Expand description
Who is a superadmin (crate::auth::superadmin) on this daemon: a
superadmin token, a tailnet identity on --superadmin-tailnet, a
verified Cloudflare Access identity on --superadmin-access, either kind
of identity added to isb.db with isb superadmin add (read per request,
so no restart), or, in a debug build, any credential-less loopback request
under ISB_DEV_SUPERADMIN (crate::auth::dev). Nothing else grants it.
One gate serves the tool endpoints (through the authn hook) and the
identity endpoints (/api/v1/auth/*).
Structs§
- Access
Allow List --superadmin-access: Access emails and service-token client ids.- Gate
- Listed
- One superadmin identity, as
superadmin_listand the start-up line show it.
Enums§
- Resolved
- What the gate makes of a request.
Constants§
- TOOLS
- Tools for superadmins only (not platform admins): the host itself, and what reaches further into its kernel (nesting for an org’s workspace).
Functions§
- announce
- Say at start-up which sources grant superadmin.
- gate
- The gate
cfgdescribes. Refuses--superadmin-accesswithout Access or a public URL (whose host the Access check needs). - host_
summary - What
host_policyreports of the configuration (never a secret). - is_
tailnet_ listen - A
--listenaddress on the tailnet (it then binds without a tunnel).