mirror of
https://github.com/EasyTier/EasyTier.git
synced 2026-10-08 10:56:13 -08:00
Persist central network intent and compile complete per-device configs with secure credentials, ACL policy, and dedicated Gateway runtimes. Expose network, credential, device registry, and runtime observation APIs. Treat central management and external Console as alternative consumers of the upstream ClientManager. Register central devices through a local webhook handler and publish through existing runtime reconciliation. Serialize public mutations with enrollment, reject direct credential changes to managed instances, and retain REST revision invalidation. Keep Gateway lifecycle publication in the central service and remove obsolete incremental result bookkeeping. Restore persisted networks and retire orphan runtimes through the same serialized publisher. Add Core and protocol support for Gateway and WireGuard management, including GUI bindings and serialized GUI config writes. Bootstrap IPv4 for DHCP-only networks and retain assigned addresses without peer IPv4. Cover intent transactions, complete configuration publication, offline recovery, authentication, revocation, Gateway lifecycle, and DHCP. Validate central candidates before persistence using Core URL, config, and portal-client rules. Reject unsupported peer schemes, unconvertible proxy subnets, and invalid portal clients without changing live intent. Expose existing pure Core validators without changing runtime behavior. Gate API-facing credential validation on API-enabled Core builds so minimal WASM targets do not reference omitted management types. Preserve session-backed device views in external Console mode. Bound Gateway admissions without cancelling transport upgrades, and cancel pending peer handshakes before retiring runtimes. Batch registry reads and bound runtime observation concurrency. Randomize DHCP bootstrap and conflict retries, keep an advertised current subnet, and select fallback subnets deterministically. Cover concurrent startup, Gateway admission lifetime, and external Console regressions. Allow DHCP bootstrap with no remote routes. Count network members through one tenant-scoped query without write transactions. Cover zero- peer allocation and tenant/empty-network counts. Preserve direct Web configurations and disabled states in central device snapshots. Remove obsolete central rows atomically with membership changes. Stop online managed instances before deleting or blocking devices, retaining intent when shutdown or deletion fails. Persist automatic IPv4 allocations separately from manual overrides so subnet changes reallocate only automatic members. Normalize mapped proxy routes to their advertised CIDRs when granting temporary credentials. Cover publication, deletion rollback, subnet migration, and grant updates. Read central intent in deferred transactions so polling does not reserve the SQLite writer lock. Test reads with an active writer and assert the temporary-member secret constraint using a valid device fixture. Persist patched WireGuard clients from the saved Web or GUI candidate without a follow-up RPC. Preserve pending settings and ownership, and cover disconnects and failed patches. Resolve named credential and config mutations against the live Core instance before checking central ownership. Forward authorized mutations by UUID on the same session, including while network renames are pending. Cover all mutation methods and preserve direct Console behavior. * feat(web-ui): add central network console and WireGuard management Add network and device views with central membership, credentials, ACL policy, temporary peers, and per-instance runtime details. Update console navigation, styling, theme handling, and API clients. Extend shared configuration and status components for central networks. Add a WireGuard portal dialog for setup and running-device management, with matching translations and network configuration types. Use secure UUID generation on HTTP, discard stale member configuration responses, and stop node-detail polling when the component unmounts. Update frontend workspace dependencies and include component, dashboard, configuration serialization, and central console end-to-end tests. Add isolated real-Core E2E coverage for central data-plane traffic, ACL, DHCP, recovery, device lifecycle, and native WireGuard clients. Record all 59 functional checks with evidence and confirmed validation/UI defects; keep runtime artifacts and test credentials out of Git. Normalize protobuf logger levels and render translated labels correctly. Cover all six levels across setting, reload, and language changes. Add real configuration-rejection E2E checks for database and Core stability and uninterrupted traffic, and record the resolved audit findings. Gate central navigation and registry actions by console mode. Refresh WireGuard settings on mounted status views and preserve explicit portal listener endpoints. Explain the trusted permanent-member ACL boundary. Cover external Console rendering, portal refresh retries and teardown, and explicit IPv4/IPv6 listener exports. Preserve PublicServer discovery when saving its settings, including when its URL matches the Gateway. Cover renaming and endpoint edits in the browser. Display automatic member addresses without converting them to manual overrides during edits. Derive offline address prefixes from the network subnet. Add browser regression coverage and real-Core checks for direct configuration preservation, temporary proxy mappings, automatic subnet migration, and shutdown before device deletion. Build enrollment commands from the configured API hostname, including IPv6 and relative endpoints. Use the PublicServer connector in temporary credential CLI and TOML exports. Add browser regression coverage. Preserve form credentials across repeated normalization and GUI storage reloads. Keep explicit form values authoritative over backend keys and cover JSON persistence, idempotence, replacement, and clearing.
