Skip to main content

Gate

Struct Gate 

Source
pub struct Gate { /* private fields */ }

Implementations§

Source§

impl Gate

Source

pub fn new( store: Arc<AuthStore>, tailnet: Option<Tailnet>, access: Option<(Arc<AccessValidator>, AccessAllowList, Vec<String>)>, ) -> Gate

Source

pub fn with_agents( self, tailnet_listens: Vec<String>, access: Option<(Arc<AccessValidator>, Vec<String>)>, ) -> Gate

Let orgs’ tailnet and Access agent identities in (crate::auth::agent_identities): the tailnet --listen addresses, and Access’s validator with the Host names to allow.

Source

pub fn agent_ways(&self) -> AgentWays

Which agent identities can reach this server at all.

Source

pub fn agent(&self, req: &Request, id: Option<&Identity>) -> Option<Principal>

The agent identity behind req, if an org maps it: a verified Access identity (id, else the request’s own assertion) on a loopback listener Access guards, or a tailnet peer, as tailscaled says. A bearer token decides on its own, so it is not asked here. Superadmin sources are judged first, by Gate::resolve.

Source

pub fn edge(&self, req: &Request, id: Option<&Identity>) -> Option<EdgeIdentity>

The person a front door verified (crate::auth::edge): a verified Access user on a loopback listener Access guards, or an untagged tailnet peer. Service tokens and tagged nodes are not people. They may claim setup unless this front door’s superadmin allow list exists and leaves them out.

Source

pub fn agent_fn(self: &Arc<Self>) -> AgentFn

Gate::agent and Gate::edge as the identity endpoints ask them.

Source

pub fn edge_fn(self: &Arc<Self>) -> EdgeFn

Source

pub fn tailnet(&self) -> Option<&Tailnet>

Source

pub fn access_list(&self) -> Option<&AccessAllowList>

Source

pub fn resolve(&self, req: &Request, id: Option<&Identity>) -> Resolved

id is the Access identity the listener already verified, if any. A bearer superadmin token decides alone; any other bearer token is not this gate’s. Then Access, then the tailnet.

Auto Trait Implementations§

§

impl !Freeze for Gate

§

impl !RefUnwindSafe for Gate

§

impl !UnwindSafe for Gate

§

impl Send for Gate

§

impl Sync for Gate

§

impl Unpin for Gate

§

impl UnsafeUnpin for Gate

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V