Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs/pangolin_config_set.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ Supported keys:
up.override_dns
up.match_domains_dns
up.prefer_local_routes
up.exit_node_takes_precedence
session_cookie_name

Examples:
Expand Down
4 changes: 3 additions & 1 deletion docs/pangolin_select_exit-node.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,9 @@ List the exit nodes in your organization and select one to route all
tunnel traffic (full tunnel) through the sites backing it.

While an exit node is active, a "None" option is shown to turn it off.
Requires a running client.

With a running client the change takes effect immediately. Without one, the
choice is saved and applied the next time you run 'pangolin up'.

```
pangolin select exit-node [flags]
Expand Down
50 changes: 26 additions & 24 deletions docs/pangolin_up.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,30 +16,32 @@ pangolin up [flags]
### Options

```
--attach Run in attached (foreground) mode, (default: detached (background) mode)
--disable-relay Disable relay connections (default false)
--endpoint string Client endpoint (required if not logged in)
--exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any)
-h, --help help for up
--holepunch Enable holepunching (default true)
--http-addr string HTTP address for API server
--id string Client ID (optional, will use user info if not provided)
--interface-name name Interface name (default "pangolin")
--log-level string Log level (default "info")
--match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set)
--mtu int Maximum transmission unit (default 1280)
--netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers.
--org string Organization ID (default: selected organization if logged in)
--override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true)
--ping-interval interval Ping interval (default 5s)
--ping-timeout timeout Ping timeout (default 5s)
--prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false)
--secret string Client secret (optional, will use user info if not provided)
--silent Disable TUI and run silently when detached
--subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false)
--tls-client-cert path TLS client certificate path
--tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server.
--upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS
--attach Run in attached (foreground) mode, (default: detached (background) mode)
--disable-relay Disable relay connections (default false)
--endpoint string Client endpoint (required if not logged in)
--exit-node-resource-id int ID of the exit node resource the --exit-node-site-ids belong to, so changes to that resource are applied while connected
--exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any). Requires --exit-node-resource-id
--exit-node-takes-precedence Do not add routes or resolve aliases for individual resources, so all traffic is sent through the exit node instead of directly to resources (default false)
-h, --help help for up
--holepunch Enable holepunching (default true)
--http-addr string HTTP address for API server
--id string Client ID (optional, will use user info if not provided)
--interface-name name Interface name (default "pangolin")
--log-level string Log level (default "info")
--match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set)
--mtu int Maximum transmission unit (default 1280)
--netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers.
--org string Organization ID (default: selected organization if logged in)
--override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true)
--ping-interval interval Ping interval (default 5s)
--ping-timeout timeout Ping timeout (default 5s)
--prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false)
--secret string Client secret (optional, will use user info if not provided)
--silent Disable TUI and run silently when detached
--subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false)
--tls-client-cert path TLS client certificate path
--tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server.
--upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS
```

### SEE ALSO
Expand Down
50 changes: 26 additions & 24 deletions docs/pangolin_up_client.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,30 +20,32 @@ pangolin up client [flags]
### Options

```
--attach Run in attached (foreground) mode, (default: detached (background) mode)
--disable-relay Disable relay connections (default false)
--endpoint string Client endpoint (required if not logged in)
--exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any)
-h, --help help for client
--holepunch Enable holepunching (default true)
--http-addr string HTTP address for API server
--id string Client ID (optional, will use user info if not provided)
--interface-name name Interface name (default "pangolin")
--log-level string Log level (default "info")
--match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set)
--mtu int Maximum transmission unit (default 1280)
--netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers.
--org string Organization ID (default: selected organization if logged in)
--override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true)
--ping-interval interval Ping interval (default 5s)
--ping-timeout timeout Ping timeout (default 5s)
--prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false)
--secret string Client secret (optional, will use user info if not provided)
--silent Disable TUI and run silently when detached
--subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false)
--tls-client-cert path TLS client certificate path
--tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server.
--upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS
--attach Run in attached (foreground) mode, (default: detached (background) mode)
--disable-relay Disable relay connections (default false)
--endpoint string Client endpoint (required if not logged in)
--exit-node-resource-id int ID of the exit node resource the --exit-node-site-ids belong to, so changes to that resource are applied while connected
--exit-node-site-ids ints Site IDs to route all traffic through as an exit node (default: the exit node saved by 'pangolin select exit-node', if any). Requires --exit-node-resource-id
--exit-node-takes-precedence Do not add routes or resolve aliases for individual resources, so all traffic is sent through the exit node instead of directly to resources (default false)
-h, --help help for client
--holepunch Enable holepunching (default true)
--http-addr string HTTP address for API server
--id string Client ID (optional, will use user info if not provided)
--interface-name name Interface name (default "pangolin")
--log-level string Log level (default "info")
--match-domains strings FQDN wildcard patterns (e.g. '*.proxy.internal') to check against local records/upstream DNS; queries for non-matching domains go directly to the system's DNS servers (default: match all domains, or the value from config if set)
--mtu int Maximum transmission unit (default 1280)
--netstack-dns server DNS server to use for Netstack. This handles DNS resolution outside of the upstream servers.
--org string Organization ID (default: selected organization if logged in)
--override-dns When enabled, the client uses custom DNS servers to resolve internal resources and aliases. This overrides your system's default DNS settings. Queries that cannot be resolved as a Pangolin resource will be forwarded to your configured Upstream DNS Server. (default true)
--ping-interval interval Ping interval (default 5s)
--ping-timeout timeout Ping timeout (default 5s)
--prefer-local-routes Add tunnel routes with a high metric so overlapping local/connected routes take precedence (default false)
--secret string Client secret (optional, will use user info if not provided)
--silent Disable TUI and run silently when detached
--subnet-router Enable this client to act as a subnet router: traffic forwarded from the local network is NATed to this client's own tunnel IP before going out over the tunnel. Linux only, requires CAP_NET_ADMIN. (default false)
--tls-client-cert path TLS client certificate path
--tunnel-dns When enabled, DNS queries are routed through the tunnel for remote resolution. To ensure queries are tunneled correctly, you must define the DNS server as a Pangolin resource and enter its address as an Upstream DNS Server.
--upstream-dns strings List of DNS servers to use for external DNS resolution if overriding system DNS
```

### SEE ALSO
Expand Down
Loading