Expand description
Edge identities: the person a front door already verified. On a tailnet
listener that is tailscaled’s whois of the real socket peer; behind
Cloudflare Access it is a verified Cf-Access-Jwt-Assertion. Who
resolves a request to one is the daemon’s gate; this module is what the
identity endpoints make of it.
- First-run setup: a claimable edge identity creates the first admin with no setup token. Reaching the port already took getting past the edge, so the race the setup token exists to stop is run only among the people the tailnet or the Access policy let in.
- Signing in: an edge identity is an external identity (provider
tailnetoraccess) with the usual rules (super::AuthStore::external_sign_in): a linked identity signs its user in, a verified email links to the user who has it, and a new account needs an invitation or open sign-up.
Only people count: a tagged tailnet node and an Access service token are never edge identities (they are what orgs’ agent identities are for).
Structs§
- Edge
Identity - A person a front door verified.
Functions§
- login_
email - A tailnet login that is a deliverable address:
local@domain.tld. Tailscale’s GitHub logins (someone@github) are not. - provider_
label - The label of an identity row whose provider is an edge.
Type Aliases§
- EdgeFn
- The edge identity behind a request, if any (the daemon’s gate).