wg

package
v0.4.109 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 32 Imported by: 0

Documentation

Index

Constants

View Source
const (

	// Gateway error codes. "unauthorized" and "invalid_request" won't be
	// fixed by reconnecting with the same credentials; "transient" might.
	GatewayErrUnauthorized   = "unauthorized"
	GatewayErrInvalidRequest = "invalid_request"
	GatewayErrTransient      = "transient"
)
View Source
const DefaultTokenGateway = "gateway.machines.dev"

Variables

View Source
var (
	// ErrNoHello means the gateway never started the token exchange,
	// which is what a legacy (non-token) gateway looks like.
	ErrNoHello = errors.New("no token-mode hello from gateway")

	// ErrNoToken means there was no macaroon to present.
	ErrNoToken = errors.New("no macaroon token to present to the gateway")

	// ErrMalformedReply means the gateway's answer didn't parse as a usable
	// provision (bad key or address); a protocol problem, not a network one.
	ErrMalformedReply = errors.New("malformed reply from gateway")
)

Functions

func TokenPeerName added in v0.4.109

func TokenPeerName(pubkey string) string

TokenPeerName mirrors the name wggwd gives an inline-provisioned peer ("token-" + the first four key bytes in hex), so logs on both sides agree.

Types

type Config

type Config struct {
	LocalPrivateKey PrivateKey `toml:"local_private_key"`
	LocalNetwork    *IPNet     `toml:"local_network"`

	RemotePublicKey PublicKey `toml:"remote_public_key"`
	RemoteNetwork   *IPNet    `toml:"remote_network"`

	Endpoint  string `toml:"endpoint"`
	DNS       net.IP `toml:"dns"`
	KeepAlive int    `toml:"keepalive"`
	MTU       int    `toml:"mtu"`
	LogLevel  int    `toml:"log_level"`
}

type GatewayError added in v0.4.109

type GatewayError struct {
	Code    string
	Message string
}

GatewayError is a rejection from the gateway.

func (*GatewayError) Error added in v0.4.109

func (e *GatewayError) Error() string

func (*GatewayError) Permanent added in v0.4.109

func (e *GatewayError) Permanent() bool

Permanent reports whether reconnecting with the same credentials is pointless: the token was rejected or the request itself is invalid.

type IPNet

type IPNet net.IPNet

func (*IPNet) MarshalText

func (n *IPNet) MarshalText() ([]byte, error)

func (*IPNet) String

func (n *IPNet) String() string

func (*IPNet) UnmarshalText

func (n *IPNet) UnmarshalText(text []byte) error

type PrivateKey

type PrivateKey device.NoisePrivateKey

func (PrivateKey) MarshalText

func (pk PrivateKey) MarshalText() ([]byte, error)

func (PrivateKey) ToHex

func (pk PrivateKey) ToHex() string

func (*PrivateKey) UnmarshalText

func (pk *PrivateKey) UnmarshalText(text []byte) error

type PublicKey

type PublicKey device.NoisePublicKey

func (PublicKey) MarshalText

func (pk PublicKey) MarshalText() ([]byte, error)

func (PublicKey) ToHex

func (pk PublicKey) ToHex() string

func (*PublicKey) UnmarshalText

func (pk *PublicKey) UnmarshalText(text []byte) error

type RebuildError added in v0.4.109

type RebuildError struct {
	PeerIP string
	Err    error
}

RebuildError is why a token-mode tunnel died when the WireGuard device couldn't be rebuilt around a re-provisioned peer. It's a client-side failure, unlike the gateway rejections that otherwise kill tunnels.

func (*RebuildError) Error added in v0.4.109

func (e *RebuildError) Error() string

func (*RebuildError) Unwrap added in v0.4.109

func (e *RebuildError) Unwrap() error

type States added in v0.2.32

type States map[string]*WireGuardState

type TokenAuth added in v0.4.109

type TokenAuth struct {
	// Token returns the macaroon header to present. It's called on every
	// (re-)connection so that refreshed tokens are picked up.
	Token       func() string
	Pubkey      string
	OrgSlug     string
	NetworkName string
}

TokenAuth is what the client presents to the gateway: a macaroon token header plus the peer it wants provisioned.

type TokenProvision added in v0.4.109

type TokenProvision struct {
	GatewayPubkey string
	PeerIP        string
	DNS           string
	ExpiresAt     time.Time
	// contains filtered or unexported fields
}

