Expand description
Headscale API client and configuration helpers for yah mesh operations.
The mesh layer manages the Headscale coordinator that all yah-provisioned machines join via Tailscale. Phase 1a runs Headscale on the operator’s camp (bootstrap coordinator); Phase 1b promotes it to a cluster machine (R040-F19); Phase 2 adds openraft-based HA (R040-F20/F21).
Consumers:
app/yah/cli/src/mesh.rs—yah mesh start/status/backup/restoreapp/yah/cli/src/cloud.rs—yah cloud machine provision(auto-generates a Headscale preauth key whenmesh-urlis set in the vault)
Structs§
- Headscale
Client - HTTP client for a running Headscale coordinator.
- Headscale
Health - Headscale version + health response.
- Node
Info - Summary information about a node in the Headscale tailnet.
- Preauth
Key - A Headscale pre-authentication key for onboarding a new node.
Constants§
- DEFAULT_
ACL_ POLICY - A permissive ACL policy that allows all nodes to communicate.
Can be refined later with
yah mesh acl edit. - HEADSCALE_
VERSION - Pinned Headscale release version used by
yah mesh start.
Functions§
- cloudflare_
credentials - Load Cloudflare credentials from vault or environment.
- generate_
headscale_ config - Generate a headscale YAML configuration for Phase 1a (camp-local coordinator).
- headscale_
download_ url - Return the GitHub release download URL for headscale on this platform.
- update_
cloudflare_ dns - Update (or create) the A record for
record_namein the given Cloudflare zone, pointing it atnew_ip. Credentials come from the caller — usecloudflare_credentialsto load them from the vault / env.