Maycon Santos
81040ff80a
[docs] Update typo ( #3477 )
2025-03-10 11:52:36 +01:00
Maycon Santos
d8bcf745b0
update integrations
2025-03-09 19:32:38 +01:00
Maycon Santos
8430139d80
fix missing method
2025-03-09 19:03:57 +01:00
Maycon Santos
a2962b4ce0
sync go.sum
2025-03-09 18:50:20 +01:00
Maycon Santos
16fffdb75b
sync changes from #3426
2025-03-09 18:48:48 +01:00
Maycon Santos
036cecbf46
update integrations and go mod
2025-03-09 18:47:05 +01:00
Maycon Santos
3482852bb6
sync proto and sum
2025-03-09 18:02:33 +01:00
Maycon Santos
fd62665b1f
Merge branch 'main' into feature/flow
...
# Conflicts:
# client/cmd/testutil_test.go
# client/firewall/iptables/router_linux.go
# client/firewall/nftables/router_linux.go
# client/firewall/uspfilter/allow_netbird.go
# client/firewall/uspfilter/allow_netbird_windows.go
# client/firewall/uspfilter/uspfilter_test.go
# client/internal/engine.go
# client/internal/engine_test.go
# client/server/server_test.go
# go.mod
# go.sum
# management/client/client_test.go
# management/cmd/management.go
# management/proto/management.pb.go
# management/proto/management.proto
# management/server/account.go
# management/server/account_test.go
# management/server/dns_test.go
# management/server/http/handler.go
# management/server/http/testing/testing_tools/tools.go
# management/server/integrations/port_forwarding/controller.go
# management/server/management_proto_test.go
# management/server/management_test.go
# management/server/nameserver_test.go
# management/server/peer.go
# management/server/peer_test.go
# management/server/route_test.go
2025-03-09 17:42:16 +01:00
Maycon Santos
619c549547
sync port forwarding
2025-03-04 16:29:59 +01:00
Maycon Santos
9a713a0987
Merge branch 'feature/port-forwarding' into feature/flow
...
# Conflicts:
# go.mod
# go.sum
2025-03-04 16:28:57 +01:00
Maycon Santos
f6d7bccfa0
Add flow client with sender/receiver ( #3405 )
...
add an initial version of receiver client and flow manager receiver and sender
2025-02-28 17:16:18 +00:00
Maycon Santos
cccc615783
update flow proto package generated code
2025-02-28 03:09:09 +00:00
Maycon Santos
2021463ca0
update flow proto package name
2025-02-28 02:51:57 +00:00
Maycon Santos
f48cfd52e9
fix logger stop ( #3403 )
...
* fix logger stop
* use context to stop receiver
* update test
2025-02-28 00:28:17 +00:00
Maycon Santos
8276236dfa
Add netflow manager ( #3398 )
...
* Add netflow manager
* fix linter issues
2025-02-27 12:05:20 +00:00
Maycon Santos
175674749f
Add memory flow store ( #3386 )
2025-02-25 15:23:43 +00:00
Maycon Santos and snyk-bot
6554026a82
[client] fix client/Dockerfile to reduce vulnerabilities ( #3359 )
...
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-ALPINE321-MUSL-8720634
- https://snyk.io/vuln/SNYK-ALPINE321-MUSL-8720634
- https://snyk.io/vuln/SNYK-ALPINE321-OPENSSL-8690014
- https://snyk.io/vuln/SNYK-ALPINE321-OPENSSL-8690014
- https://snyk.io/vuln/SNYK-ALPINE321-OPENSSL-8710358
Co-authored-by: snyk-bot <snyk-bot@snyk.io >
2025-02-21 12:04:26 +01:00
Maycon Santos
bd381d59cd
[misc] Run management benchmark jobs on file changes ( #3343 )
...
They will always run on Main
2025-02-18 10:45:41 +01:00
Maycon Santos
46766e7e24
[misc] Update sign pipeline version ( #3246 )
2025-01-28 22:48:19 +01:00
Maycon Santos
9f4db0a953
[client] Close ice agent only if not nil ( #3210 )
2025-01-18 00:18:59 +01:00
Maycon Santos
8154069e77
[misc] Skip docker step when fork PR ( #3175 )
2025-01-13 10:11:54 +01:00
Maycon Santos
1cc88a2190
[management] adjust benchmark ( #3168 )
2025-01-11 14:08:13 +01:00
Maycon Santos
649bfb236b
[management] Send relay credentials with turn updates ( #3164 )
...
send relay credentials when sending turn credentials update to avoid removing servers
from clients
2025-01-10 09:44:02 +01:00
Maycon Santos
03fd656344
[management] Fix policy tests ( #3135 )
...
