diff --git a/main.go b/main.go index 9d20e24..a29338f 100644 --- a/main.go +++ b/main.go @@ -74,6 +74,7 @@ type upstream struct { name string backend *url.URL prometheus bool + funnel bool } type target struct { @@ -98,6 +99,8 @@ func parseUpstreamFlag(fval string) (upstream, error) { switch opt { case "prometheus": up.prometheus = true + case "funnel": + up.funnel = true default: return upstream{}, fmt.Errorf("unsupported option: %v", opt) } @@ -257,6 +260,15 @@ func tsproxy(ctx context.Context) error { if err != nil { return fmt.Errorf("tailscale: wait for node %s to be ready: %w", upstream.name, err) } + + if upstream.funnel { + ln, err := ts.ListenFunnel("tcp", ":443") + if err != nil { + return fmt.Errorf("tailscale: listen for %s on port 443: %w", upstream.name, err) + } + return srv.Serve(ln) + } + ln, err := ts.Listen("tcp", ":443") if err != nil { return fmt.Errorf("tailscale: listen for %s on port 443: %w", upstream.name, err) diff --git a/tsproxy_test.go b/tsproxy_test.go index c86c629..2ca7b6e 100644 --- a/tsproxy_test.go +++ b/tsproxy_test.go @@ -50,6 +50,10 @@ func TestParseUpstream(t *testing.T) { upstream: "test=http://localhost;prometheus", want: upstream{name: "test", backend: mustParseURL("http://localhost"), prometheus: true}, }, + { + upstream: "test=http://localhost;funnel;prometheus", + want: upstream{name: "test", backend: mustParseURL("http://localhost"), prometheus: true, funnel: true}, + }, { upstream: "test=http://localhost;foo", want: upstream{},