Files
wild-central/CLAUDE.md
Paul Payne 68d6fde80d Show routes, TLS certs, and port-forwarding on services page
- Add Routes model to services UI (paths, headers, IP whitelisting per route)
- Show TLS cert info per service with inline provision/renew actions
- Remove TLS Certificates section from dashboard (now on services page)
- Make gateway router port list dynamic from config + VPN state
- Add TODO for header validation in HAProxy config generation
2026-07-10 06:10:40 +00:00

3.5 KiB

CLAUDE.md

Project Overview

Wild Central is the networking and coordination platform for the Wild product family. It runs as a standalone service on a local network device (e.g., Raspberry Pi) and manages:

  • DNS (dnsmasq) — internal name resolution + optional DHCP
  • Gateway (HAProxy) — L4 SNI passthrough + L7 HTTP reverse proxy with TLS termination
  • Firewall (nftables) — host firewall rules
  • VPN (WireGuard) — remote access with peer management
  • TLS (certbot) — certificate provisioning via DNS-01
  • Tunnels (cloudflared) — outbound-only public exposure via Cloudflare
  • DDNS (Cloudflare) — A record + CNAME management
  • Security (CrowdSec) — intrusion detection
  • NATS JetStream — coordination bus for service registration, presence, and events
  • Service Registration — the contract API for Wild Cloud and Wild Works

Architecture

Wild Central is a Go service that manages Linux networking daemons via config file generation and systemctl commands. It provides an HTTP API and an embedded NATS JetStream server.

Consumers:

  • Wild Cloud — registers k8s instance domains for L4 SNI passthrough
  • Wild Works — registers services for L7 HTTP reverse proxy with TLS termination

Both connect to Central's NATS (port 4222) or use the HTTP API (port 5055) to register services.

Development

make dev    # Run with live reloading (requires air)
make build  # Build binary
make test   # Run tests
make check  # Lint + test

Environment Variables

  • WILD_CENTRAL_DATA_DIR — Data directory (default: /var/lib/wild-central)
  • WILD_CENTRAL_PORT — API listen port (default: 5055)
  • WILD_CENTRAL_NATS_PORT — NATS listen port (default: 4222)
  • WILD_CENTRAL_DNSMASQ_CONFIG_PATH — dnsmasq config path
  • WILD_CENTRAL_HAPROXY_CONFIG_PATH — HAProxy config path
  • WILD_CENTRAL_NFTABLES_RULES_PATH — nftables rules path
  • WILD_CENTRAL_VPN_CONFIG_PATH — WireGuard config path
  • WILD_CENTRAL_CORS_ORIGINS — Allowed CORS origins
  • WILD_CENTRAL_STATIC_DIR — Web UI static files directory
  • WILD_CENTRAL_VITE_URL — Vite dev server URL for frontend proxying

Data Directory

Runtime state is persisted in {WILD_CENTRAL_DATA_DIR}/:

  • state.yaml — operator, domain, firewall, DDNS, DHCP settings (managed via API)
  • secrets.yaml — API tokens and credentials
  • services/ — per-domain service registration files
  • nats/ — embedded NATS JetStream data
  • instances/ — Wild Cloud instance configs

Service Registration API

The key abstraction. Services register with Central to get DNS, proxy, TLS, and public exposure.

POST   /api/v1/services              Register a service
GET    /api/v1/services              List all services
GET    /api/v1/services/{name}       Get service details
PATCH  /api/v1/services/{name}       Update service
DELETE /api/v1/services/{name}       Deregister service

Service payload

{
  "domain": "my-api.payne.io",
  "source": "wild-works",
  "backend": {
    "address": "192.168.8.60:9001",
    "type": "http",
    "health": "/health"
  },
  "public": false,
  "tls": "terminate"
}

Backend types

  • tcp-passthrough — L4, SNI routing, backend handles TLS (Wild Cloud k8s)
  • http — L7, Central terminates TLS with wildcard cert (Wild Works services)
  • static — L7, static file serving (Wild Works frontends)

Public

  • false (default) — LAN-visible only (DNS + proxy + TLS)
  • true — internet-visible (+ DDNS or tunnel exposure)