248 lines
7.1 KiB
Protocol Buffer
248 lines
7.1 KiB
Protocol Buffer
syntax = "proto3";
|
|
|
|
import "common.proto";
|
|
import "peer_rpc.proto";
|
|
import "api_instance.proto";
|
|
import "acl.proto";
|
|
|
|
package api.manage;
|
|
|
|
enum NetworkingMethod {
|
|
PublicServer = 0;
|
|
Manual = 1;
|
|
Standalone = 2;
|
|
}
|
|
|
|
enum ConfigSource {
|
|
ConfigSourceUnspecified = 0;
|
|
ConfigSourceUser = 1;
|
|
ConfigSourceWeb = 2;
|
|
}
|
|
|
|
message NetworkConfig {
|
|
optional string instance_id = 1;
|
|
|
|
optional bool dhcp = 2;
|
|
optional string virtual_ipv4 = 3;
|
|
optional int32 network_length = 4;
|
|
optional string hostname = 5;
|
|
optional string network_name = 6;
|
|
optional string network_secret = 7;
|
|
optional NetworkingMethod networking_method = 8;
|
|
|
|
optional string public_server_url = 9;
|
|
repeated string peer_urls = 10;
|
|
|
|
repeated string proxy_cidrs = 11;
|
|
|
|
optional bool enable_vpn_portal = 12 [deprecated = true];
|
|
optional int32 vpn_portal_listen_port = 13 [deprecated = true];
|
|
optional string vpn_portal_client_network_addr = 14 [deprecated = true];
|
|
optional int32 vpn_portal_client_network_len = 15 [deprecated = true];
|
|
|
|
optional bool advanced_settings = 16;
|
|
|
|
repeated string listener_urls = 17;
|
|
// optional int32 rpc_port = 18;
|
|
optional bool latency_first = 19;
|
|
|
|
optional string dev_name = 20;
|
|
|
|
optional bool use_smoltcp = 21;
|
|
optional bool disable_ipv6 = 47;
|
|
optional bool enable_kcp_proxy = 22;
|
|
optional bool disable_kcp_input = 23;
|
|
optional bool disable_p2p = 24;
|
|
optional bool bind_device = 25;
|
|
optional bool no_tun = 26;
|
|
|
|
optional bool enable_exit_node = 27;
|
|
optional bool relay_all_peer_rpc = 28;
|
|
optional bool multi_thread = 29;
|
|
optional bool enable_relay_network_whitelist = 30;
|
|
repeated string relay_network_whitelist = 31;
|
|
optional bool enable_manual_routes = 32;
|
|
repeated string routes = 33;
|
|
repeated string exit_nodes = 34;
|
|
optional bool proxy_forward_by_system = 35;
|
|
optional bool disable_encryption = 36;
|
|
optional bool enable_socks5 = 37;
|
|
optional int32 socks5_port = 38;
|
|
