Skip to content

FM-944 — ADR and implementation: tailnet identity as the request principal #147

Description

@Andreas-Froyland

Epic: #122 · Depends on: FM-943

Context

The maintainer reaches the controller through tailscale serve, which can attach identity headers (e.g. Tailscale-User-Login) to proxied requests. The maintainer approved exploring this as the first step away from anonymous-lan-admin.

Goal

An ADR, then an opt-in mode: when requests arrive from a configured loopback serve proxy with identity headers, the principal is the tailnet user. It feeds the existing authz boundary and audit; otherwise behavior is unchanged.

Architecture reference

ADR-0003/0004; FM-105/FM-S02 (deferred auth); docs/architecture/security.md; PLAN M8.

Dependencies

FM-943

Research required

Tailscale serve identity header documentation; header spoofing risks when not behind serve.

Acceptance criteria

  • Headers trusted only from the configured loopback peer; spoofed headers from other peers are ignored and audited as evidence
  • Audit records the tailnet principal; UI shows who you are

Non-goals

  • Full M8 authentication, OIDC, per-user permissions

Tests

Header-trust unit tests, spoofing tests, audit tests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:codexAssign to Codex: logic, API, storage, backend

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions