Documentation
¶
Overview ¶
Package tailscale provides a minimal control plane API client for internal use. A full client for 3rd party use is available at tailscale.com/client/tailscale/v2. The internal client is provided to avoid having to import that whole package.
Index ¶
- Constants
- Variables
- func HandleErrorResponse(b []byte, resp *http.Response) error
- func SendRequest(c *Client, req *http.Request) ([]byte, *http.Response, error)
- type APIKey
- type AuthMethod
- type Client
- func (client *Client) CreateOrUpdateVIPService(ctx context.Context, svc *VIPService) error
- func (client *Client) DeleteVIPService(ctx context.Context, name tailcfg.ServiceName) error
- func (client *Client) GetVIPService(ctx context.Context, name tailcfg.ServiceName) (*VIPService, error)
- func (client *Client) ListVIPServices(ctx context.Context) (*VIPServiceList, error)
- type Device
- type DeviceFieldsOpts
- type ErrResponse
- type ExchangeJWTForTokenWIFArgs
- type Key
- type KeyCapabilities
- type KeyDeviceCapabilities
- type KeyDeviceCreateCapabilities
- type ResolveAuthKeyArgs
- type ResolveAuthKeyWIFArgs
- type VIPService
- type VIPServiceList
Constants ¶
const ResolvePrefixAWSParameterStore = "arn:aws:ssm:"
ResolvePrefixAWSParameterStore is the string prefix for values that can be resolved from AWS Parameter Store.
Variables ¶
var HookExchangeJWTForTokenViaWIF feature.Hook[func(ctx context.Context, arg ExchangeJWTForTokenWIFArgs) (string, error)]
HookExchangeJWTForTokenViaWIF resolves to [identityfederation.exchangeJWTForToken] when the corresponding feature tag is enabled in the build process.
var HookResolveAuthKey feature.Hook[func(ctx context.Context, args ResolveAuthKeyArgs) (string, error)]
HookResolveAuthKey resolves to [oauthkey.ResolveAuthKey] when the corresponding feature tag is enabled in the build process.
var HookResolveAuthKeyViaWIF feature.Hook[func(ctx context.Context, args ResolveAuthKeyWIFArgs) (string, error)]
HookResolveAuthKeyViaWIF resolves to [identityfederation.resolveAuthKey] when the corresponding feature tag is enabled in the build process.
var HookResolveValueFromParameterStore feature.Hook[func(ctx context.Context, valueOrARN string) (string, error)]
HookResolveValueFromParameterStore resolves to [awsparamstore.ResolveValue] when the corresponding feature tag is enabled in the build process.
It fetches a value from AWS Parameter Store given an ARN. If the provided value is not an Parameter Store ARN, it returns the value unchanged.
Functions ¶
func HandleErrorResponse ¶
HandleErrorResponse is an alias to tailscale.com/client/tailscale.
Types ¶
type AuthMethod ¶
type AuthMethod = tsclient.AuthMethod
AuthMethod is an alias to tailscale.com/client/tailscale.
type Client ¶
Client is a wrapper of tailscale.com/client/tailscale.
func NewClient ¶
func NewClient(tailnet string, auth AuthMethod) *Client
NewClient is an alias to tailscale.com/client/tailscale.
func (*Client) CreateOrUpdateVIPService ¶
func (client *Client) CreateOrUpdateVIPService(ctx context.Context, svc *VIPService) error
CreateOrUpdateVIPService creates or updates a VIPService by its name. Caller must ensure that, if the VIPService already exists, the VIPService is fetched first to ensure that any auto-allocated IP addresses are not lost during the update. If the VIPService was created without any IP addresses explicitly set (so that they were auto-allocated by Tailscale) any subsequent request to this function that does not set any IP addresses will error.
func (*Client) DeleteVIPService ¶
DeleteVIPService deletes a VIPService by its name. It returns an error if the VIPService does not exist or if the deletion fails.
func (*Client) GetVIPService ¶
func (client *Client) GetVIPService(ctx context.Context, name tailcfg.ServiceName) (*VIPService, error)
GetVIPService retrieves a VIPService by its name. It returns 404 if the VIPService is not found.
func (*Client) ListVIPServices ¶ added in v1.86.0
func (client *Client) ListVIPServices(ctx context.Context) (*VIPServiceList, error)
ListVIPServices retrieves all existing Services and returns them as a list.
type DeviceFieldsOpts ¶
type DeviceFieldsOpts = tsclient.DeviceFieldsOpts
DeviceFieldsOpts is an alias to tailscale.com/client/tailscale.
type ErrResponse ¶
type ErrResponse = tsclient.ErrResponse
ErrResponse is an alias to tailscale.com/client/tailscale.
type ExchangeJWTForTokenWIFArgs ¶ added in v1.102.0
type KeyCapabilities ¶
type KeyCapabilities = tsclient.KeyCapabilities
KeyCapabilities is an alias to tailscale.com/client/tailscale.
type KeyDeviceCapabilities ¶
type KeyDeviceCapabilities = tsclient.KeyDeviceCapabilities
KeyDeviceCapabilities is an alias to tailscale.com/client/tailscale.
type KeyDeviceCreateCapabilities ¶
type KeyDeviceCreateCapabilities = tsclient.KeyDeviceCreateCapabilities
KeyDeviceCreateCapabilities is an alias to tailscale.com/client/tailscale.
type ResolveAuthKeyArgs ¶ added in v1.102.0
type ResolveAuthKeyArgs struct {
// Authkey is a standard device auth key or an OAuth client secret to resolve into an auth key.
AuthKey string
// Tags is the list of tags being advertised by the client (required to be provided for the
// OAuth secret case, and required to be the same as the list of tags for which the OAuth
// secret is allowed to issue auth keys).
Tags []string
}
type ResolveAuthKeyWIFArgs ¶ added in v1.102.0
type ResolveAuthKeyWIFArgs struct {
// BaseURL is the URL of the control server used for token exchange and authkey generation.
BaseURL string
// ClientID is the federated client ID used for token exchange.
ClientID string
// IDToken is the Identity token from the identity provider.
IDToken string
// Audience is the federated audience acquired by configuring the trust credential in the admin UI.
Audience string
// Tags is the list of tags to be associated with the auth key.
Tags []string
}
type VIPService ¶
type VIPService struct {
// Name is a VIPService name in form svc:<leftmost-label-of-service-DNS-name>.
Name tailcfg.ServiceName `json:"name,omitempty"`
// Addrs are the IP addresses of the VIP Service. There are two addresses:
// the first is IPv4 and the second is IPv6.
// When creating a new VIP Service, the IP addresses are optional: if no
// addresses are specified then they will be selected. If an IPv4 address is
// specified at index 0, then that address will attempt to be used. An IPv6
// address can not be specified upon creation.
Addrs []string `json:"addrs,omitempty"`
// Comment is an optional text string for display in the admin panel.
Comment string `json:"comment,omitempty"`
// Annotations are optional key-value pairs that can be used to store arbitrary metadata.
Annotations map[string]string `json:"annotations,omitempty"`
// Ports are the ports of a VIPService that will be configured via Tailscale serve config.
// If set, any node wishing to advertise this VIPService must have this port configured via Tailscale serve.
Ports []string `json:"ports,omitempty"`
// Tags are optional ACL tags that will be applied to the VIPService.
Tags []string `json:"tags,omitempty"`
}
VIPService is a Tailscale VIPService with Tailscale API JSON representation.
type VIPServiceList ¶ added in v1.86.0
type VIPServiceList struct {
VIPServices []VIPService `json:"vipServices"`
}
VIPServiceList represents the JSON response to the list VIP Services API.