Expand description
Handing the CLI something too big or too private for an argument list.
An argument list is world-readable on every platform we support: ps shows
it, /proc shows it, and a crash reporter will happily upload it. Tailscale
anticipates this and accepts file:<path> wherever it accepts a key, so the
secret goes into a file only this process can read, for only as long as the
call takes. That is SecretFile.
PrivateFile is the other direction: a document the CLI insists on
exchanging through a file rather than a stream, in either direction. It
protects the directory rather than the file, because a file the CLI
creates is created with the CLI’s idea of a mode, not ours.
Structs§
- Private
File - A scratch file inside a directory only this user can enter, removed when this value is dropped along with the directory holding it.
- Secret
File - A private file holding one secret, removed when this value is dropped.