Administration — portal generation –
Agents — an agent's addresses are the site's device pools
| ID | Name | Address | Port | Endpoint | Public key | Applied gen | Sync | Last seen | Last error | |
Temporary access — lets a user reach the portal from one address before they have a tunnel
| ID | Source | Note | Added by | Expires | |
Users — read from Authentik, put into access groups here
| Username | Name | Email | Access groups | Devices |
Access | Last synced |
Who is on this list is Authentik's answer and cannot be changed here. Which access
groups they are in is the portal's, and is changed here. Someone removed from the Authentik
groups, or deactivated there, has their devices deleted on the next pass and
their tunnel drops with it. That is not reversible: rejoining brings nothing back, they register
a device again and download a new config. Their access groups do come back, because those say
what the person is meant to reach and that does not stop being true while they are away.
Access groups — what a member reaches, decided here and not in Authentik
| Name | Description | Targets | Members | |
Targets — a named set of destinations, opened on every port
| Name | Description | Destinations | Carried by | |
A target is addresses and nothing else, so it opens the machines in it on every
port, SSH included. A narrower grant is a narrower target.
reading the policy…
A device whose owner is in no group at all is left alone and reaches
what it reached before any of this existed. Putting someone in a group is therefore the moment
their access narrows to that group. Everyone reaches the internet, and reaches
nothing regardless of their groups.
All devices
| ID | Name | Owner | Public key | Address |
Tunnel subnet | |