Skip to main content

Module superadmin

Module superadmin 

Source
Expand description

Who is a superadmin (crate::auth::superadmin) on this daemon: a superadmin token, a tailnet identity on --superadmin-tailnet, a verified Cloudflare Access identity on --superadmin-access, either kind of identity added to isb.db with isb superadmin add (read per request, so no restart), or, in a debug build, any credential-less loopback request under ISB_DEV_SUPERADMIN (crate::auth::dev). Nothing else grants it. One gate serves the tool endpoints (through the authn hook) and the identity endpoints (/api/v1/auth/*).

Structs§

AccessAllowList
--superadmin-access: Access emails and service-token client ids.
Gate
Listed
One superadmin identity, as superadmin_list and the start-up line show it.

Enums§

Resolved
What the gate makes of a request.

Constants§

TOOLS
Tools for superadmins only (not platform admins): the host itself, and what reaches further into its kernel (nesting for an org’s workspace).

Functions§

announce
Say at start-up which sources grant superadmin.
gate
The gate cfg describes. Refuses --superadmin-access without Access or a public URL (whose host the Access check needs).
host_summary
What host_policy reports of the configuration (never a secret).
is_tailnet_listen
A --listen address on the tailnet (it then binds without a tunnel).