Documentation
¶
Index ¶
- Constants
- Variables
- func TokenPeerName(pubkey string) string
- type Config
- type GatewayError
- type IPNet
- type PrivateKey
- type PublicKey
- type RebuildError
- type States
- type TokenAuth
- type TokenProvision
- type Tunnel
- func (t *Tunnel) Close() error
- func (t *Tunnel) DialContext(ctx context.Context, network, addr string) (net.Conn, error)
- func (t *Tunnel) Done() <-chan struct{}
- func (t *Tunnel) Ephemeral() bool
- func (t *Tunnel) Err() error
- func (t *Tunnel) ListenPing() (*netstack.PingConn, error)
- func (t *Tunnel) LookupAAAA(ctx context.Context, name string) ([]net.IP, error)
- func (t *Tunnel) LookupTXT(ctx context.Context, name string) ([]string, error)
- func (t *Tunnel) Provision() *TokenProvision
- func (t *Tunnel) Resolver() *net.Resolver
- func (t *Tunnel) StateAndConfig() (*WireGuardState, *Config)
- type WireGuardState
- type WsWgProxy
- Bugs
Constants ¶
const ( // Gateway error codes. "unauthorized" and "invalid_request" won't be // fixed by reconnecting with the same credentials; "transient" might. GatewayErrInvalidRequest = "invalid_request" GatewayErrTransient = "transient" )
const DefaultTokenGateway = "gateway.machines.dev"
Variables ¶
var ( // ErrNoHello means the gateway never started the token exchange, // which is what a legacy (non-token) gateway looks like. ErrNoHello = errors.New("no token-mode hello from gateway") // ErrNoToken means there was no macaroon to present. ErrNoToken = errors.New("no macaroon token to present to the gateway") // ErrMalformedReply means the gateway's answer didn't parse as a usable // provision (bad key or address); a protocol problem, not a network one. ErrMalformedReply = errors.New("malformed reply from gateway") )
Functions ¶
func TokenPeerName ¶ added in v0.4.109
TokenPeerName mirrors the name wggwd gives an inline-provisioned peer ("token-" + the first four key bytes in hex), so logs on both sides agree.
Types ¶
type Config ¶
type Config struct {
LocalPrivateKey PrivateKey `toml:"local_private_key"`
LocalNetwork *IPNet `toml:"local_network"`
RemotePublicKey PublicKey `toml:"remote_public_key"`
RemoteNetwork *IPNet `toml:"remote_network"`
Endpoint string `toml:"endpoint"`
DNS net.IP `toml:"dns"`
KeepAlive int `toml:"keepalive"`
MTU int `toml:"mtu"`
LogLevel int `toml:"log_level"`
}
type GatewayError ¶ added in v0.4.109
GatewayError is a rejection from the gateway.
func (*GatewayError) Error ¶ added in v0.4.109
func (e *GatewayError) Error() string
func (*GatewayError) Permanent ¶ added in v0.4.109
func (e *GatewayError) Permanent() bool
Permanent reports whether reconnecting with the same credentials is pointless: the token was rejected or the request itself is invalid.
type PrivateKey ¶
type PrivateKey device.NoisePrivateKey
func (PrivateKey) MarshalText ¶
func (pk PrivateKey) MarshalText() ([]byte, error)
func (PrivateKey) ToHex ¶
func (pk PrivateKey) ToHex() string
func (*PrivateKey) UnmarshalText ¶
func (pk *PrivateKey) UnmarshalText(text []byte) error
type PublicKey ¶
type PublicKey device.NoisePublicKey
func (PublicKey) MarshalText ¶
func (*PublicKey) UnmarshalText ¶
type RebuildError ¶ added in v0.4.109
RebuildError is why a token-mode tunnel died when the WireGuard device couldn't be rebuilt around a re-provisioned peer. It's a client-side failure, unlike the gateway rejections that otherwise kill tunnels.
func (*RebuildError) Error ¶ added in v0.4.109
func (e *RebuildError) Error() string
func (*RebuildError) Unwrap ¶ added in v0.4.109
func (e *RebuildError) Unwrap() error
type States ¶ added in v0.2.32
type States map[string]*WireGuardState
type TokenAuth ¶ added in v0.4.109
type TokenAuth struct {
// Token returns the macaroon header to present. It's called on every
// (re-)connection so that refreshed tokens are picked up.
Token func() string
Pubkey string
OrgSlug string
NetworkName string
}
TokenAuth is what the client presents to the gateway: a macaroon token header plus the peer it wants provisioned.
type TokenProvision ¶ added in v0.4.109
type TokenProvision struct {
GatewayPubkey string
PeerIP string
DNS string
ExpiresAt time.Time
// contains filtered or unexported fields
}
TokenProvision is the gateway's answer: the peer address it allocated (and the gateway public key it announced in its hello packet).
type Tunnel ¶
type Tunnel struct {
State *WireGuardState
Config *Config
// contains filtered or unexported fields
}
func ConnectToken ¶ added in v0.4.109
func ConnectToken(ctx context.Context, state *WireGuardState, endpoint string, auth *TokenAuth) (*Tunnel, error)
ConnectToken establishes a WireGuard tunnel to a token-provisioning gateway. There's no pre-existing peer: the state's keys plus the auth packet are presented over the websocket and the gateway allocates our address inline. The state's Peer and DNS are filled in from the gateway's answer (and updated again if an anycast reconnect re-provisions us).
func (*Tunnel) DialContext ¶
func (*Tunnel) Done ¶ added in v0.4.109
func (t *Tunnel) Done() <-chan struct{}
Done is closed once the tunnel is closed, or, for token-mode tunnels, once the gateway has rejected it for good; Err says which.
func (*Tunnel) Ephemeral ¶ added in v0.4.109
Ephemeral reports whether the peer was provisioned inline by a token-mode gateway (and so isn't registered with the API or in the config file).
func (*Tunnel) Err ¶ added in v0.4.109
Err returns why the tunnel died, or nil if it was closed by its owner.
func (*Tunnel) LookupAAAA ¶
func (*Tunnel) Provision ¶ added in v0.4.109
func (t *Tunnel) Provision() *TokenProvision
Provision returns what the token gateway last allocated to us (the expiry moves every time the token is re-presented), or nil for legacy tunnels.
func (*Tunnel) StateAndConfig ¶ added in v0.4.109
func (t *Tunnel) StateAndConfig() (*WireGuardState, *Config)
StateAndConfig returns the tunnel's current WireGuard state and config. Token-mode tunnels may change these on reconnect.
type WireGuardState ¶
type WireGuardState struct {
Org string `json:"org"`
Name string `json:"name"`
Region string `json:"region"`
LocalPublic string `json:"localprivate"`
LocalPrivate string `json:"localpublic"`
DNS string `json:"dns"`
Peer fly.CreatedWireGuardPeer `json:"peer"`
}
func (*WireGuardState) TunnelConfig ¶
func (s *WireGuardState) TunnelConfig() *Config
BUG(tqbf): Obviously all this needs to go, and I should just make my code conform to the marshal/unmarshal protocol wireguard-go uses, but in the service of landing this feature, I'm just going to apply a layer of spackle for now.
Notes ¶
Bugs ¶
Obviously all this needs to go, and I should just make my code conform to the marshal/unmarshal protocol wireguard-go uses, but in the service of landing this feature, I'm just going to apply a layer of spackle for now.
for now, we never manage tunnels for different organizations, and while this comment is eating more space than the code I'd need to do this right, it's more fun to type, so we just hardcode.
I think this dance just because these needed to parse for Ben's TOML code.