Documentation
¶
Overview ¶
Package tslockjsonv1 provides types for unmarshaling the JSON output of the "tailscale lock --json=1" command:
- LogResponse will unmarshal the output of "tailscale lock log --json=1"
- StatusResponse will unmarshal the output of "tailscale lock status --json=1".
Index ¶
Examples ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AUM ¶
type AUM struct {
MessageKind string
PrevAUMHash string `json:",omitzero"`
// Key encodes a public key to be added to the key authority.
// This field is used for AddKey AUMs.
Key Key `json:",omitzero"`
// KeyID references a public key which is part of the key authority.
// This field is used for RemoveKey and UpdateKey AUMs.
KeyID string `json:",omitzero"`
// State describes the full state of the key authority.
// This field is used for Checkpoint AUMs.
State TKAState `json:",omitzero"`
// Votes and Meta describe properties of a key in the key authority.
// These fields are used for UpdateKey AUMs.
Votes uint `json:",omitzero"`
Meta map[string]string `json:",omitzero"`
// Signatures lists the signatures over this AUM.
Signatures []Signature `json:",omitzero"`
}
AUM is the expanded version of a [tka.AUM], designed so external tools can read the AUM without knowing our CBOR definitions.
type Key ¶
type Key struct {
Kind string `json:",omitzero"`
// Votes describes the weight applied to signatures using this key.
Votes uint
// Public encodes the public key of the key as a hex string.
Public string
// Meta describes arbitrary metadata about the key. This could be
// used to store the name of the key, for instance.
Meta map[string]string `json:",omitzero"`
}
Key is the expanded version of a [tka.Key], which describes the public components of a key known to tailnet-lock.
type LogMessage ¶
type LogMessage struct {
// The BLAKE2s digest of the CBOR-encoded [tka.AUM]. This is printed as a
// base32-encoded string, e.g. KCE…XZQ
Hash string
// The expanded form of the [tka.AUM], which presents the fields in a more
// accessible format than doing a CBOR decoding.
AUM AUM
// The raw bytes of the CBOR-encoded [tka.AUM], encoded as base64.
// This is useful for verifying the AUM hash.
Raw string
}
LogMessage is the JSON representation of a [tka.AUM] as both raw bytes and in its expanded form, and the CLI output is a list of these entries.
type LogResponse ¶
type LogResponse struct {
jsonoutput.ResponseEnvelope
Messages []LogMessage
}
LogResponse is the full Tailnet Lock log output collected from the local Tailscale daemon.
Example ¶
package main
import (
"encoding/json"
"errors"
"fmt"
"os"
"os/exec"
"tailscale.com/cmd/tailscale/tslockjsonv1"
)
func main() {
cmd := exec.Command("tailscale", "lock", "log", "--json")
out, err := cmd.Output()
if err != nil {
if err, ok := errors.AsType[*exec.ExitError](err); ok {
fmt.Fprintf(os.Stderr, "%s", err.Stderr)
}
panic(err)
}
var logs tslockjsonv1.LogResponse
if err := json.Unmarshal(out, &logs); err != nil {
panic(err)
}
for _, msg := range logs.Messages {
fmt.Printf("{kind: %s, key id: %s, key: %+v}\n", msg.AUM.MessageKind, msg.AUM.KeyID, msg.AUM.Key)
}
}
Output:
type NodeKeySignature ¶
type NodeKeySignature struct {
// SigKind identifies the variety of signature.
SigKind string
// PublicKey identifies the key.NodePublic which is being authorized.
// SigCredential signatures do not use this field.
PublicKey string `json:",omitzero"`
// KeyID identifies which key in the tailnet key authority should
// be used to verify this signature. Only set for SigDirect and
// SigCredential signature kinds.
KeyID string `json:",omitzero"`
// Signature is the packed (R, S) ed25519 signature over all other
// fields of the structure.
Signature string
// Nested describes a NodeKeySignature which authorizes the node-key
// used as Pubkey. Only used for SigRotation signatures.
Nested *NodeKeySignature `json:",omitzero"`
// WrappingPubkey specifies the ed25519 public key which must be used
// to sign a Signature which embeds this one.
