Commit Graph
20 Commits
Author SHA1 Message Date
Jack Carter 82f3d74b54 docs: reverse proxy protocols, path prefix matching, active TCP services (#1007)
* docs: reverse proxy protocols, path prefix matching, active TCP services

Add a protocol support section: WebSocket, SSE and HTTP/2 in HTTP mode,
HTTP/1.1 toward cleartext targets (no h2c), and which mode fits gRPC
with and without TLS. Explain that path prefixes match as text, that the
matched prefix is stripped unless Preserve Full Path is on, and how a
trailing slash matches a whole segment. Add a troubleshooting entry for
an active TCP service whose backend does not answer.

* docs: split path matching from prefix stripping, tighten wording

Move the path-matching notes after the existing overview sentence they
were interrupting, and split them into matching (and the trailing-slash
form) and prefix stripping (and Preserve Full Path). Merge two
overlapping sentences on the upstream HTTP version, and shorten the
troubleshooting cause and solution.

* docs: point the active-TCP troubleshooting entry at the listener check

Step 3 of the checklist is an HTTP request, which cannot confirm a TCP
backend such as SSH or RDP; step 6 checks the listening socket and bind
address on the target host.
2026-09-28 16:44:43 +02:00
Nicolas Frati b86cb6e8d3 docs: add Reverse Proxy on OpenShift guide (#990)
* docs: add Reverse Proxy on OpenShift guide

Add a guide for running the NetBird reverse proxy on OpenShift with the
rootless UBI image under the restricted-v2 SCC. It covers the proxy
Deployment with self-managed ACME certificates on a PVC, exposure via a
TCP LoadBalancer or TLS-passthrough Routes, wiring a backend through a
routing peer, verification, and troubleshooting.

Adds the page to the Reverse Proxy sidebar and cross-links it from the
overview and Bring Your Own Proxy pages.

* docs: simplify OpenShift proxy guide

Drop the version availability note and the amd64 node restriction since
the rootless UBI proxy image is published for both AMD64 and ARM64, and
replace the interactive token prompt with plain export statements.

* docs: restructure OpenShift proxy guide and add http-01 variation

Make the guide easier to follow for reverse proxy operators:
- Put the LoadBalancer vs passthrough Route decision and the resource
  footprint up front.
- Source the management address from the Secret and drop hardcoded
  namespaces so the manifests apply without edits.
- Add checkpoints after each step and move alternatives (cert-manager,
  replicas, upgrades, removal) into an "Operating the proxy" section.
- Document http-01 with the UBI image's :8081 challenge listener and why
  it requires the LoadBalancer exposure.

Fixes from a test deployment on OpenShift 4.17 with the PR build of the
UBI proxy image:
- Add pkgs.netbird.io (geolocation database) to the egress requirements.
- Show how to switch a pending LoadBalancer Service back to ClusterIP.
- Describe the periodic PROTOCOL_ERROR reconnect symptom of a management
  idle timeout separately from gRPC routing failures.
- Note that autocert handshake warnings during first issuance are expected.
2026-09-28 09:47:01 +02:00
Jack Carter 62baad95a1 docs: standardize on "NetBird client" over "agent" for the client software (#940)
* docs: standardize on "NetBird client" over "agent" for the client software

* docs: address review feedback

- fix "a software" grammar and use lowercase "NetBird client"
- define routing peer as a peer whose client bridges, keeping peer and client distinct
- correct kernel-space claim: the kernel WireGuard data path is what runs in the kernel
- clarify which address the application uses to reach the SOCKS5 proxy from a separate container
2026-08-21 13:24:33 +02:00
Bruno Mercier CostaandClaude Opus 4.8 a6c4910479 Note that reverse proxy access rules combine with AND by default (#863)
Clarify in "Step 3b: Configure access control" that access restrictions
of different types (IP CIDR, country, CrowdSec) are combined with a
logical AND by default: a connection must satisfy all of them.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 09:42:01 +02:00
Jack CarterandBrandon Hopkins 8824f4af97 docs: reorganize Use Cases navigation (#834)
* docs: consolidate scenario guides under /use-cases with redirects

Move 11 pages: feature-nested use cases from manage/networks,
manage/network-routes, manage/reverse-proxy, and the Kubernetes
integration into /use-cases/remote-access, /use-cases/cloud, and
/use-cases/security; the site-to-site decision page becomes
/use-cases/remote-access; the MikroTik guide becomes an install
guide at /get-started/install/mikrotik.