TokenProvision is the gateway's answer: the peer address it allocated (and the gateway public key it announced in its hello packet).

type Tunnel

type Tunnel struct {
	State  *WireGuardState
	Config *Config
	// contains filtered or unexported fields
}

func Connect

func Connect(ctx context.Context, state *WireGuardState) (*Tunnel, error)

func ConnectToken added in v0.4.109

func ConnectToken(ctx context.Context, state *WireGuardState, endpoint string, auth *TokenAuth) (*Tunnel, error)

ConnectToken establishes a WireGuard tunnel to a token-provisioning gateway. There's no pre-existing peer: the state's keys plus the auth packet are presented over the websocket and the gateway allocates our address inline. The state's Peer and DNS are filled in from the gateway's answer (and updated again if an anycast reconnect re-provisions us).

func ConnectWS

func ConnectWS(ctx context.Context, state *WireGuardState) (*Tunnel, error)

func (*Tunnel) Close

func (t *Tunnel) Close() error

func (*Tunnel) DialContext

func (t *Tunnel) DialContext(ctx context.Context, network, addr string) (net.Conn, error)

func (*Tunnel) Done added in v0.4.109

func (t *Tunnel) Done() <-chan struct{}

Done is closed once the tunnel is closed, or, for token-mode tunnels, once the gateway has rejected it for good; Err says which.

func (*Tunnel) Ephemeral added in v0.4.109

func (t *Tunnel) Ephemeral() bool

Ephemeral reports whether the peer was provisioned inline by a token-mode gateway (and so isn't registered with the API or in the config file).

func (*Tunnel) Err added in v0.4.109

func (t *Tunnel) Err() error

Err returns why the tunnel died, or nil if it was closed by its owner.

func (*Tunnel) ListenPing

func (t *Tunnel) ListenPing() (*netstack.PingConn, error)

func (*Tunnel) LookupAAAA

func (t *Tunnel) LookupAAAA(ctx context.Context, name string) ([]net.IP, error)

func (*Tunnel) LookupTXT

func (t *Tunnel) LookupTXT(ctx context.Context, name string) ([]string, error)

func (*Tunnel) Provision added in v0.4.109

func (t *Tunnel) Provision() *TokenProvision

Provision returns what the token gateway last allocated to us (the expiry moves every time the token is re-presented), or nil for legacy tunnels.

func (*Tunnel) Resolver

func (t *Tunnel) Resolver() *net.Resolver

func (*Tunnel) StateAndConfig added in v0.4.109

func (t *Tunnel) StateAndConfig() (*WireGuardState, *Config)

StateAndConfig returns the tunnel's current WireGuard state and config. Token-mode tunnels may change these on reconnect.

type WireGuardState

type WireGuardState struct {
	Org          string                   `json:"org"`
	Name         string                   `json:"name"`
	Region       string                   `json:"region"`
	LocalPublic  string                   `json:"localprivate"`
	LocalPrivate string                   `json:"localpublic"`
	DNS          string                   `json:"dns"`
	Peer         fly.CreatedWireGuardPeer `json:"peer"`
}

func (*WireGuardState) TunnelConfig

func (s *WireGuardState) TunnelConfig() *Config

BUG(tqbf): Obviously all this needs to go, and I should just make my code conform to the marshal/unmarshal protocol wireguard-go uses, but in the service of landing this feature, I'm just going to apply a layer of spackle for now.

type WsWgProxy

type WsWgProxy struct {
	// contains filtered or unexported fields
}

func NewWsWgProxy

func NewWsWgProxy() (*WsWgProxy, error)

func (*WsWgProxy) Connect

func (wswg *WsWgProxy) Connect(dialCtx, lifetimeCtx context.Context, endpoint string) error

func (*WsWgProxy) Port

func (wswg *WsWgProxy) Port() (int, error)

Notes

Bugs

  • Obviously all this needs to go, and I should just make my code conform to the marshal/unmarshal protocol wireguard-go uses, but in the service of landing this feature, I'm just going to apply a layer of spackle for now.

  • for now, we never manage tunnels for different organizations, and while this comment is eating more space than the code I'd need to do this right, it's more fun to type, so we just hardcode.

  • I think this dance just because these needed to parse for Ben's TOML code.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL