Documentation
¶
Overview ¶
Package derpserver implements a DERP server.
Index ¶
- Constants
- Variables
- func AddWebSocketSupport(s *Server, base http.Handler) http.Handler
- func Handler(s *Server) http.Handler
- func ProbeHandler(w http.ResponseWriter, r *http.Request)
- func ServeNoContent(w http.ResponseWriter, r *http.Request)
- type BytesSentRecv
- type PacketForwarder
- type RateConfig
- type Server
- func (s *Server) Accept(ctx context.Context, nc derp.Conn, brw *bufio.ReadWriter, remoteAddr string)
- func (s *Server) AddPacketForwarder(dst key.NodePublic, fwd PacketForwarder)
- func (s *Server) Close() error
- func (s *Server) ConsistencyCheck() error
- func (s *Server) ExpVar(rateLimitEnabled bool) expvar.Var
- func (s *Server) ForTest() forTest
- func (s *Server) HasMeshKey() bool
- func (s *Server) IsClientConnectedForTest(k key.NodePublic) bool
- func (s *Server) LoadAndApplyRateConfig(path string) error
- func (s *Server) MeshKey() key.DERPMesh
- func (s *Server) MetaCert() []byte
- func (s *Server) ModifyTLSConfigToAddMetaCert(c *tls.Config)
- func (s *Server) PrivateKey() key.NodePrivate
- func (s *Server) PublicKey() key.NodePublic
- func (s *Server) RemovePacketForwarder(dst key.NodePublic, fwd PacketForwarder)
- func (s *Server) ServeDebugClients(w http.ResponseWriter, r *http.Request)
- func (s *Server) ServeDebugTraffic(w http.ResponseWriter, r *http.Request)
- func (s *Server) SetDisallowedAppNames(names []string)
- func (s *Server) SetMeshKey(v string) error
- func (s *Server) SetTCPWriteTimeout(d time.Duration)
- func (s *Server) SetTailscaledSocketPath(path string)
- func (s *Server) SetVerifyClient(v bool)
- func (s *Server) SetVerifyClientURL(v string)
- func (s *Server) SetVerifyClientURLFailOpen(v bool)
- func (s *Server) UpdateRateLimits(rc RateConfig) (applied RateConfig)
- type ServerInfo
Constants ¶
const ( NoContentChallengeHeader = "X-Tailscale-Challenge" NoContentResponseHeader = "X-Tailscale-Response" )
const (
DefaultTCPWiteTimeout = 2 * time.Second
)
Variables ¶
var IdealNodeContextKey = ctxkey.New("ideal-node", "")
IdealNodeContextKey is the context key used to pass the IdealNodeHeader value from the HTTP handler to the DERP server's Accept method.
Functions ¶
func AddWebSocketSupport ¶ added in v1.100.0
AddWebSocketSupport returns an http.Handler wrapping base that adds WebSocket-DERP support. WebSocket-DERP requests (those with an Upgrade: websocket header and a "derp" Sec-WebSocket-Protocol value) are handled here; all other requests pass through to base.
The browser-side Tailscale client (cmd/tsconnect/wasm) can only reach DERP via WebSocket, so any DERP server intended to be reachable from browsers must wrap derpserver.Handler with this function.
func ProbeHandler ¶
func ProbeHandler(w http.ResponseWriter, r *http.Request)
ProbeHandler is the endpoint that clients without UDP access (including js/wasm) hit to measure DERP latency, as a replacement for UDP STUN queries.
func ServeNoContent ¶
func ServeNoContent(w http.ResponseWriter, r *http.Request)
ServeNoContent generates the /generate_204 response used by Tailscale's captive portal detection.
Types ¶
type BytesSentRecv ¶
type BytesSentRecv struct {
Sent uint64
Recv uint64
// Key is the public key of the client which sent/received these bytes.
Key key.NodePublic
UniqueSenders uint64 `json:",omitzero"`
}
BytesSentRecv records the number of bytes that have been sent since the last traffic check for a given process, as well as the public key of the process sending those bytes.
type PacketForwarder ¶
type PacketForwarder interface {
// ForwardPacket forwards payload from src to dst. The payload is
// only on loan for the duration of the call; the Server reuses
// the memory once it returns.
ForwardPacket(src, dst key.NodePublic, payload derp.LoanedBytes) error
String() string
}
PacketForwarder is something that can forward packets.
It's mostly an interface for circular dependency reasons; the typical implementation is derphttp.Client. The other implementation is a multiForwarder, which this package creates as needed if a public key gets more than one PacketForwarder registered for it.
type RateConfig ¶ added in v1.98.0
type RateConfig struct {
// PerClientRateLimitBytesPerSec represents the per-client
// rate limit in bytes per second. A zero value disables all rate limiting.
PerClientRateLimitBytesPerSec uint64 `json:",omitzero"`
// PerClientRateBurstBytes represents the per-client token bucket depth,
// or burst, in bytes. Any value lower than [minRateLimitTokenBucketSize]
// will be increased to [minRateLimitTokenBucketSize] before application. Only
// relevant if PerClientRateLimitBytesPerSec is nonzero.
PerClientRateBurstBytes uint64 `json:",omitzero"`
}
RateConfig is a JSON-serializable configuration for rate limits. Values are in bytes.
func LoadRateConfig ¶ added in v1.98.0
func LoadRateConfig(path string) (RateConfig, error)
LoadRateConfig reads and JSON-unmarshals a RateConfig from the file at path.
type Server ¶
type Server struct {
// WriteTimeout, if non-zero, specifies how long to wait
// before failing when writing to a client.
WriteTimeout time.Duration
// contains filtered or unexported fields
}
Server is a DERP server.
func New ¶
func New(privateKey key.NodePrivate, logf logger.Logf) *Server
New returns a new DERP server. It doesn't listen on its own. Connections are given to it via Server.Accept.
func (*Server) Accept ¶
func (s *Server) Accept(ctx context.Context, nc derp.Conn, brw *bufio.ReadWriter, remoteAddr string)
Accept adds a new connection to the server and serves it.
The provided bufio ReadWriter must be already connected to nc. brw.Writer may be nil, in which case Accept writes to nc through pooled buffers held only during writes, which keeps the per-client standing memory lower for mostly idle connections. Accept blocks until the Server is closed or the connection closes on its own.
Accept closes nc.
func (*Server) AddPacketForwarder ¶
func (s *Server) AddPacketForwarder(dst key.NodePublic, fwd PacketForwarder)
AddPacketForwarder registers fwd as a packet forwarder for dst. fwd must be comparable.
func (*Server) ConsistencyCheck ¶
func (*Server) ExpVar ¶
ExpVar returns an expvar variable suitable for registering with expvar.Publish.
func (*Server) ForTest ¶ added in v1.102.0
func (s *Server) ForTest() forTest
ForTest returns a handle to test-only methods on s. The resulting type is unexported to make it very obvious in godoc that this is not stable API. This method panics if called outside of tests, which also centralizes all must-be-in-tests validation.
func (*Server) HasMeshKey ¶
HasMeshKey reports whether the server is configured with a mesh key.
func (*Server) IsClientConnectedForTest ¶
func (s *Server) IsClientConnectedForTest(k key.NodePublic) bool
IsClientConnectedForTest reports whether the client with specified key is connected. This is used in tests to verify that nodes are connected.
func (*Server) LoadAndApplyRateConfig ¶ added in v1.98.0
LoadAndApplyRateConfig reads a RateConfig from the file at path and applies it to the server via Server.UpdateRateLimits.
func (*Server) MetaCert ¶
MetaCert returns the server metadata cert that can be sent by the TLS server to let the client skip a round trip during start-up.
func (*Server) ModifyTLSConfigToAddMetaCert ¶
ModifyTLSConfigToAddMetaCert modifies c.GetCertificate to make it append s.MetaCert to the returned certificates. The certificate returned by the underlying GetCertificate is not mutated; a copy with the meta cert appended is returned instead.
