docs: add NB_PROXY_DIRECT_UPSTREAM_BLOCK_PRIVATE to proxy env var reference (#1011)

Documents the opt-in guard from netbirdio/netbird#7913 that refuses
Direct Upstream dials to non-publicly-routable addresses.
This commit is contained in:
Brad Ison
2026-10-02 14:05:19 +02:00
committed by GitHub
parent ca2634d77d
commit 15fb59df47
@@ -758,6 +758,7 @@ The proxy is configured through environment variables (each one maps to an equiv
| `NB_PROXY_SUPPORTS_CUSTOM_PORTS` | No | Whether the proxy can bind arbitrary ports for UDP/TCP passthrough. | `true` |
| `NB_PROXY_REQUIRE_SUBDOMAIN` | No | Require a subdomain label in front of the cluster domain. | `false` |
| `NB_PROXY_PRIVATE` | No | Serve private services with NetBird-Only authentication, reachable exclusively over the WireGuard tunnel (also enables per-account inbound listeners). Required for the **Proxy Cluster** target type and **NetBird-Only Access**. The `netbirdio/reverse-proxy` image runs in embedded mode by default, so setting this on a standard self-hosted deployment is supported: the cluster then reports the `Private` capability and the dashboard **Clusters** page shows a **Private** badge. | `false` |
| `NB_PROXY_DIRECT_UPSTREAM_BLOCK_PRIVATE` | No | Refuse **Direct Upstream** dials to addresses that are not publicly routable (loopback, RFC 1918, CGNAT, link-local including cloud metadata services, ULA, multicast, and reserved ranges). Hostnames are checked after DNS resolution. Refused requests return `502 Destination Not Allowed`. Enable this on proxies that serve untrusted accounts; leave it off if services need to reach LAN or localhost backends. Tunneled traffic through peers is unaffected. | `false` |
| `NB_PROXY_MAX_DIAL_TIMEOUT` | No | Cap the per-service backend dial timeout (`0` = no cap), e.g. `10s`. | `0` |
| `NB_PROXY_MAX_SESSION_IDLE_TIMEOUT` | No | Cap the per-service session idle timeout (`0` = no cap), e.g. `5m`. | `0` |