Add allow_match any/all mode to reverse proxy access restrictions

This commit is contained in:
Viktor Liu
2026-08-19 10:54:21 +02:00
parent 6d223042eb
commit 4efadd1e33
9 changed files with 794 additions and 385 deletions
+12
View File
@@ -3380,6 +3380,18 @@ components:
- "observe"
default: "off"
description: CrowdSec IP reputation mode. Only available when the proxy cluster supports CrowdSec.
allow_match:
type: string
enum:
- "all"
- "any"
default: "all"
description: >-
How the allowlists (allowed_cidrs, allowed_countries) combine.
"all" (default) requires a connection to match every configured
allowlist (AND); "any" requires it to match at least one (OR), e.g.
an allowed country OR an allowed CIDR. Blocklists always reject on
match regardless of this setting.
PasswordAuthConfig:
type: object
properties: