

func (c *Client) WaitForDNS(parent context.Context, dialer Dialer, slug, host, network string) (err error)

WaitForDNS waits for a Fly host internal DNS entry to register

func (*Client) WaitForTunnel

func (c *Client) WaitForTunnel(parent context.Context, slug, network string) (err error)

WaitForTunnel waits for a tunnel to the given org slug to become available in the next four minutes.

type Dialer

type Dialer interface {
	State() *wg.WireGuardState
	Config() *wg.Config
	DialContext(ctx context.Context, network, addr string) (net.Conn, error)
}

TODO: refactor to struct

func DialerFromContext added in v0.0.367

func DialerFromContext(ctx context.Context) Dialer

type EstablishResponse

type EstablishResponse struct {
	WireGuardState *wg.WireGuardState
	TunnelConfig   *wg.Config
}

type Instances

type Instances struct {
	Labels    []string
	Addresses []string
}

type PingResponse

type PingResponse struct {
	PID        int
	Version    string
	Background bool
	// TokenMode reports whether the agent provisions peers at the token
	// gateway; absent (false) from agents predating it.
	TokenMode bool
}

type Pinger

type Pinger struct {
	// contains filtered or unexported fields
}

Pinger wraps a connection to the flyctl agent over which ICMP requests and replies are written. There's a simple protocol for encapsulating requests and responses; drive it with the Pinger member functions. Pinger implements most of net.PacketConn but is not really intended as such.

func (*Pinger) Close

func (p *Pinger) Close() error

func (*Pinger) Err

func (p *Pinger) Err() error

Err returns any non-recoverable error seen on this Pinger connection; WriteTo and ReadFrom on a Pinger will not function if Err returns non-nil.

func (*Pinger) ReadFrom

func (p *Pinger) ReadFrom(buf []byte) (int64, net.Addr, error)

ReadFrom reads an ICMP message from a Pinger, using the same protocol as WriteTo. Call `SetReadDeadline` to poll this interface while watching channels or whatever.

func (*Pinger) SetReadDeadline

func (p *Pinger) SetReadDeadline(t time.Time) error

func (*Pinger) WriteTo

func (p *Pinger) WriteTo(buf []byte, addr net.Addr) (int64, error)

WriteTo writes an ICMP message, including headers, to the specified address. `addr` should always be an IPv6 net.IPAddr beginning with `fdaa` --- you cannot ping random hosts on the Internet with this interface. See golang/x/net/icmp for message construction details; this interface uses gVisor netstack, which is fussy about ICMP, and will only allow icmp.Echo messages with a code of 0.

Pinger runs a trivial protocol to encapsulate ICMP messages over agent connections: each message is a 16-byte IPv6 address, followed by an NBO u16 length, followed by the ICMP message bytes, which again must begin with an ICMP header. Checksums are performed by netstack; don't bother with them.

Directories

Path Synopsis
internal
proto
Package proto implements the agent's protocol.
Package proto implements the agent's protocol.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL