M17: illogical control (accounts, devices, enrollment, directory) #29
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
#33 M21: push relay
jhgaylor/illogical
#30 M18: relay and end-to-end encryption
jhgaylor/illogical
#28 S15: spike before M17 (about two days)
jhgaylor/illogical
Reference
jhgaylor/illogical#29
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Depends on: #28
Blocks: #30, #33
From PLAN.md, "Control track → M17: illogical control (accounts, devices, enrollment, directory)".
crates/control, theillogical-controlbinary: axum, SQLite (Postgres optional for the hosted one), and the same release builds as the daemon.illogical-control --domain control.example.comserves the API and the web client.illogicald join https://control.example.comprints a code; approving it on a device enrolls the daemon to your account;illogicald leaveremoves it.hosts.rslist for enrolled daemons;tailscale servein front. No feature is hosted-only except billing (M22).Track overview and decisions
The daemon is the WireGuard: a useful piece of technology for one person
on their own network. This track is the Tailscale: a central service that
makes it work for people who have never heard of a tailnet, and for teams.
The code already draws the line. M4's home daemon is "a directory and
control point, never a relay": it holds the host list and provider tokens,
mints per-host tokens, and receives dial-out connections and log sync.
That is a coordination server running on geek. This track moves that role
into its own program, illogical control (
illogical-control), whichanyone can run and which we also host. Then it adds what a single home box
can't do: accounts, reaching machines behind NAT, teams, push and hosted
compute.
Decisions (2026-10-01):
illogical-controlis open source, in this repo, and the hosted one runs the same code.What control knows and doesn't:
Trust. The service distributes public keys, so a malicious control server could add a device of its own and read what it's sent. As with Tailscale's Tailnet Lock, a new device must be approved by one of the user's existing devices (the first is trusted on enrollment). Daemons only encrypt to devices carrying that approval, and team membership changes are signed by a team owner's device. Control can refuse service, but it can't read.
Order:
The launch issues (#19–#27: licence, releases, install, quickstart) come first: control is worth little if strangers can't install the daemon.
Later, not planned yet: