From c86c47d1e2b87f49e0734f80925f8f224501d11d Mon Sep 17 00:00:00 2001 From: Owen Date: Wed, 30 Sep 2026 09:54:08 -0400 Subject: [PATCH] Update docs --- docs/pangolin_config_set.md | 1 + docs/pangolin_select_exit-node.md | 4 ++- docs/pangolin_up.md | 50 ++++++++++++++++--------------- docs/pangolin_up_client.md | 50 ++++++++++++++++--------------- 4 files changed, 56 insertions(+), 49 deletions(-) diff --git a/docs/pangolin_config_set.md b/docs/pangolin_config_set.md index 4f71938..5af1965 100644 --- a/docs/pangolin_config_set.md +++ b/docs/pangolin_config_set.md @@ -15,6 +15,7 @@ Supported keys: up.override_dns up.match_domains_dns up.prefer_local_routes + up.exit_node_takes_precedence session_cookie_name Examples: diff --git a/docs/pangolin_select_exit-node.md b/docs/pangolin_select_exit-node.md index 0b963ce..e2b0d16 100644 --- a/docs/pangolin_select_exit-node.md +++ b/docs/pangolin_select_exit-node.md @@ -8,7 +8,9 @@ List the exit nodes in your organization and select one to route all tunnel traffic (full tunnel) through the sites backing it. While an exit node is active, a "None" option is shown to turn it off. -Requires a running client. + +With a running client the change takes effect immediately. Without one, the +choice is saved and applied the next time you run 'pangolin up'. ``` pangolin select exit-node [flags] diff --git a/docs/pangolin_up.md b/docs/pangolin_up.md index c05b63e..63e52c2 100644 --- a/docs/pangolin_up.md +++ b/docs/pangolin_up.md @@ -16,30 +16,32 @@ pangolin up [flags] ### Options ``` - --attach Run in attached (foreground) mode, (default: detached (background) mode) - --disable-relay Disable relay connections (default false) - --endpoint string Client endpoint (required if not logged in) - --exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any) - -h, --help help for up - --holepunch Enable holepunching (default true) - --http-addr string HTTP address for API server - --id string Client ID (optional, will use user info if not provided) - --interface-name name Interface name (default "pangolin") - --log-level string Log level (default "info") - --match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set) - --mtu int Maximum transmission unit (default 1280) - --netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers. - --org string Organization ID (default: selected organization if logged in) - --override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true) - --ping-interval interval Ping interval (default 5s) - --ping-timeout timeout Ping timeout (default 5s) - --prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false) - --secret string Client secret (optional, will use user info if not provided) - --silent Disable TUI and run silently when detached - --subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false) - --tls-client-cert path TLS client certificate path - --tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server. - --upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS + --attach Run in attached (foreground) mode, (default: detached (background) mode) + --disable-relay Disable relay connections (default false) + --endpoint string Client endpoint (required if not logged in) + --exit-node-resource-id int ID of the exit node resource the --exit-node-site-ids belong to, so changes to that resource are applied while connected + --exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any). Requires --exit-node-resource-id + --exit-node-takes-precedence Do not add routes or resolve aliases for individual resources, so all traffic is sent through the exit node instead of directly to resources (default false) + -h, --help help for up + --holepunch Enable holepunching (default true) + --http-addr string HTTP address for API server + --id string Client ID (optional, will use user info if not provided) + --interface-name name Interface name (default "pangolin") + --log-level string Log level (default "info") + --match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set) + --mtu int Maximum transmission unit (default 1280) + --netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers. + --org string Organization ID (default: selected organization if logged in) + --override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true) + --ping-interval interval Ping interval (default 5s) + --ping-timeout timeout Ping timeout (default 5s) + --prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false) + --secret string Client secret (optional, will use user info if not provided) + --silent Disable TUI and run silently when detached + --subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false) + --tls-client-cert path TLS client certificate path + --tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server. + --upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS ``` ### SEE ALSO diff --git a/docs/pangolin_up_client.md b/docs/pangolin_up_client.md index dd079b8..646632f 100644 --- a/docs/pangolin_up_client.md +++ b/docs/pangolin_up_client.md @@ -20,30 +20,32 @@ pangolin up client [flags] ### Options ``` - --attach Run in attached (foreground) mode, (default: detached (background) mode) - --disable-relay Disable relay connections (default false) - --endpoint string Client endpoint (required if not logged in) - --exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any) - -h, --help help for client - --holepunch Enable holepunching (default true) - --http-addr string HTTP address for API server - --id string Client ID (optional, will use user info if not provided) - --interface-name name Interface name (default "pangolin") - --log-level string Log level (default "info") - --match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set) - --mtu int Maximum transmission unit (default 1280) - --netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers. - --org string Organization ID (default: selected organization if logged in) - --override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true) - --ping-interval interval Ping interval (default 5s) - --ping-timeout timeout Ping timeout (default 5s) - --prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false) - --secret string Client secret (optional, will use user info if not provided) - --silent Disable TUI and run silently when detached - --subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false) - --tls-client-cert path TLS client certificate path - --tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server. - --upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS + --attach Run in attached (foreground) mode, (default: detached (background) mode) + --disable-relay Disable relay connections (default false) + --endpoint string Client endpoint (required if not logged in) + --exit-node-resource-id int ID of the exit node resource the --exit-node-site-ids belong to, so changes to that resource are applied while connected + --exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any). Requires --exit-node-resource-id + --exit-node-takes-precedence Do not add routes or resolve aliases for individual resources, so all traffic is sent through the exit node instead of directly to resources (default false) + -h, --help help for client + --holepunch Enable holepunching (default true) + --http-addr string HTTP address for API server + --id string Client ID (optional, will use user info if not provided) + --interface-name name Interface name (default "pangolin") + --log-level string Log level (default "info") + --match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set) + --mtu int Maximum transmission unit (default 1280) + --netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers. + --org string Organization ID (default: selected organization if logged in) + --override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true) + --ping-interval interval Ping interval (default 5s) + --ping-timeout timeout Ping timeout (default 5s) + --prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false) + --secret string Client secret (optional, will use user info if not provided) + --silent Disable TUI and run silently when detached + --subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false) + --tls-client-cert path TLS client certificate path + --tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server. + --upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS ``` ### SEE ALSO