/** * The single declaration of the tunnel provider axis. * * Every provider-specific fact lives here exactly once: the display label, the legacy * credential key, where the public entry comes from, whether the local runtime can start * it, and the extra parameters the settings form renders. The API serves this catalog to * the UI, so the settings page looks a fact up instead of keeping its own copy of the * provider list (the drift between those copies is what produced the audit's N09). */ export declare const TUNNEL_PROVIDER_IDS: readonly ["ngrok", "cloudflare", "sakura_frp", "frp"]; export type TunnelProviderId = (typeof TUNNEL_PROVIDER_IDS)[number]; export type ActiveTunnelProvider = TunnelProviderId | 'none'; /** * Where a provider's public entry comes from: * - `discovered`: the provider reports it (ngrok agent API / logs), so nobody types it. * - `declared`: it is a fact of the provider's own console, so an operator may declare it * for display and DNS diagnostics — a declaration is never proof that it is reachable. */ export type TunnelEndpointSource = 'discovered' | 'declared'; export interface TunnelProviderParameterField { key: string; label: string; } export interface TunnelProviderDescriptor { id: TunnelProviderId; label: string; /** Legacy provider-scoped credential key, still honoured for single-profile setups. */ legacyCredentialEnvKey: string; /** Legacy env keys that used to declare this provider's public entry. */ legacyPublicUrlKeys: readonly string[]; endpointSource: TunnelEndpointSource; /** * Who decides which local port the tunnel forwards to. * * `runtime` means we dial the provider, so the port is ours to choose; `console` means the * provider console holds that value and the operator has to copy this runtime's ingress * address into it. The settings page renders the copy affordance from this fact instead of * branching on a provider id. */ originOwner: 'runtime' | 'console'; /** * Where the operator creates or edits this provider's tunnel. * * The settings page links to it, because a remotely-managed tunnel's origin (port) is a * fact of that console: the operator copies this runtime's ingress address there. */ consoleUrl?: string; /** Whether the local runtime has an implementation that can actually start it. */ runtimeSupported: boolean; parameterFields: readonly TunnelProviderParameterField[]; } export declare const TUNNEL_PROVIDERS: readonly TunnelProviderDescriptor[]; /** Normalizes any stored/legacy spelling onto the canonical provider vocabulary. */ export declare function parseTunnelProvider(value: unknown): ActiveTunnelProvider | undefined; export declare function isTunnelProviderId(value: unknown): value is TunnelProviderId; export declare function tunnelProviderDescriptor(id: unknown): TunnelProviderDescriptor | undefined; export declare function tunnelProviderIds(): TunnelProviderId[]; /** Credential key namespace for one profile, so two profiles never share a secret. */ export declare const TUNNEL_PROFILE_CREDENTIAL_PREFIX = "XPOD_TUNNEL_PROFILE_"; /** Env key holding one profile's credential; the `_TOKEN` suffix keeps it secret-classified. */ export declare function tunnelProfileCredentialEnvKey(profileId: string): string; export declare function isTunnelProfileCredentialEnvKey(key: string): boolean;