Skip to main content

POLICY_MODE

Constant POLICY_MODE 

Source
pub const POLICY_MODE: &str = "database";
Expand description

The policy.mode every in-tree renderer emits (R861-T2).

database puts the ACL policy in headscale.db, which litestream already replicates, instead of in an acls.yaml that nothing replicates. It is also the only mode in which PUT /api/v1/policy is accepted, so it is the mode that makes super::reconciler::headscale’s declared policy pushable rather than merely observable.

Verified against the pinned headscale v0.23.0 source: policy.mode takes exactly "file" or "database" (hscontrol/types/config.go), and an unrecognised value is a log.Fatal at startup — so this string is load-bearing and must not be reworded.

policy.path is deliberately absent: headscale reads it only in file mode (hscontrol/grpcv1.go GetPolicy, hscontrol/app.go loadACLPolicy), so leaving it set would document a file that is no longer the source of truth.

yubaba’s generate_remote_headscale_config / generate_bootstrap_headscale_config emit the same value from their own crate (no dependency edge exists between them and this one) and are kept in lockstep by convention, the way DEFAULT_HEADSCALE_VERSION already is.