Add one redirect per moved page and flatten existing redirect
chains so every legacy URL resolves in a single hop. The
deprecated Routes site-to-site recipe stays put.

* docs: rebuild sidebar navigation for use-cases reorg

Remove the four nested Use Cases sublists from Manage NetBird;
keep the deprecated Routes recipe as a direct 'Site-to-Site
(legacy)' link. Rebuild USE CASES with Remote Access, Cloud &
Kubernetes, Security groups and a flat Homelab link. Add MikroTik
to Get Started > Platforms.

* docs: rebuild use-case index pages and refresh feature landing links

Turn /use-cases into an "I want to..." scenario finder. Retitle
the site-to-site decision page to Remote Access and point its
links at the new sibling URLs. Add the Kubernetes service and
private-proxy guides to the cloud and security indexes, refresh
the homelab landing links, and update the Networks, Routes,
Reverse Proxy, and Kubernetes landing pages to the new use-case
URLs.

* docs: update internal links to new use-case URLs

Point cross-links across the docs at the consolidated
/use-cases URLs. Links to the deprecated Routes site-to-site
recipe and all image paths under public/docs-static are left
unchanged.

* docs: shorten sidebar label to Site-to-Site

* docs: move Kubernetes into its own Use Cases section

Pull the entire Kubernetes integration out of Manage > Integrations
into a dedicated Kubernetes group under Use Cases at /use-cases/
kubernetes, and move the two Kubernetes cloud guides there too.
Rename the Cloud group (was 'Cloud & Kubernetes'); Integrations
keeps the MDM deployment pages. Add redirects for every moved page
and flatten existing chains.

* docs: drop 'NetBird on' prefix from cloud sidebar labels

* docs: alphabetize Remote Access use cases in sidebar

* ❯ add mikrotik to install index

* docs: fix duplicated word in remote-access link label on TV install pages

---------

Co-authored-by: Brandon Hopkins <brandon@techhut.tv>
2026-07-08 10:20:12 +02:00
Jack Carter 9311271386 docs: add "Private Proxy Without Public Inbound Ports" use case (#803)
Document running a BYOP proxy in private mode with no public inbound
ports by disabling proxy ACME, issuing the wildcard TLS certificate
externally over DNS-01, and serving it as a static certificate that the
proxy hot-reloads on renewal.

Adds the page under reverse-proxy/use-cases with a new Use Cases nav
group, plus cross-links from the Bring Your Own Proxy page (port-443
prerequisite + TLS table) and the Reverse Proxy overview (static cert
mode).
2026-07-06 19:05:10 -07:00
Maycon SantosandTechHutTV c2ccdf43e0 Documented NetBird-Only Access and Proxy Cluster features in reverse … (#767)
* Documented NetBird-Only Access and Proxy Cluster features in reverse proxy settings. Updated authentication methods, backend configuration guides, and cluster capability requirements.

* Expanded documentation for NetBird-Only services, updated Access Control baseline behavior, added details on Direct Upstream and Proxy Cluster features, and refined cluster capability descriptions.

