# turnscale Tailscale-native MCP gateway with identity-based access control and SQLite audit logging. ## Architecture - **Language**: Go - **Transport**: Streamable HTTP (proxies JSON-RPC POST and SSE GET) - **Auth**: Tailscale identity via tsnet (zero credential management) - **Access Control**: YAML policy engine (user login + node tags, first-match-wins) - **Audit**: SQLite with server-rendered HTML UI at `/ui/audit` - **Dashboard**: Web UI at `/ui/` showing identity, server health, policies, audit ## Project Layout ``` cmd/turnscale/main.go # Entry point, tsnet setup, signal handling internal/config/ # YAML config parsing internal/identity/ # Tailscale WhoIs identity extraction internal/policy/ # Access control evaluation internal/audit/ # SQLite audit logger + web UI internal/gateway/ # HTTP handler, JSON-RPC proxy, SSE proxy internal/ui/ # Web dashboard (server health, policies, audit) ``` ## Build & Test ```bash go build ./cmd/turnscale go test ./... ``` ## Config `gateway.yaml` — defines servers (upstream MCP backends) and policies (ACL rules). Policies are evaluated top-to-bottom, first match wins. Default is deny. ## Key Dependencies - `tailscale.com/tsnet` — embedded Tailscale node - `modernc.org/sqlite` — pure-Go SQLite (no CGO) - `gopkg.in/yaml.v3` — config parsing ## Conventions - Conventional commits: `feat:`, `fix:`, `refactor:`, `test:`, `chore:` - Tests live next to their code (`*_test.go`) - No CGO — pure Go build for easy cross-compilation