Expand description
Superadmins: the unix socket’s reach (every tool, no remote-spec policy, any instance) for an HTTP caller. Three sources grant it, and nothing else:
- a superadmin token (
isb_sa_...), minted only on the host withisb token create NAME --superadmin, never over HTTP, so a stolen HTTP credential cannot mint a durable one; - a tailnet identity on
isb serve --superadmin-tailnet(the daemon’scrate::server::tailnetcheck), judged from the real socket peer; - a Cloudflare Access identity on
isb serve --superadmin-access: a verifiedCf-Access-Jwt-Assertionwhose email (or service token client id) is on the list.
A superadmin acts as an isb user when its tailnet login or Access email is one, else as a synthetic principal (user id 0) named after the source.
Structs§
- NewSuperadmin
Token - Superadmin
- A caller with the unix socket’s reach.
- Superadmin
Token - A superadmin token’s metadata.
Enums§
- Superadmin
Source - Where a superadmin’s power comes from.