* add private services diagrams and update auth screenshot

* Document ProxyService gRPC routes and expand reverse proxy configuration details

---------

Co-authored-by: TechHutTV <brandon@techhut.tv>
2026-06-05 08:16:03 -07:00
Bruno Mercier CostaandAshley Mensah 357c431103 Update Reverse Proxy Main (#659)
* Update Reverse Proxy Main

- Adapted Availability to only mention Beta access
- Adapted support of pre-shared keys, and only mention Rosenpass not being supported

* re-add reverse proxy beta note

---------

Co-authored-by: Ashley Mensah <ashleyamo982@gmail.com>
2026-04-21 14:48:45 +02:00
Viktor Liu b2602add87 Add CrowdSec IP reputation documentation (#698) 2026-04-16 18:06:43 +02:00
f169522dde Document L4 service modes, header authentication, and access restrictions (#666)
---------

Co-authored-by: Brandon Hopkins <brandon@techhut.tv>
Co-authored-by: Ashley Mensah <ashleyamo982@gmail.com>
2026-04-01 11:22:04 +02:00
Brandon Hopkins 85e12be9ff Add Reverse Proxy Troubleshooting Page & Clean Up Availability Notes (#672)
* Add troubleshoot page and remove availability notes

* Added Debugging with the Proxy Debug Endpoint

* localhost is unreachable and packet capture
2026-03-30 09:50:01 -07:00
Brandon Hopkins 515c809bbf Edit Availability Note (#662) 2026-03-19 14:25:15 +01:00
shuuri-labs 8680e5e822 Document TLS-ALPN-01 challenge requirements for reverse proxy (#656) 2026-03-16 15:26:52 +01:00
shuuri-labsandBrandon Hopkins b35d3ce6c8 Add backend service configuration guide trusted proxies and fix images (#639)
* Add backend service configuration guide for reverse proxy trusted proxies

Many self-hosted services (Jellyfin, Home Assistant, Nextcloud, Plex)
require a "trusted proxies" or "known hosts" setting when behind a
reverse proxy. With NetBird, the proxy's IP is a dynamic NetBird IP
from 100.64.0.0/10 that can change on restart, so hardcoding it breaks.

This adds a new doc page with the recommended solution (trust the full
CGNAT range), per-service config examples, Docker bridge network
guidance, and a warning on the reverse proxy overview page.

* Update service-configuration.mdx and move/add images

* Fixing typos

---------

Co-authored-by: Brandon Hopkins <brandon@techhut.tv>
2026-02-27 20:27:30 +01:00
Maycon SantosandBrandon Hopkins 13ec8c817a add expose command (#633)
* add expose command

* Fix peer groups steo

* Update CLI documentation with examples and clarifications for flags

* update docs

---------

Co-authored-by: Brandon Hopkins <brandon@techhut.tv>
2026-02-24 10:02:39 +01:00
shuuri-labs 9c74c1b26e Update (external) reverse proxy docs (#624)
- update (external) reverse proxy docs, added 'external' terminology to avoid confusion with the new internal reverse proxy feature
- add templates for combined container setups
- clearer clarifications (3478 needs to be publicy accessible etc)
2026-02-19 19:08:08 +01:00
shuuri-labs d49f899db1 Reverse Proxy - Multiple Instances (#620) 2026-02-19 13:14:43 +01:00
Brandon Hopkins 8da42f59ff Add Temp Diagram and Fix Sidebar Nav (#613) 2026-02-17 21:31:10 +01:00
shuuri-labs bca8559980 Reverse proxy amendments 2 (#616)
* Reverse Proxy Doc Amendments

- update custom domains page to more closely reflect wording in the UI, added screenshots
- add warning to index page that reverse proxy feature does not currently work with pre-shared keys/rosenpass

* Update navigation order (move reverse proxy below network routes)

* update migration guide to mention the need for TWO cname records (proxy and proxy wildcard)
2026-02-17 14:37:37 +01:00
shuuri-labs 432602e35e Add Reverse Proxy documentation and update self-hosted quickstart (#594)
- Add Reverse Proxy docs: overview, custom domains, authentication, access logs
- Add Reverse Proxy section to sidebar navigation
- Update self-hosted quickstart for new getting-started.sh (Traefik default, combined server)
2026-02-13 19:07:01 +01:00