tslockjsonv1

package
v1.104.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: BSD-3-Clause Imports: 1 Imported by: 0

Documentation

Overview

Package tslockjsonv1 provides types for unmarshaling the JSON output of the "tailscale lock --json=1" command:

  • LogResponse will unmarshal the output of "tailscale lock log --json=1"
  • StatusResponse will unmarshal the output of "tailscale lock status --json=1".

Index

Examples

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type AUM

type AUM struct {
	MessageKind string
	PrevAUMHash string `json:",omitzero"`

	// Key encodes a public key to be added to the key authority.
	// This field is used for AddKey AUMs.
	Key Key `json:",omitzero"`

	// KeyID references a public key which is part of the key authority.
	// This field is used for RemoveKey and UpdateKey AUMs.
	KeyID string `json:",omitzero"`

	// State describes the full state of the key authority.
	// This field is used for Checkpoint AUMs.
	State TKAState `json:",omitzero"`

	// Votes and Meta describe properties of a key in the key authority.
	// These fields are used for UpdateKey AUMs.
	Votes uint              `json:",omitzero"`
	Meta  map[string]string `json:",omitzero"`

	// Signatures lists the signatures over this AUM.
	Signatures []Signature `json:",omitzero"`
}

AUM is the expanded version of a [tka.AUM], designed so external tools can read the AUM without knowing our CBOR definitions.

type Key

type Key struct {
	Kind string `json:",omitzero"`

	// Votes describes the weight applied to signatures using this key.
	Votes uint

	// Public encodes the public key of the key as a hex string.
	Public string

	// Meta describes arbitrary metadata about the key. This could be
	// used to store the name of the key, for instance.
	Meta map[string]string `json:",omitzero"`
}

Key is the expanded version of a [tka.Key], which describes the public components of a key known to tailnet-lock.

type LogMessage

type LogMessage struct {
	// The BLAKE2s digest of the CBOR-encoded [tka.AUM].  This is printed as a
	// base32-encoded string, e.g. KCE…XZQ
	Hash string

	// The expanded form of the [tka.AUM], which presents the fields in a more
	// accessible format than doing a CBOR decoding.
	AUM AUM

	// The raw bytes of the CBOR-encoded [tka.AUM], encoded as base64.
	// This is useful for verifying the AUM hash.
	Raw string
}

LogMessage is the JSON representation of a [tka.AUM] as both raw bytes and in its expanded form, and the CLI output is a list of these entries.

type LogResponse

type LogResponse struct {
	jsonoutput.ResponseEnvelope
	Messages []LogMessage
}

LogResponse is the full Tailnet Lock log output collected from the local Tailscale daemon.

Example
package main

import (
	"encoding/json"
	"errors"
	"fmt"
	"os"
	"os/exec"

	"tailscale.com/cmd/tailscale/tslockjsonv1"
)

func main() {
	cmd := exec.Command("tailscale", "lock", "log", "--json")
	out, err := cmd.Output()
	if err != nil {
		if err, ok := errors.AsType[*exec.ExitError](err); ok {
			fmt.Fprintf(os.Stderr, "%s", err.Stderr)
		}
		panic(err)
	}

	var logs tslockjsonv1.LogResponse
	if err := json.Unmarshal(out, &logs); err != nil {
		panic(err)
	}
	for _, msg := range logs.Messages {
		fmt.Printf("{kind: %s, key id: %s, key: %+v}\n", msg.AUM.MessageKind, msg.AUM.KeyID, msg.AUM.Key)
	}
}

type NodeKeySignature

type NodeKeySignature struct {
	// SigKind identifies the variety of signature.
	SigKind string

	// PublicKey identifies the key.NodePublic which is being authorized.
	// SigCredential signatures do not use this field.
	PublicKey string `json:",omitzero"`

	// KeyID identifies which key in the tailnet key authority should
	// be used to verify this signature. Only set for SigDirect and
	// SigCredential signature kinds.
	KeyID string `json:",omitzero"`

	// Signature is the packed (R, S) ed25519 signature over all other
	// fields of the structure.
	Signature string

	// Nested describes a NodeKeySignature which authorizes the node-key
	// used as Pubkey. Only used for SigRotation signatures.
	Nested *NodeKeySignature `json:",omitzero"`

	// WrappingPubkey specifies the ed25519 public key which must be used
	// to sign a Signature which embeds this one.
	WrappingPublicKey string `json:",omitzero"`
}

