Documentation ¶
Overview ¶
Package controlhttp implements the Tailscale 2021 control protocol base transport over HTTP.
This tunnels the protocol in control/controlbase over HTTP with a variety of compatibility fallbacks for handling picky or deep inspecting proxies.
In the happy path, a client makes a single cleartext HTTP request to the server, the server responds with 101 Switching Protocols, and the control base protocol takes place over plain TCP.
In the compatibility path, the client does the above over HTTPS, resulting in double encryption (once for the control transport, and once for the outer TLS layer).
Index ¶
Constants ¶
const NoPort = "none"
NoPort is a sentinel value for Dialer.HTTPSPort to indicate that HTTPS should not be tried on any port. It exists primarily for some localhost tests where the control plane only runs on HTTP.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type ClientConn ¶
type ClientConn struct { // Conn is the noise connection. *controlbase.Conn }
ClientConn is a Tailscale control client as returned by the Dialer.
It's effectively just a *controlbase.Conn (which it embeds) with optional metadata.
type Dialer ¶
type Dialer struct { // Hostname is the hostname to connect to, with no port number. // // This field is required. Hostname string // MachineKey contains the current machine's private key. // // This field is required. MachineKey key.MachinePrivate // ControlKey contains the expected public key for the control server. // // This field is required. ControlKey key.MachinePublic // ProtocolVersion is the expected protocol version to negotiate. // // This field is required. ProtocolVersion uint16 // HTTPPort is the port number to use when making a HTTP connection. // // If not specified, this defaults to port 80. HTTPPort string // HTTPSPort is the port number to use when making a HTTPS connection. // // If not specified, this defaults to port 443. // // If "none" (NoPort), HTTPS is disabled. HTTPSPort string // Dialer is the dialer used to make outbound connections. // // If not specified, this defaults to net.Dialer.DialContext. Dialer dnscache.DialContextFunc // DNSCache is the caching Resolver used by this Dialer. // // If not specified, a new Resolver is created per attempt. DNSCache *dnscache.Resolver // Logf, if set, is a logging function to use; if unset, logs are // dropped. Logf logger.Logf // NetMon is the [netmon.Monitor] to use for this Dialer. It must be // non-nil. NetMon *netmon.Monitor // HealthTracker, if non-nil, is the health tracker to use. HealthTracker *health.Tracker // DialPlan, if set, contains instructions from the control server on // how to connect to it. If present, we will try the methods in this // plan before falling back to DNS. DialPlan *tailcfg.ControlDialPlan // Clock, if non-nil, overrides the clock to use. // If nil, tstime.StdClock is used. // This exists primarily for tests. Clock tstime.Clock // contains filtered or unexported fields }
Dialer contains configuration on how to dial the Tailscale control server.
func (*Dialer) Dial ¶
func (a *Dialer) Dial(ctx context.Context) (*ClientConn, error)
Dial connects to the HTTP server at this Dialer's Host:HTTPPort, requests to switch to the Tailscale control protocol, and returns an established control protocol connection.
If Dial fails to connect using HTTP, it also tries to tunnel over TLS to the Dialer's Host:HTTPSPort as a compatibility fallback.
The provided ctx is only used for the initial connection, until Dial returns. It does not affect the connection once established.
Directories ¶
Path | Synopsis |
---|---|
Package controlhttpcommon contains common constants for used by the controlhttp client and controlhttpserver packages.
|
Package controlhttpcommon contains common constants for used by the controlhttp client and controlhttpserver packages. |
Package controlhttpserver contains the HTTP server side of the ts2021 control protocol.
|
Package controlhttpserver contains the HTTP server side of the ts2021 control protocol. |