Skip to main content

Module superadmin

Module superadmin 

Source
Expand description

Superadmins: the unix socket’s reach (every tool, no remote-spec policy, any instance) for an HTTP caller. Three sources grant it, and nothing else:

  • a superadmin token (isb_sa_...), minted only on the host with isb token create NAME --superadmin, never over HTTP, so a stolen HTTP credential cannot mint a durable one;
  • a tailnet identity on isb serve --superadmin-tailnet (the daemon’s crate::server::tailnet check), judged from the real socket peer;
  • a Cloudflare Access identity on isb serve --superadmin-access: a verified Cf-Access-Jwt-Assertion whose email (or service token client id) is on the list.

A superadmin acts as an isb user when its tailnet login or Access email is one, else as a synthetic principal (user id 0) named after the source.

Structs§

NewSuperadminToken
Superadmin
A caller with the unix socket’s reach.
SuperadminToken
A superadmin token’s metadata.

Enums§

SuperadminSource
Where a superadmin’s power comes from.