optional bool disable_udp_hole_punching = 39;
|
|
optional int32 mtu = 40;
|
|
repeated string mapped_listeners = 41;
|
|
|
|
optional bool enable_magic_dns = 42;
|
|
optional bool enable_private_mode = 43;
|
|
|
|
// repeated string rpc_portal_whitelists = 44;
|
|
|
|
optional bool enable_quic_proxy = 45;
|
|
optional bool disable_quic_input = 46;
|
|
optional int32 quic_listen_port = 50 [deprecated = true];
|
|
repeated PortForwardConfig port_forwards = 48;
|
|
|
|
optional bool disable_sym_hole_punching = 49;
|
|
|
|
optional bool p2p_only = 51;
|
|
optional common.CompressionAlgoPb data_compress_algo = 52;
|
|
optional string encryption_algorithm = 53;
|
|
optional bool disable_tcp_hole_punching = 54;
|
|
|
|
common.SecureModeConfig secure_mode = 55;
|
|
optional acl.Acl acl = 56;
|
|
optional string credential_file = 57;
|
|
optional bool lazy_p2p = 58;
|
|
optional bool need_p2p = 59;
|
|
optional uint64 instance_recv_bps_limit = 60;
|
|
optional bool disable_upnp = 61;
|
|
optional bool ipv6_public_addr_provider = 62;
|
|
optional bool ipv6_public_addr_auto = 63;
|
|
optional string ipv6_public_addr_prefix = 64;
|
|
optional bool disable_relay_data = 65;
|
|
optional bool enable_udp_broadcast_relay = 66;
|
|
optional uint32 socket_mark = 67;
|
|
repeated NetworkPeerConfig peers = 68;
|
|
optional VpnPortalConfig vpn_portal_config = 69;
|
|
repeated ManagedCredentialConfig managed_credentials = 71;
|
|
optional bool prefer_peer_relay = 72;
|
|
}
|
|
|
|
message ManagedCredentialConfig {
|
|
string credential_id = 1;
|
|
string credential_secret = 2;
|
|
repeated string groups = 3;
|
|
bool allow_relay = 4;
|
|
repeated string allowed_proxy_cidrs = 5;
|
|
int64 expiry_unix = 6;
|
|
optional bool reusable = 7;
|
|
}
|
|
|
|
message ManagedCredentialSet {
|
|
repeated ManagedCredentialConfig entries = 1;
|
|
}
|
|
|
|
message VpnPortalClientConfig {
|
|
string name = 1;
|
|
string virtual_ip = 2;
|
|
repeated string groups = 3;
|
|
}
|
|
|
|
message VpnPortalConfig {
|
|
string wireguard_listen = 1;
|
|
optional string wireguard_private_key = 2;
|
|
repeated VpnPortalClientConfig clients = 3;
|
|
// Omitted in existing configurations, where the portal is enabled.
