Skip to main content

Module credentials

Module credentials 

Source
Expand description

Finding a control-plane credential in the environment.

Three shapes are accepted, in a fixed order of precedence: an API access token, an OAuth client, and a federated identity backed by a JWT on disk. The order is fixed rather than “whichever is set” so that an operator who leaves an old token in a shell profile gets a predictable answer instead of a lottery.

ApiKey and API_KEY_ENV keep the ecosystem’s spelling because the variable they read is TAILSCALE_API_KEY and an operator setting it should be able to find it here. CONTEXT.md governs the prose, which says “API access token”.

Enums§

Credentials
How this server proves who it is to the control plane.

Constants§

API_KEY_ENV
DEFAULT_TAILNET
What the API accepts to mean “the tailnet this credential belongs to”.
ENV_VARS
Every variable this module reads, for the diagnosis subcommand and for the documentation to stay in step with the code.
OAUTH_CLIENT_ID_ENV
OAUTH_CLIENT_SECRET_ENV
OAUTH_JWT_FILE_ENV
OAUTH_SCOPES_ENV
TAILNET_ENV

Functions§

tailnet_from_env
The tailnet these credentials act on.
tailnet_from_source
The tailnet these credentials act on, from an arbitrary source.