Expand description
Tailnet identity, for isb serve --superadmin-tailnet and orgs’ agent
identities: who is at the other end of a TCP connection from a tailnet
address, asked of the local tailscaled.
- Only the real socket peer counts. Forwarded headers
(
X-Forwarded-For,Tailscale-User-Login) are never read: anything on the path could write them. - The peer must be a tailnet address (100.64.0.0/10, fd7a:115c:a1e0::/48)
and the request’s
Hostone of this server’s names (its tailnet listen addresses, its MagicDNS names, the public URL’s host), which blocks DNS rebinding: a page on another site that resolves its name to this address still sends its ownHost. - tailscaled answers
whoisthrough its LocalAPI (the unix socket on Linux), else thetailscale whois --jsonCLI (macOS). When neither answers, nobody is a tailnet superadmin; why is logged once. - A tagged node is its tags (its login is
tagged-devices); any other node is its user’s login name. The allow list names either. - Answers are cached per peer address for a minute, failures for five seconds.
Structs§
- Allow
List --superadmin-tailnet: login names and node tags.- Tailnet
- The check
isb serve --superadmin-tailnetruns on every TCP request. - Whois
- Who tailscaled says is behind an address.
Constants§
- LOCALAPI_
SOCKETS - tailscaled’s LocalAPI socket on Linux.
Functions§
- host_
only host[:port]or[v6]:portto its lowercased host, brackets kept for v6 so it compares with what a browser sends.- is_
tailnet_ ip - 100.64.0.0/10 (IPv4, also v4-mapped) or fd7a:115c:a1e0::/48.
- parse_
whois - Parse tailscale’s whois JSON (LocalAPI and CLI share the shape).
- self_
names - This node’s MagicDNS name and short host name, for the
Hostcheck. Empty when tailscaled does not answer. - system_
fetcher - The real thing: tailscaled’s LocalAPI, else the CLI.
Type Aliases§
- Whois
Fetcher - Asks tailscaled about one peer. Injectable, for tests.