mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add flag to disable all direct connections (#7936)
This commit is contained in:
@@ -25,10 +25,14 @@ func TestNetcheck(t *testing.T) {
|
||||
|
||||
clitest.StartWithWaiter(t, inv).RequireSuccess()
|
||||
|
||||
b := out.Bytes()
|
||||
t.Log(string(b))
|
||||
var report healthcheck.DERPReport
|
||||
require.NoError(t, json.Unmarshal(out.Bytes(), &report))
|
||||
require.NoError(t, json.Unmarshal(b, &report))
|
||||
|
||||
assert.True(t, report.Healthy)
|
||||
require.Len(t, report.Regions, 1)
|
||||
require.Len(t, report.Regions[1].NodeReports, 1)
|
||||
for _, v := range report.Regions {
|
||||
require.Len(t, v.NodeReports, len(v.Region.Nodes))
|
||||
}
|
||||
}
|
||||
|
||||
@@ -413,6 +413,7 @@ func (r *RootCmd) Server(newAPI func(context.Context, *coderd.Options) (*coderd.
|
||||
derpMap, err := tailnet.NewDERPMap(
|
||||
ctx, defaultRegion, cfg.DERP.Server.STUNAddresses,
|
||||
cfg.DERP.Config.URL.String(), cfg.DERP.Config.Path.String(),
|
||||
cfg.DERP.Config.BlockDirect.Value(),
|
||||
)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("create derp map: %w", err)
|
||||
|
||||
+8
@@ -150,6 +150,14 @@ between workspaces and users are peer-to-peer. However, when Coder cannot
|
||||
establish a peer to peer connection, Coder uses a distributed relay network
|
||||
backed by Tailscale and WireGuard.
|
||||
|
||||
--block-direct-connections bool, $CODER_BLOCK_DIRECT
|
||||
Block peer-to-peer (aka. direct) workspace connections. All workspace
|
||||
connections from the CLI will be proxied through Coder (or custom
|
||||
configured DERP servers) and will never be peer-to-peer when enabled.
|
||||
Workspaces may still reach out to STUN servers to get their address
|
||||
until they are restarted after this change has been made, but new
|
||||
connections will still be proxied regardless.
|
||||
|
||||
--derp-config-path string, $CODER_DERP_CONFIG_PATH
|
||||
Path to read a DERP mapping from. See:
|
||||
https://tailscale.com/kb/1118/custom-derp-servers/.
|
||||
|
||||
+7
@@ -117,6 +117,13 @@ networking:
|
||||
# for high availability.
|
||||
# (default: <unset>, type: url)
|
||||
relayURL:
|
||||
# Block peer-to-peer (aka. direct) workspace connections. All workspace
|
||||
# connections from the CLI will be proxied through Coder (or custom configured
|
||||
# DERP servers) and will never be peer-to-peer when enabled. Workspaces may still
|
||||
# reach out to STUN servers to get their address until they are restarted after
|
||||
# this change has been made, but new connections will still be proxied regardless.
|
||||
# (default: <unset>, type: bool)
|
||||
blockDirect: false
|
||||
# URL to fetch a DERP mapping on startup. See:
|
||||
# https://tailscale.com/kb/1118/custom-derp-servers/.
|
||||
# (default: <unset>, type: string)
|
||||
|
||||
Reference in New Issue
Block a user