diff --git a/content/docs/self-host/advanced/config-file.mdx b/content/docs/self-host/advanced/config-file.mdx
index 65cef1a..300c4d9 100644
--- a/content/docs/self-host/advanced/config-file.mdx
+++ b/content/docs/self-host/advanced/config-file.mdx
@@ -38,12 +38,6 @@ server:
allowed_headers: ["X-CSRF-Token", "Content-Type"]
credentials: false
-# Optional organization network settings (defaults shown):
-# orgs:
-# block_size: 24
-# subnet_group: "100.90.128.0/20"
-# utility_subnet_group: "100.96.128.0/20"
-
flags:
require_email_verification: false
disable_signup_without_invite: true
@@ -305,6 +299,40 @@ This section contains the complete reference for all configuration options in `c
+
+ IP ranges, in CIDR format, of the upstream proxies or load balancers that Badger trusts to supply the real client IP.
+
+ **Example**: `["10.0.0.0/8", "172.16.0.0/12"]`
+
+ **Default**: `[]`
+
+
+ By default Badger trusts Cloudflare's IP ranges and reads the client IP from the `CF-Connecting-IP` header. Setting one or more ranges here replaces the Cloudflare ranges, so only the ranges you list are trusted. Use this when a proxy other than Cloudflare sits in front of Pangolin.
+
+
+
+ Only list addresses of proxies you control. Any request arriving from a trusted range can set the client IP that Pangolin uses for rules and logging.
+
+
+
+
+ Name of the HTTP header Badger reads the real client IP from when a request arrives from a trusted IP range.
+
+ **Example**: `X-Real-Ip`
+
+ **Default**: `""` (uses `CF-Connecting-IP`)
+
+
+ The header is only honored for requests from a trusted source: the ranges in `trust_ips`, or Cloudflare's ranges when `trust_ips` is empty. The header value is used as-is, so choose a header your proxy sets to a single IP address. If the header is missing, Badger falls back to `CF-Connecting-IP` and then to the connection's remote address.
+
+
+ ```yaml
+ server:
+ trust_ips: ["10.0.0.0/8"]
+ custom_ip_header: "X-Real-Ip"
+ ```
+
+
Whether to have Badger stamp the resolved client IP into a dedicated `X-Pangolin-Client-Ip` header on the site-resource AI Gateway route.