diff --git a/src/pages/ipa/resources/services.mdx b/src/pages/ipa/resources/services.mdx index 1942072a..4cc55473 100644 --- a/src/pages/ipa/resources/services.mdx +++ b/src/pages/ipa/resources/services.mdx @@ -170,7 +170,8 @@ echo $response; "connected_proxies": 3, "supports_custom_ports": true, "require_subdomain": false, - "supports_crowdsec": false + "supports_crowdsec": false, + "private": false } ] ``` @@ -184,7 +185,8 @@ echo $response; "connected_proxies": "integer", "supports_custom_ports": "boolean", "require_subdomain": "boolean", - "supports_crowdsec": "boolean" + "supports_crowdsec": "boolean", + "private": "boolean" } ] ``` @@ -547,7 +549,8 @@ echo $response; "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -609,7 +612,11 @@ echo $response; "created_at": "2024-02-03T10:30:00Z", "certificate_issued_at": "2024-02-03T10:35:00Z", "status": "active" - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] } ] ``` @@ -646,7 +653,8 @@ echo $response; } }, "proxy_protocol": "boolean", - "session_idle_timeout": "string" + "session_idle_timeout": "string", + "direct_upstream": "boolean" } } ], @@ -699,7 +707,11 @@ echo $response; "created_at": "string", "certificate_issued_at": "string", "status": "string" - } + }, + "private": "boolean", + "access_groups": [ + "string" + ] } ] ``` @@ -751,7 +763,7 @@ echo $response; Target ID - + Target type @@ -816,6 +828,15 @@ echo $response; Idle timeout before a UDP session is reaped, as a Go duration string (e.g. "30s", "2m"). + + + + When true, the proxy dials this target via the host's network stack +instead of through its embedded NetBird client. Use for upstreams +reachable without WireGuard (public APIs, LAN services, localhost +sidecars). + + @@ -1002,6 +1023,16 @@ echo $response; + + + + When true, the service is NetBird-only — its target points at a proxy cluster, inbound peers authenticate via their WireGuard tunnel identity (no OIDC), and an ACL policy is auto-generated from access_groups to the cluster's proxy-peer group. Requires mode=http. + + + + + NetBird group IDs whose peers may reach this private service over the tunnel. Required when private=true; ignored otherwise. Mutually exclusive with bearer auth (SSO). + @@ -1037,7 +1068,8 @@ curl -X POST https://api.netbird.io/api/reverse-proxies/services \ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1093,7 +1125,11 @@ curl -X POST https://api.netbird.io/api/reverse-proxies/services \ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }' ``` @@ -1121,7 +1157,8 @@ let data = JSON.stringify({ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1177,7 +1214,11 @@ let data = JSON.stringify({ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }); let config = { method: 'post', @@ -1227,7 +1268,8 @@ payload = json.dumps({ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1283,7 +1325,11 @@ payload = json.dumps({ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }) headers = { 'Content-Type': 'application/json', @@ -1333,7 +1379,8 @@ func main() { "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1389,7 +1436,11 @@ func main() { "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }`) client := &http.Client { } @@ -1458,7 +1509,8 @@ request.body = JSON.dump({ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1514,7 +1566,11 @@ request.body = JSON.dump({ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }) response = https.request(request) puts response.read_body @@ -1546,7 +1602,8 @@ RequestBody body = RequestBody.create(mediaType, '{ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1602,7 +1659,11 @@ RequestBody body = RequestBody.create(mediaType, '{ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }'); Request request = new Request.Builder() .url("https://api.netbird.io/api/reverse-proxies/services") @@ -1650,7 +1711,8 @@ curl_setopt_array($curl, array( "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1706,7 +1768,11 @@ curl_setopt_array($curl, array( "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }', CURLOPT_HTTPHEADER => array( 'Content-Type: application/json', @@ -1751,7 +1817,8 @@ echo $response; "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -1813,7 +1880,11 @@ echo $response; "created_at": "2024-02-03T10:30:00Z", "certificate_issued_at": "2024-02-03T10:35:00Z", "status": "active" - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] } ``` ```json {{ title: 'Schema' }} @@ -1848,7 +1919,8 @@ echo $response; } }, "proxy_protocol": "boolean", - "session_idle_timeout": "string" + "session_idle_timeout": "string", + "direct_upstream": "boolean" } } ], @@ -1901,7 +1973,11 @@ echo $response; "created_at": "string", "certificate_issued_at": "string", "status": "string" - } + }, + "private": "boolean", + "access_groups": [ + "string" + ] } ``` @@ -2105,7 +2181,8 @@ echo $response; "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -2167,7 +2244,11 @@ echo $response; "created_at": "2024-02-03T10:30:00Z", "certificate_issued_at": "2024-02-03T10:35:00Z", "status": "active" - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] } ``` ```json {{ title: 'Schema' }} @@ -2202,7 +2283,8 @@ echo $response; } }, "proxy_protocol": "boolean", - "session_idle_timeout": "string" + "session_idle_timeout": "string", + "direct_upstream": "boolean" } } ], @@ -2255,7 +2337,11 @@ echo $response; "created_at": "string", "certificate_issued_at": "string", "status": "string" - } + }, + "private": "boolean", + "access_groups": [ + "string" + ] } ``` @@ -2314,7 +2400,7 @@ echo $response; Target ID - + Target type @@ -2379,6 +2465,15 @@ echo $response; Idle timeout before a UDP session is reaped, as a Go duration string (e.g. "30s", "2m"). + + + + When true, the proxy dials this target via the host's network stack +instead of through its embedded NetBird client. Use for upstreams +reachable without WireGuard (public APIs, LAN services, localhost +sidecars). + + @@ -2565,6 +2660,16 @@ echo $response; + + + + When true, the service is NetBird-only — its target points at a proxy cluster, inbound peers authenticate via their WireGuard tunnel identity (no OIDC), and an ACL policy is auto-generated from access_groups to the cluster's proxy-peer group. Requires mode=http. + + + + + NetBird group IDs whose peers may reach this private service over the tunnel. Required when private=true; ignored otherwise. Mutually exclusive with bearer auth (SSO). + @@ -2600,7 +2705,8 @@ curl -X PUT https://api.netbird.io/api/reverse-proxies/services/{serviceId} \ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -2656,7 +2762,11 @@ curl -X PUT https://api.netbird.io/api/reverse-proxies/services/{serviceId} \ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }' ``` @@ -2684,7 +2794,8 @@ let data = JSON.stringify({ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -2740,7 +2851,11 @@ let data = JSON.stringify({ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }); let config = { method: 'put', @@ -2790,7 +2905,8 @@ payload = json.dumps({ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -2846,7 +2962,11 @@ payload = json.dumps({ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }) headers = { 'Content-Type': 'application/json', @@ -2896,7 +3016,8 @@ func main() { "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -2952,7 +3073,11 @@ func main() { "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }`) client := &http.Client { } @@ -3021,7 +3146,8 @@ request.body = JSON.dump({ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -3077,7 +3203,11 @@ request.body = JSON.dump({ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }) response = https.request(request) puts response.read_body @@ -3109,7 +3239,8 @@ RequestBody body = RequestBody.create(mediaType, '{ "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -3165,7 +3296,11 @@ RequestBody body = RequestBody.create(mediaType, '{ "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }'); Request request = new Request.Builder() .url("https://api.netbird.io/api/reverse-proxies/services/{serviceId}") @@ -3213,7 +3348,8 @@ curl_setopt_array($curl, array( "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -3269,7 +3405,11 @@ curl_setopt_array($curl, array( "default": "off", "description": "CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec." } - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] }', CURLOPT_HTTPHEADER => array( 'Content-Type: application/json', @@ -3314,7 +3454,8 @@ echo $response; "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -3376,7 +3517,11 @@ echo $response; "created_at": "2024-02-03T10:30:00Z", "certificate_issued_at": "2024-02-03T10:35:00Z", "status": "active" - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] } ``` ```json {{ title: 'Schema' }} @@ -3411,7 +3556,8 @@ echo $response; } }, "proxy_protocol": "boolean", - "session_idle_timeout": "string" + "session_idle_timeout": "string", + "direct_upstream": "boolean" } } ], @@ -3464,7 +3610,11 @@ echo $response; "created_at": "string", "certificate_issued_at": "string", "status": "string" - } + }, + "private": "boolean", + "access_groups": [ + "string" + ] } ``` @@ -3809,7 +3959,8 @@ echo $response; "target_cluster": "eu.proxy.netbird.io", "supports_custom_ports": true, "require_subdomain": false, - "supports_crowdsec": false + "supports_crowdsec": false, + "supports_private": false } ] ``` @@ -3823,7 +3974,8 @@ echo $response; "target_cluster": "string", "supports_custom_ports": "boolean", "require_subdomain": "boolean", - "supports_crowdsec": "boolean" + "supports_crowdsec": "boolean", + "supports_private": "boolean" } ] ``` @@ -4070,7 +4222,8 @@ echo $response; "X-Custom-Header": "value" }, "proxy_protocol": false, - "session_idle_timeout": "2m" + "session_idle_timeout": "2m", + "direct_upstream": false } } ], @@ -4132,7 +4285,11 @@ echo $response; "created_at": "2024-02-03T10:30:00Z", "certificate_issued_at": "2024-02-03T10:35:00Z", "status": "active" - } + }, + "private": false, + "access_groups": [ + "group-engineering" + ] } ``` ```json {{ title: 'Schema' }} @@ -4167,7 +4324,8 @@ echo $response; } }, "proxy_protocol": "boolean", - "session_idle_timeout": "string" + "session_idle_timeout": "string", + "direct_upstream": "boolean" } } ], @@ -4220,7 +4378,11 @@ echo $response; "created_at": "string", "certificate_issued_at": "string", "status": "string" - } + }, + "private": "boolean", + "access_groups": [ + "string" + ] } ```