Skip to main content

Module tailnet

Module tailnet 

Source
Expand description

Tailnet identity, for isb serve --superadmin-tailnet and orgs’ agent identities: who is at the other end of a TCP connection from a tailnet address, asked of the local tailscaled.

  • Only the real socket peer counts. Forwarded headers (X-Forwarded-For, Tailscale-User-Login) are never read: anything on the path could write them.
  • The peer must be a tailnet address (100.64.0.0/10, fd7a:115c:a1e0::/48) and the request’s Host one of this server’s names (its tailnet listen addresses, its MagicDNS names, the public URL’s host), which blocks DNS rebinding: a page on another site that resolves its name to this address still sends its own Host.
  • tailscaled answers whois through its LocalAPI (the unix socket on Linux), else the tailscale whois --json CLI (macOS). When neither answers, nobody is a tailnet superadmin; why is logged once.
  • A tagged node is its tags (its login is tagged-devices); any other node is its user’s login name. The allow list names either.
  • Answers are cached per peer address for a minute, failures for five seconds.

Structs§

AllowList
--superadmin-tailnet: login names and node tags.
Tailnet
The check isb serve --superadmin-tailnet runs on every TCP request.
Whois
Who tailscaled says is behind an address.

Constants§

LOCALAPI_SOCKETS
tailscaled’s LocalAPI socket on Linux.

Functions§

host_only
host[:port] or [v6]:port to its lowercased host, brackets kept for v6 so it compares with what a browser sends.
is_tailnet_ip
100.64.0.0/10 (IPv4, also v4-mapped) or fd7a:115c:a1e0::/48.
parse_whois
Parse tailscale’s whois JSON (LocalAPI and CLI share the shape).
self_names
This node’s MagicDNS name and short host name, for the Host check. Empty when tailscaled does not answer.
system_fetcher
The real thing: tailscaled’s LocalAPI, else the CLI.

Type Aliases§

WhoisFetcher
Asks tailscaled about one peer. Injectable, for tests.