Files
rustunnel/droid-wiki/features/connection-keys.md
T
rootandfactory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com> 0166fb6511
CI / cargo fmt (push) Has been cancelled
CI / cargo clippy (macos-latest) (push) Has been cancelled
CI / cargo clippy (ubuntu-latest) (push) Has been cancelled
CI / cargo clippy (windows-latest) (push) Has been cancelled
CI / cargo test (macos-latest) (push) Has been cancelled
CI / cargo test (ubuntu-latest) (push) Has been cancelled
CI / cargo test (windows-latest) (push) Has been cancelled
CI / cargo build (macos-latest) (push) Has been cancelled
CI / cargo build (ubuntu-latest) (push) Has been cancelled
CI / cargo build (windows-latest) (push) Has been cancelled
CI / cargo build --release (macos-latest) (push) Has been cancelled
CI / cargo build --release (ubuntu-latest) (push) Has been cancelled
CI / cargo build --release (windows-latest) (push) Has been cancelled
CI / CLI smoke (macos-latest) (push) Has been cancelled
CI / CLI smoke (ubuntu-latest) (push) Has been cancelled
CI / CLI smoke (windows-latest) (push) Has been cancelled
CI / Minimal E2E (macos-latest) (push) Has been cancelled
CI / Minimal E2E (ubuntu-latest) (push) Has been cancelled
CI / Minimal E2E (windows-latest) (push) Has been cancelled
docs: add comprehensive project wiki for v1.0
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
2026-06-04 14:07:55 -06:00

2.1 KiB

Connection keys

A connection key bundles all credential material and the target address into a single copy-pasteable string.

Purpose

Simplify distribution of tunnel credentials between machines. Instead of transferring eight separate files, a user can generate one key and paste it into the listen and connect commands.

Format

Connection keys start with the prefix rtun1. followed by base64url-encoded (no padding) JSON:

{
  "version": 1,
  "target": "198.51.100.10:4180",
  "ca_cert_pem": "-----BEGIN CERTIFICATE-----...",
  "server_cert_pem": "-----BEGIN CERTIFICATE-----...",
  "server_key_pem": "-----BEGIN PRIVATE KEY-----...",
  "client_cert_pem": "-----BEGIN CERTIFICATE-----...",
  "client_key_pem": "-----BEGIN PRIVATE KEY-----...",
  "auth_token": "a1b2c3..."
}

Key abstractions

Type File Description
ConnectionKey src/connkey.rs Struct with all fields, version check, validation
ConnectionKey::encode src/connkey.rs Serialize to JSON, base64url-encode, prepend prefix
ConnectionKey::decode src/connkey.rs Strip prefix, base64url-decode, deserialize, validate
looks_like_connection_key src/connkey.rs Quick check if a string starts with rtun1.

Validation

decode validates:

  • Prefix must be rtun1.
  • Base64 decoding must succeed
  • JSON deserialization must succeed
  • Version must be exactly 1
  • All string fields must be non-empty after trimming

Integration

src/main.rs uses ConnectionKey::decode when the --connection-key flag or positional argument is provided. The decoded material is passed to ServerTlsMaterial::Pem or ClientTlsMaterial::Pem variants, which bypass file loading and use the embedded PEM strings directly.

Entry points for modification

  • To change the key format or add versioning: modify src/connkey.rs.
  • To add compression or encryption: consider extending the encode/decode pipeline in ConnectionKey.

Key source files

File Purpose
src/connkey.rs Connection key struct, encoding, decoding, validation