Add allow_match any/all mode to reverse proxy access restrictions

This commit is contained in:
Viktor Liu
2026-07-24 18:18:40 +02:00
parent 1e5b0a5c89
commit 40cdfda878
9 changed files with 794 additions and 385 deletions
+12
View File
@@ -3379,6 +3379,18 @@ components:
- "observe"
default: "off"
description: CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec.
allow_match:
type: string
enum:
- "all"
- "any"
default: "all"
description: >-
How the allowlists (allowed_cidrs, allowed_countries) combine.
"all" (default) requires a connection to match every configured
allowlist (AND); "any" requires it to match at least one (OR), e.g.
an allowed country OR an allowed CIDR. Blocklists always reject on
match regardless of this setting.
PasswordAuthConfig:
type: object
properties: