pub struct Listener {
pub kind: ListenerKind,
pub access: Option<Arc<AccessValidator>>,
pub policy: ToolPolicy,
pub allow_unauthenticated: bool,
pub tailnet: bool,
pub routes: Option<Routes>,
pub public_routes: Option<Routes>,
pub preview: Option<Routes>,
pub hooks: Hooks,
}Expand description
One address the server answers on, with its own gate and tool policy.
Fields§
§kind: ListenerKind§access: Option<Arc<AccessValidator>>Required on TCP unless allow_unauthenticated; refused on unix.
policy: ToolPolicy§allow_unauthenticated: boolServe TCP with no Access validation, trusting whatever reaches the port.
tailnet: boolA TCP listener on a tailnet address rather than loopback.
routes: Option<Routes>Paths other than /healthz and /mcp.
public_routes: Option<Routes>Routes that authenticate every request themselves and are served even with Access configured (webhooks, signed by their sender).
preview: Option<Routes>Requests for preview hosts, by Host, ahead of everything else.
hooks: HooksAuthentication and authorization the embedder supplies.
Implementations§
Source§impl Listener
impl Listener
pub fn tcp(addr: impl Into<String>) -> Self
pub fn unix(path: impl Into<PathBuf>) -> Self
Sourcepub fn mtls(addr: impl Into<String>, tls: TlsConfig) -> Self
pub fn mtls(addr: impl Into<String>, tls: TlsConfig) -> Self
TLS on any address, admitting only clients whose certificate tls
verifies.
pub fn routes(self, r: Routes) -> Self
Sourcepub fn public_routes(self, r: Routes) -> Self
pub fn public_routes(self, r: Routes) -> Self
Serve r ahead of Access: only for routes whose every request
carries its own credential.
Sourcepub fn preview(self, r: Routes) -> Self
pub fn preview(self, r: Routes) -> Self
Let r take requests by their Host before anything else: it
answers only for hosts that are its own.
pub fn access(self, v: AccessValidator) -> Self
Self::access, sharing a validator (and its key cache).
Sourcepub fn tailnet(self, yes: bool) -> Self
pub fn tailnet(self, yes: bool) -> Self
Bind a tailnet address instead of loopback (no Access: only tailnet peers reach it).
pub fn policy(self, p: ToolPolicy) -> Self
pub fn allow_unauthenticated(self, yes: bool) -> Self
Sourcepub fn is_trusted(&self) -> bool
pub fn is_trusted(&self) -> bool
The unix socket is trusted as itself; a TCP caller is trusted only as a superadmin, per request.