Expand description
MCP server for Tailscale.
Two surfaces, deliberately kept apart. The local surface drives the node
this server runs on through the tailscale command-line interface
(ADR-0001). The tailnet surface acts on the whole tailnet through the
control-plane REST API (ADR-0002). A tool belongs to exactly one of them.
The crate is a library as well as a binary so that the tests can build a whole server in-process and drive it as a client, which is where nearly all of the behaviour is observable.
That is the whole of why the library is public, and so it carries no
stability guarantee: the compatible thing to depend on is the protocol this
server speaks, which the contract tests pin, rather than the Rust surface
the tests happen to reach through. A signature here may change in any
release, and cargo semver-checks will say so — the question that answers
is whether the change was meant, not whether it is allowed.
Modules§
- cli
- Running a local command and reading its failure.
- completion
completion/complete: values for the slots whose set the server can know.- config
- Turning flags and environment variables into a settled configuration.
- context
- What a tool handler is given.
- error
- The tool-level error model, and the redaction every error passes through.
- gating
- Which tools this server offers, and at which risk tier.
- http
- The Streamable HTTP transport, and everything that stands in front of it.
- instructions
- What the server tells a model about itself.
- meta
- Tool metadata: the single table that the router, the
toolssubcommand, the contract tests and the generated documentation all read. - registry
- The tool table, and the macro that fills it.
- resources
- Nine resources and three prompts.
- server
- The MCP handler, and what has to be true before it can be built.
- subcommands
- The things this binary does other than serve.
- tools
- The tool table.
- version
- Reading, comparing and reporting the local Tailscale version.
Macros§
- tools
- Declare tools.