Skip to main content

Module superadmin

Module superadmin 

Source
Expand description

Superadmins: the unix socket’s reach (every tool, no remote-spec policy, any instance) for an HTTP caller. These sources grant it, and nothing else:

  • a superadmin token (isb_sa_...), minted only on the host with isb token create NAME --superadmin, never over HTTP, so a stolen HTTP credential cannot mint a durable one;
  • a tailnet identity on isb serve --superadmin-tailnet or added with isb superadmin add --tailnet (SuperadminIdentity; the daemon’s crate::server::tailnet check), judged from the real socket peer;
  • a Cloudflare Access identity on isb serve --superadmin-access or added with isb superadmin add --access/--access-token: a verified Cf-Access-Jwt-Assertion whose email (or service token client id) is listed;
  • in a debug build, ISB_DEV_SUPERADMIN (super::dev): any loopback request with no credential, for developing isb.

A superadmin acts as an isb user when its tailnet login, Access email or dev email is one, else as a synthetic principal (user id 0) named after the source.

Structs§

NewSuperadminToken
Superadmin
A caller with the unix socket’s reach.
SuperadminIdentity
One identity in the table.
SuperadminToken
A superadmin token’s metadata.

Enums§

SuperadminSource
Where a superadmin’s power comes from.

Constants§

MAX_SUPERADMIN_IDENTITIES
How many the table may hold: it is read on every request that could match one.