WrappingPublicKey string `json:",omitzero"`
}
NodeKeySignature is the JSON representation of a [tka.NodeKeySignature], which describes a signature that authorizes a specific node key.
type Peer ¶
type Peer struct {
// Stable ID, i.e. [tailscale.com/tailcfg.StableNodeID]
ID string
// DNS name
DNSName string
// Tailscale IP(s) assigned to this node
TailscaleIPs []string
// The node's public key
NodeKey string
}
Peer is the JSON representation of an [ipnstate.TKAPeer], which describes a peer and its Tailnet Lock details.
type Signature ¶
Signature is the expanded form of a [tka.Signature], which describes a signature over an AUM. This signature can be verified using the key referenced by KeyID.
type StatusResponse ¶
type StatusResponse struct {
jsonoutput.ResponseEnvelope
// Enabled is true if Tailnet Lock is enabled.
Enabled bool
// PublicKey describes the node's tailnet-lock public key.
PublicKey string `json:",omitzero"`
// NodeKey describes the node's current node-key. This field is not
// populated if the node is not operating (i.e. waiting for a login).
NodeKey string `json:",omitzero"`
// Head describes the AUM hash of the leaf AUM.
Head string `json:",omitzero"`
// NodeKeySigned is true if our node is authorized by Tailnet Lock.
NodeKeySigned *bool `json:",omitzero"`
// NodeKeySignature is the current signature of this node's key.
NodeKeySignature *NodeKeySignature `json:",omitzero"`
// TrustedKeys describes the keys currently trusted to make changes
// to tailnet-lock.
TrustedKeys []Key `json:",omitzero"`
// VisiblePeers describes peers which are visible in the netmap that
// have valid Tailnet Lock signatures.
VisiblePeers []TrustedPeer `json:",omitzero"`
// FilteredPeers describes peers which were removed from the netmap
// (i.e. no connectivity) because they failed Tailnet Lock
// checks.
FilteredPeers []Peer `json:",omitzero"`
// StateID is a nonce associated with the Tailnet Lock authority,
// generated upon enablement.
StateID uint64 `json:"State,omitzero"`
}
StatusResponse is the full Tailnet Lock Status output collected from the local Tailscale daemon.
Example ¶
package main
import (
"encoding/json"
"errors"
"fmt"
"os"
"os/exec"
"tailscale.com/cmd/tailscale/tslockjsonv1"
)
func main() {
cmd := exec.Command("tailscale", "lock", "status", "--json")
out, err := cmd.Output()
if err != nil {
if err, ok := errors.AsType[*exec.ExitError](err); ok {
fmt.Fprintf(os.Stderr, "%s", err.Stderr)
}
panic(err)
}
var status tslockjsonv1.StatusResponse
if err := json.Unmarshal(out, &status); err != nil {
panic(err)
}
fmt.Printf("{enabled: %t, public key: %s, node key: %s}\n", status.Enabled, status.PublicKey, status.NodeKey)
}
Output:
type TKAState ¶
type TKAState struct {
// LastAUMHash is the blake2s digest of the last-applied AUM.
LastAUMHash string `json:",omitzero"`
// DisablementValues are KDF-derived values used to verify that a caller
// possesses a valid DisablementSecret. These values are used during the
// Tailnet Lock deactivation process.
//
// These are safe to share publicly or store in the clear. They cannot be
// used to derive the original DisablementSecret.
DisablementValues []string
// Keys are the public keys of either:
//
// 1. The signing nodes currently trusted by the TKA.
// 2. Ephemeral keys that were used to generate pre-signed auth keys.
Keys []Key
// StateID's are nonces, generated on enablement and fixed for
// the lifetime of the Tailnet Key Authority.
StateID1 uint64
StateID2 uint64
}
TKAState is the expanded version of a [tka.TKAState], which describes Tailnet Key Authority state at an instant in time.
type TrustedPeer ¶
type TrustedPeer struct {
// Stable ID, i.e. [tailscale.com/tailcfg.StableNodeID]
ID string
// DNS name
DNSName string
// Tailscale IP(s) assigned to this node
TailscaleIPs []string
// The node's public key
NodeKey string
// The node's key signature
NodeKeySignature *NodeKeySignature `json:",omitzero"`
}
TrustedPeer is the JSON representation of a trusted [ipnstate.TKAPeer], which has a node key signature in addition to Peer.