mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: wire DERPTLSConfig through CLI, SDK, tailnet, VPN, agent, and health checks (#24435)
Wire DERPTLSConfig through the CLI, SDK, tailnet, VPN client, agent, and health checks to allow custom TLS configuration for DERP connections. The main use case is to be able to set a custom CA and also present client certs (mTLS). See https://github.com/coder/tailscale/pull/105 for related changes. Adds three new global CLI flags: - `--client-tls-ca-file` / `CODER_CLIENT_TLS_CA_FILE` - `--client-tls-cert-file` / `CODER_CLIENT_TLS_CERT_FILE` - `--client-tls-key-file` / `CODER_CLIENT_TLS_KEY_FILE` Based on community PR #22695 by @ibdafna, with autogeneration issues fixed (protobuf version mismatches in .pb.go files, golden file regeneration, lint fixes). > [!NOTE] > This PR was authored by Coder Agents on behalf of a Coder team member. <details> <summary>Relationship to #22695</summary> This is a clean reimplementation of the changes from #22695 on top of current `main`, with the following differences: - **Removed**: Accidental protobuf version changes in `.pb.go` files (contributor had `protoc v6.33.4` vs project's `protoc v4.23.4`) - **Added**: Properly regenerated golden files and docs via `make gen` - **Fixed**: Lint issue (`var-declaration` revive warning on explicit type in `createHTTPClient`) - All meaningful code changes are identical to the original PR </details>
This commit is contained in:
Generated
+27
@@ -174,6 +174,33 @@ Disable direct (P2P) connections to workspaces.
|
||||
|
||||
Disable network telemetry. Network telemetry is collected when connecting to workspaces using the CLI, and is forwarded to the server. If telemetry is also enabled on the server, it may be sent to Coder. Network telemetry is used to measure network quality and detect regressions.
|
||||
|
||||
### --client-tls-ca-file
|
||||
|
||||
| | |
|
||||
|-------------|----------------------------------------|
|
||||
| Type | <code>string</code> |
|
||||
| Environment | <code>$CODER_CLIENT_TLS_CA_FILE</code> |
|
||||
|
||||
Path to a CA certificate file to trust for API and DERP connections.
|
||||
|
||||
### --client-tls-cert-file
|
||||
|
||||
| | |
|
||||
|-------------|------------------------------------------|
|
||||
| Type | <code>string</code> |
|
||||
| Environment | <code>$CODER_CLIENT_TLS_CERT_FILE</code> |
|
||||
|
||||
Path to a client certificate file for mTLS authentication with API and DERP. Requires --client-tls-key-file.
|
||||
|
||||
### --client-tls-key-file
|
||||
|
||||
| | |
|
||||
|-------------|-----------------------------------------|
|
||||
| Type | <code>string</code> |
|
||||
| Environment | <code>$CODER_CLIENT_TLS_KEY_FILE</code> |
|
||||
|
||||
Path to a client private key file for mTLS authentication with API and DERP. Requires --client-tls-cert-file.
|
||||
|
||||
### --use-keyring
|
||||
|
||||
| | |
|
||||
|
||||
Reference in New Issue
Block a user