Expand description
Finding a control-plane credential in the environment.
Three shapes are accepted, in a fixed order of precedence: an API access token, an OAuth client, and a federated identity backed by a JWT on disk. The order is fixed rather than “whichever is set” so that an operator who leaves an old token in a shell profile gets a predictable answer instead of a lottery.
ApiKey and API_KEY_ENV keep the ecosystem’s spelling because the variable
they read is TAILSCALE_API_KEY and an operator setting it should be able to
find it here. CONTEXT.md governs the prose, which says “API access token”.
Enums§
- Credentials
- How this server proves who it is to the control plane.
Constants§
- API_
KEY_ ENV - DEFAULT_
TAILNET - What the API accepts to mean “the tailnet this credential belongs to”.
- ENV_
VARS - Every variable this module reads, for the diagnosis subcommand and for the documentation to stay in step with the code.
- OAUTH_
CLIENT_ ID_ ENV - OAUTH_
CLIENT_ SECRET_ ENV - OAUTH_
JWT_ FILE_ ENV - OAUTH_
SCOPES_ ENV - TAILNET_
ENV
Functions§
- tailnet_
from_ env - The tailnet these credentials act on.
- tailnet_
from_ source - The tailnet these credentials act on, from an arbitrary source.