It panics if c or c.GetCertificate is nil.
func (*Server) PrivateKey ¶
func (s *Server) PrivateKey() key.NodePrivate
PrivateKey returns the server's private key.
func (*Server) PublicKey ¶
func (s *Server) PublicKey() key.NodePublic
PublicKey returns the server's public key.
func (*Server) RemovePacketForwarder ¶
func (s *Server) RemovePacketForwarder(dst key.NodePublic, fwd PacketForwarder)
RemovePacketForwarder removes fwd as a packet forwarder for dst. fwd must be comparable.
func (*Server) ServeDebugClients ¶ added in v1.104.0
func (s *Server) ServeDebugClients(w http.ResponseWriter, r *http.Request)
ServeDebugClients serves the /debug/clients/ page listing connected clients.
With no query parameters it serves an index page with a form to pick one of the filters below. Otherwise it lists the clients matching exactly one of:
?all every connected client ?ip=1.2.3.4 clients connected from that IP address ?cidr=1.2.0.0/16 clients connected from that prefix ?key=nodekey:... the connection(s) for that node key
Any of those can be narrowed with app=NAME, repeatable to match any of several app names; app alone implies all. An empty app matches connections that sent no app name.
Results are paginated. sort=key (the default), ip, conn, connected, rx, tx, rxpkts, or txpkts picks the walk order, with a leading - for descending; connected ascending is longest connected first. limit=N sets the page size. after=X, where X is a value of the sort field, starts the page after that value; the next-page links also add afterconn=N to resume precisely among connections that share the value. For the connected sort, X is a connection time in Unix nanoseconds, or a duration such as 30m meaning connections up that long. Cursors are applied while walking, so skipped connections are never snapshotted.
format=json returns the page as a [debugClientsJSON] object instead of HTML, with the next page's relative URL in "next".
The traffic counters keep changing between pages, so walking by one of them can show a connection twice or skip it if its counter crossed the cursor in between.
func (*Server) ServeDebugTraffic ¶
func (s *Server) ServeDebugTraffic(w http.ResponseWriter, r *http.Request)
func (*Server) SetDisallowedAppNames ¶ added in v1.104.0
SetDisallowedAppNames sets the list of client app names (as advertised in their ClientInfo.AppName) that are not allowed to connect. Trusted mesh peers are exempt.
It must be called before serving begins.
func (*Server) SetMeshKey ¶
SetMesh sets the pre-shared key that regional DERP servers used to mesh amongst themselves.
It must be called before serving begins.
func (*Server) SetTCPWriteTimeout ¶
SetTCPWriteTimeout sets the timeout for writing to connected clients. This timeout does not apply to mesh connections. Defaults to 2 seconds.
func (*Server) SetTailscaledSocketPath ¶
SetTailscaledSocketPath sets the unix socket path to use to talk to tailscaled if client verification is enabled.
If unset or set to the empty string, the default path for the operating system is used.
func (*Server) SetVerifyClient ¶
SetVerifyClients sets whether this DERP server verifies clients through tailscaled.
It must be called before serving begins.
func (*Server) SetVerifyClientURL ¶
SetVerifyClientURL sets the admission controller URL to use for verifying clients. If empty, all clients are accepted (unless restricted by SetVerifyClient checking against tailscaled).
func (*Server) SetVerifyClientURLFailOpen ¶
SetVerifyClientURLFailOpen sets whether to allow clients to connect if the admission controller URL is unreachable.
func (*Server) UpdateRateLimits ¶ added in v1.98.0
func (s *Server) UpdateRateLimits(rc RateConfig) (applied RateConfig)
UpdateRateLimits sets the receive rate limits, updating all existing client connections. It returns the applied config, which may differ from rc. If the per-client rate limits is 0, rate limiting is disabled. Mesh peers are always exempt from rate limiting.
type ServerInfo ¶
type ServerInfo = derp.ServerInfo