|
|
optional bool enabled = 4;
|
|
}
|
|
|
|
message NetworkPeerConfig {
|
|
string uri = 1;
|
|
optional string peer_public_key = 2;
|
|
}
|
|
|
|
message PortForwardConfig {
|
|
string bind_ip = 1;
|
|
uint32 bind_port = 2;
|
|
string dst_ip = 3;
|
|
uint32 dst_port = 4;
|
|
string proto = 5;
|
|
}
|
|
|
|
message MyNodeInfo {
|
|
common.Ipv4Inet virtual_ipv4 = 1;
|
|
string hostname = 2;
|
|
string version = 3;
|
|
peer_rpc.GetIpListResponse ips = 4;
|
|
common.StunInfo stun_info = 5;
|
|
repeated common.Url listeners = 6;
|
|
optional string vpn_portal_cfg = 7 [deprecated = true];
|
|
uint32 peer_id = 8;
|
|
}
|
|
|
|
message NetworkInstanceRunningInfo {
|
|
string dev_name = 1;
|
|
MyNodeInfo my_node_info = 2;
|
|
repeated string events = 3;
|
|
repeated api.instance.Route routes = 4;
|
|
repeated api.instance.PeerInfo peers = 5;
|
|
repeated api.instance.PeerRoutePair peer_route_pairs = 6;
|
|
bool running = 7;
|
|
optional string error_msg = 8;
|
|
peer_rpc.RouteForeignNetworkSummary foreign_network_summary = 9;
|
|
}
|
|
|
|
message NetworkInstanceRunningInfoMap {
|
|
map<string, NetworkInstanceRunningInfo> map = 1;
|
|
}
|
|
|
|
message NetworkMeta {
|
|
common.UUID inst_id = 1;
|
|
string network_name = 2;
|
|
uint32 config_permission = 3;
|
|
string instance_name = 4;
|
|
ConfigSource source = 5;
|
|
}
|
|
|
|
message ValidateConfigRequest { NetworkConfig config = 1; }
|
|
|
|
message ValidateConfigResponse { string toml_config = 1; }
|
|
|
|
message RunNetworkInstanceRequest {
|
|
common.UUID inst_id = 1;
|
|
NetworkConfig config = 2;
|
|
bool overwrite = 3;
|
|
ConfigSource source = 4;
|
|
}
|
|
|
|
message RunNetworkInstanceResponse { common.UUID inst_id = 1; }
|
|
|
|
message RetainNetworkInstanceRequest { repeated common.UUID inst_ids = 1; }
|
|
|
|
message RetainNetworkInstanceResponse {
|
|
repeated common.UUID remain_inst_ids = 1;
|
|
}
|
|
|
|
message CollectNetworkInfoRequest { repeated common.UUID inst_ids = 1; }
|
|
|
|
message CollectNetworkInfoResponse { NetworkInstanceRunningInfoMap info = 1; }
|
|
|
|
message ListNetworkInstanceRequest {}
|
|
|
|
message ListNetworkInstanceResponse { repeated common.UUID inst_ids = 1; }
|
|
|
|
message DeleteNetworkInstanceRequest { repeated common.UUID inst_ids = 1; }
|
|
|
|
message DeleteNetworkInstanceResponse {
|
|
repeated common.UUID remain_inst_ids = 1;
|
|
}
|
|
|
|
message GetNetworkInstanceConfigRequest { common.UUID inst_id = 1; }
|
|
|
|
message GetNetworkInstanceConfigResponse {
|
|
NetworkConfig config = 1;
|
|
ConfigSource source = 2;
|
|
}
|
|
|
|
message ListNetworkInstanceMetaRequest { repeated common.UUID inst_ids = 1; }
|
|
|
|
message ListNetworkInstanceMetaResponse { repeated NetworkMeta metas = 1; }
|
|
|
|
service WebClientService {
|
|
rpc ValidateConfig(ValidateConfigRequest) returns (ValidateConfigResponse) {}
|
|
rpc RunNetworkInstance(RunNetworkInstanceRequest)
|
|
returns (RunNetworkInstanceResponse) {}
|
|
rpc RetainNetworkInstance(RetainNetworkInstanceRequest)
|
|
returns (RetainNetworkInstanceResponse) {}
|
|
rpc CollectNetworkInfo(CollectNetworkInfoRequest)
|
|
returns (CollectNetworkInfoResponse) {}
|
|
rpc ListNetworkInstance(ListNetworkInstanceRequest)
|
|
returns (ListNetworkInstanceResponse) {}
|
|
rpc DeleteNetworkInstance(DeleteNetworkInstanceRequest)
|
|
returns (DeleteNetworkInstanceResponse) {}
|
|
rpc GetNetworkInstanceConfig(GetNetworkInstanceConfigRequest)
|
|
returns (GetNetworkInstanceConfigResponse) {}
|
|
rpc ListNetworkInstanceMeta(ListNetworkInstanceMetaRequest)
|
|
returns (ListNetworkInstanceMetaResponse) {}
|
|
}
|