NodeKeySignature is the JSON representation of a [tka.NodeKeySignature], which describes a signature that authorizes a specific node key.

type Peer

type Peer struct {
	// Stable ID, i.e. [tailscale.com/tailcfg.StableNodeID]
	ID string

	// DNS name
	DNSName string

	// Tailscale IP(s) assigned to this node
	TailscaleIPs []string

	// The node's public key
	NodeKey string
}

Peer is the JSON representation of an [ipnstate.TKAPeer], which describes a peer and its Tailnet Lock details.

type Signature

type Signature struct {
	KeyID     string
	Signature string
}

Signature is the expanded form of a [tka.Signature], which describes a signature over an AUM. This signature can be verified using the key referenced by KeyID.

type StatusResponse

type StatusResponse struct {
	jsonoutput.ResponseEnvelope

	// Enabled is true if Tailnet Lock is enabled.
	Enabled bool

	// PublicKey describes the node's tailnet-lock public key.
	PublicKey string `json:",omitzero"`

	// NodeKey describes the node's current node-key. This field is not
	// populated if the node is not operating (i.e. waiting for a login).
	NodeKey string `json:",omitzero"`

	// Head describes the AUM hash of the leaf AUM.
	Head string `json:",omitzero"`

	// NodeKeySigned is true if our node is authorized by Tailnet Lock.
	NodeKeySigned *bool `json:",omitzero"`

	// NodeKeySignature is the current signature of this node's key.
	NodeKeySignature *NodeKeySignature `json:",omitzero"`

	// TrustedKeys describes the keys currently trusted to make changes
	// to tailnet-lock.
	TrustedKeys []Key `json:",omitzero"`

	// VisiblePeers describes peers which are visible in the netmap that
	// have valid Tailnet Lock signatures.
	VisiblePeers []TrustedPeer `json:",omitzero"`

	// FilteredPeers describes peers which were removed from the netmap
	// (i.e. no connectivity) because they failed Tailnet Lock
	// checks.
	FilteredPeers []Peer `json:",omitzero"`

	// StateID is a nonce associated with the Tailnet Lock authority,
	// generated upon enablement.
	StateID uint64 `json:"State,omitzero"`
}

StatusResponse is the full Tailnet Lock Status output collected from the local Tailscale daemon.

Example
package main

import (
	"encoding/json"
	"errors"
	"fmt"
	"os"
	"os/exec"

	"tailscale.com/cmd/tailscale/tslockjsonv1"
)

func main() {
	cmd := exec.Command("tailscale", "lock", "status", "--json")
	out, err := cmd.Output()
	if err != nil {
		if err, ok := errors.AsType[*exec.ExitError](err); ok {
			fmt.Fprintf(os.Stderr, "%s", err.Stderr)
		}
		panic(err)
	}

	var status tslockjsonv1.StatusResponse
	if err := json.Unmarshal(out, &status); err != nil {
		panic(err)
	}
	fmt.Printf("{enabled: %t, public key: %s, node key: %s}\n", status.Enabled, status.PublicKey, status.NodeKey)
}

type TKAState

type TKAState struct {
	// LastAUMHash is the blake2s digest of the last-applied AUM.
	LastAUMHash string `json:",omitzero"`

	// DisablementValues are KDF-derived values used to verify that a caller
	// possesses a valid DisablementSecret. These values are used during the
	// Tailnet Lock deactivation process.
	//
	// These are safe to share publicly or store in the clear. They cannot be
	// used to derive the original DisablementSecret.
	DisablementValues []string

	// Keys are the public keys of either:
	//
	//   1. The signing nodes currently trusted by the TKA.
	//   2. Ephemeral keys that were used to generate pre-signed auth keys.
	Keys []Key

	// StateID's are nonces, generated on enablement and fixed for
	// the lifetime of the Tailnet Key Authority.
	StateID1 uint64
	StateID2 uint64
}

TKAState is the expanded version of a [tka.TKAState], which describes Tailnet Key Authority state at an instant in time.

type TrustedPeer

type TrustedPeer struct {
	// Stable ID, i.e. [tailscale.com/tailcfg.StableNodeID]
	ID string

	// DNS name
	DNSName string

	// Tailscale IP(s) assigned to this node
	TailscaleIPs []string

	// The node's public key
	NodeKey string

	// The node's key signature
	NodeKeySignature *NodeKeySignature `json:",omitzero"`
}

TrustedPeer is the JSON representation of a trusted [ipnstate.TKAPeer], which has a node key signature in addition to Peer.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL