mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add server flag to force DERP to use always websockets (#9238)
This commit is contained in:
@@ -89,6 +89,7 @@ type Manifest struct {
|
||||
VSCodePortProxyURI string `json:"vscode_port_proxy_uri"`
|
||||
Apps []codersdk.WorkspaceApp `json:"apps"`
|
||||
DERPMap *tailcfg.DERPMap `json:"derpmap"`
|
||||
DERPForceWebSockets bool `json:"derp_force_websockets"`
|
||||
EnvironmentVariables map[string]string `json:"environment_variables"`
|
||||
StartupScript string `json:"startup_script"`
|
||||
StartupScriptTimeout time.Duration `json:"startup_script_timeout"`
|
||||
|
||||
+13
-3
@@ -229,9 +229,10 @@ type DERPServerConfig struct {
|
||||
}
|
||||
|
||||
type DERPConfig struct {
|
||||
BlockDirect clibase.Bool `json:"block_direct" typescript:",notnull"`
|
||||
URL clibase.String `json:"url" typescript:",notnull"`
|
||||
Path clibase.String `json:"path" typescript:",notnull"`
|
||||
BlockDirect clibase.Bool `json:"block_direct" typescript:",notnull"`
|
||||
ForceWebSockets clibase.Bool `json:"force_websockets" typescript:",notnull"`
|
||||
URL clibase.String `json:"url" typescript:",notnull"`
|
||||
Path clibase.String `json:"path" typescript:",notnull"`
|
||||
}
|
||||
|
||||
type PrometheusConfig struct {
|
||||
@@ -797,6 +798,15 @@ when required by your organization's security policy.`,
|
||||
Group: &deploymentGroupNetworkingDERP,
|
||||
YAML: "blockDirect",
|
||||
},
|
||||
{
|
||||
Name: "DERP Force WebSockets",
|
||||
Description: "Force clients and agents to always use WebSocket to connect to DERP relay servers. By default, DERP uses `Upgrade: derp`, which may cause issues with some reverse proxies. Clients may automatically fallback to WebSocket if they detect an issue with `Upgrade: derp`, but this does not work in all situations.",
|
||||
Flag: "derp-force-websockets",
|
||||
Env: "CODER_DERP_FORCE_WEBSOCKETS",
|
||||
Value: &c.DERP.Config.ForceWebSockets,
|
||||
Group: &deploymentGroupNetworkingDERP,
|
||||
YAML: "forceWebSockets",
|
||||
},
|
||||
{
|
||||
Name: "DERP Config URL",
|
||||
Description: "URL to fetch a DERP mapping on startup. See: https://tailscale.com/kb/1118/custom-derp-servers/.",
|
||||
|
||||
@@ -186,6 +186,7 @@ type DERPRegion struct {
|
||||
// @typescript-ignore WorkspaceAgentConnectionInfo
|
||||
type WorkspaceAgentConnectionInfo struct {
|
||||
DERPMap *tailcfg.DERPMap `json:"derp_map"`
|
||||
DERPForceWebSockets bool `json:"derp_force_websockets"`
|
||||
DisableDirectConnections bool `json:"disable_direct_connections"`
|
||||
}
|
||||
|
||||
@@ -247,11 +248,12 @@ func (c *Client) DialWorkspaceAgent(ctx context.Context, agentID uuid.UUID, opti
|
||||
header = headerTransport.Header()
|
||||
}
|
||||
conn, err := tailnet.NewConn(&tailnet.Options{
|
||||
Addresses: []netip.Prefix{netip.PrefixFrom(ip, 128)},
|
||||
DERPMap: connInfo.DERPMap,
|
||||
DERPHeader: &header,
|
||||
Logger: options.Logger,
|
||||
BlockEndpoints: c.DisableDirectConnections || options.BlockEndpoints,
|
||||
Addresses: []netip.Prefix{netip.PrefixFrom(ip, 128)},
|
||||
DERPMap: connInfo.DERPMap,
|
||||
DERPHeader: &header,
|
||||
DERPForceWebSockets: connInfo.DERPForceWebSockets,
|
||||
Logger: options.Logger,
|
||||
BlockEndpoints: c.DisableDirectConnections || options.BlockEndpoints,
|
||||
})
|
||||
if err != nil {
|
||||
return nil, xerrors.Errorf("create tailnet: %w", err)
|
||||
|
||||
Reference in New Issue
Block a user