Skip to main content

Module edge

Module edge 

Source
Expand description

Edge identities: the person a front door already verified. On a tailnet listener that is tailscaled’s whois of the real socket peer; behind Cloudflare Access it is a verified Cf-Access-Jwt-Assertion. Who resolves a request to one is the daemon’s gate; this module is what the identity endpoints make of it.

  • First-run setup: a claimable edge identity creates the first admin with no setup token. Reaching the port already took getting past the edge, so the race the setup token exists to stop is run only among the people the tailnet or the Access policy let in.
  • Signing in: an edge identity is an external identity (provider tailnet or access) with the usual rules (super::AuthStore::external_sign_in): a linked identity signs its user in, a verified email links to the user who has it, and a new account needs an invitation or open sign-up.

Only people count: a tagged tailnet node and an Access service token are never edge identities (they are what orgs’ agent identities are for).

Structs§

EdgeIdentity
A person a front door verified.

Functions§

login_email
A tailnet login that is a deliverable address: local@domain.tld. Tailscale’s GitHub logins (someone@github) are not.
provider_label
The label of an identity row whose provider is an edge.

Type Aliases§

EdgeFn
The edge identity behind a request, if any (the daemon’s gate).