mirror of
https://github.com/netbirdio/docs.git
synced 2026-10-09 23:29:04 +02:00
Document the client local metrics endpoint (#952)
This commit is contained in:
@@ -60,7 +60,7 @@ stale residue on the device.
|
||||
|
||||
## Policy keys reference
|
||||
|
||||
The same 16 keys apply on every platform. Names are camelCase in the
|
||||
The same 20 keys apply on every platform. Names are camelCase in the
|
||||
managed-configuration payload; the Windows ADMX template renders the
|
||||
PascalCase variant in the Group Policy Editor — both are recognized.
|
||||
|
||||
@@ -82,6 +82,8 @@ PascalCase variant in the Group Policy Editor — both are recognized.
|
||||
| `disableUpdateSettings` | boolean | Block every configuration change from UI or CLI on this device (read-only mode). |
|
||||
| `disableProfiles` | boolean | Hide the profile menu in the GUI and reject profile CRUD via CLI. |
|
||||
| `disableNetworks` | boolean | Hide the Networks / Exit Node menus in the GUI and reject the related RPCs. |
|
||||
| `enableLocalMetrics` | boolean | Expose the client's [local Prometheus `/metrics` endpoint](/client/local-metrics). |
|
||||
| `localMetricsAddress` | string | Listen address of the local `/metrics` endpoint (default `127.0.0.1:9191`). |
|
||||
| `splitTunnelMode` | string | `allow` or `disallow` — split-tunnel policy mode (Android only at the client level; harmless on desktop). |
|
||||
| `splitTunnelApps` | string | Comma-separated list of package names that the split-tunnel mode applies to (Android only). |
|
||||
|
||||
@@ -100,6 +102,11 @@ PascalCase variant in the Group Policy Editor — both are recognized.
|
||||
See [Enforcing the Exit Node on Managed Devices](/use-cases/remote-access/exit-nodes#enforcing-the-exit-node-on-managed-devices)
|
||||
for the full recipe, including why the policy must be deployed
|
||||
before users touch the exit node switch.
|
||||
- `localMetricsAddress` is applied as pushed. Users are held to a
|
||||
loopback address unless they are root, because the endpoint is
|
||||
unauthenticated, but a policy already comes from an administrator and
|
||||
is not subject to that check. A non-loopback address publishes peer
|
||||
names and connectivity state to anything that can reach the port.
|
||||
- `splitTunnelMode` and `splitTunnelApps` are wired into Android's
|
||||
`VpnService.Builder.addAllowedApplication()` flow; on Windows and
|
||||
macOS the daemon parses the keys but ignores them. They are safe to
|
||||
|
||||
Reference in New Issue
Block a user