Skip to main content

Module mesh

Module mesh 

Source
Expand description

Headscale API client and configuration helpers for yah mesh operations.

The mesh layer manages the Headscale coordinator that all yah-provisioned machines join via Tailscale. Phase 1a runs Headscale on the operator’s camp (bootstrap coordinator); Phase 1b promotes it to a cluster machine (R040-F19); Phase 2 adds openraft-based HA (R040-F20/F21).

Consumers:

  • app/yah/cli/src/mesh.rs — yah mesh start/status/backup/restore
  • app/yah/cli/src/cloud.rs — yah cloud machine provision (auto-generates a Headscale preauth key when mesh-url is set in the vault)

Structs§

HeadscaleClient
HTTP client for a running Headscale coordinator.
HeadscaleHealth
Headscale version + health response.
NodeInfo
Summary information about a node in the Headscale tailnet.
PreauthKey
A Headscale pre-authentication key for onboarding a new node.

Constants§

DEFAULT_ACL_POLICY
A permissive ACL policy that allows all nodes to communicate. Can be refined later with yah mesh acl edit.
HEADSCALE_VERSION
Pinned Headscale release version used by yah mesh start.

Functions§

cloudflare_credentials
Load Cloudflare credentials from vault or environment.
generate_headscale_config
Generate a headscale YAML configuration for Phase 1a (camp-local coordinator).
headscale_download_url
Return the GitHub release download URL for headscale on this platform.
update_cloudflare_dns
Update (or create) the A record for record_name in the given Cloudflare zone, pointing it at new_ip. Credentials come from the caller — use cloudflare_credentials to load them from the vault / env.