- Add firewall rule isEqual method
- Fix tests
2024-12-31 18:45:40 +01:00
Maycon Santos
1a623943c8
[management] Fix networks net map generation with posture checks ( #3124 )
2024-12-30 12:40:24 +01:00
Maycon Santos
37ad370344
[client] Avoid using iota on mixed const block ( #3057 )
...
Used the values as resolved when the first iota value was the second const in the block.
2024-12-16 18:09:31 +01:00
Maycon Santos
9eff58ae62
Upgrade x/crypto package ( #3055 )
...
Mitigates the CVE-2024-45337
2024-12-16 10:30:41 +01:00
Maycon Santos
287ae81195
[misc] split tests with management and rest ( #3051 )
...
optimize go cache for tests
2024-12-14 21:18:46 +01:00
Maycon Santos and snyk-bot
dcba6a6b7e
fix: client/Dockerfile to reduce vulnerabilities ( #3019 )
...
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8235201
- https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8235201
Co-authored-by: snyk-bot <snyk-bot@snyk.io >
2024-12-11 16:46:51 +01:00
Maycon Santos
2147bf75eb
[client] Add peer conn init limit ( #3001 )
...
Limit the peer connection initialization to 200 peers at the same time
2024-12-09 17:10:31 +01:00
Maycon Santos
e67fe89adb
Reduce max wait time to initialize peer connections ( #2984 )
...
* Reduce max wait time to initialize peer connections
setting rand time range to 100-300ms instead of 100-800ms
* remove min wait time
2024-12-05 13:03:11 +01:00
Maycon Santos
b50b89ba14
[client] Cleanup status resources on engine stop ( #2981 )
...
cleanup leftovers from status recorder when stopping the engine
2024-12-04 14:09:04 +01:00
Maycon Santos
a4826cfb5f
[client] Get static system info once ( #2965 )
...
Get static system info once for Windows, Darwin, and Linux nodes
This should improve startup and peer authentication times
2024-12-03 10:22:04 +01:00
Maycon Santos and Viktor Liu
f9723c9266
[client] Account different policiy rules for routes firewall rules ( #2939 )
...
* Account different policies rules for routes firewall rules
This change ensures that route firewall rules will consider source group peers in the rules generation for access control policies.
This fixes the behavior where multiple policies with different levels of access was being applied to all peers in a distribution group
* split function
* avoid unnecessary allocation
Co-authored-by: Viktor Liu <17948409+lixmal@users.noreply.github.com >
---------
Co-authored-by: Viktor Liu <17948409+lixmal@users.noreply.github.com >
2024-11-29 17:50:35 +01:00
Maycon Santos and Copilot
8efad1d170
Add guide when signing key is not found ( #2942 )
...
Some users face issues with their IdP due to signing key not being refreshed
With this change we advise users to configure key refresh
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* removing leftover
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2024-11-29 10:06:40 +01:00
Maycon Santos
56cecf849e
Import time package ( #2940 )
2024-11-22 20:40:30 +01:00
Maycon Santos
05c4aa7c2c
[misc] Renew slack link ( #2938 )
2024-11-22 18:50:47 +01:00
Maycon Santos
78fab877c0
[misc] Update signing pipeline version ( #2900 )
2024-11-18 15:31:53 +01:00
Maycon Santos
65a94f695f
use google domain for tests ( #2902 )
2024-11-18 12:55:02 +01:00
Maycon Santos
6886691213
Update route calculation tests ( #2884 )
...
- Add two new test cases for p2p and relay routes with same latency
- Add extra statuses generation
2024-11-13 15:21:33 +01:00
Maycon Santos
738387f2de
Add benchmark tests to get account with claims ( #2761 )
...
* Add benchmark tests to get account with claims
* add users to account objects
* remove hardcoded env
2024-11-07 17:23:35 +01:00
Maycon Santos
b952d8693d
Fix cached device flow oauth ( #2833 )
...
This change removes the cached device flow oauth info when a down command is called
Removing the need for the agent to be restarted
2024-11-05 14:51:17 +01:00
Maycon Santos
5b46cc8e9c
Avoid failing all other matrix tests if one fails ( #2839 )
2024-11-05 13:28:42 +01:00
Maycon Santos
9929b22afc
Replace suite tests with regular go tests ( #2762 )
...
* Replace file suite tests with go tests
* Replace file suite tests with go tests
2024-10-21 14:39:28 +02:00
Maycon Santos
88e4fc2245
Release global lock on early error ( #2760 )
2024-10-19 18:32:17 +02:00
Maycon Santos
c8d8748dcf
Update sign workflow version ( #2756 )
2024-10-18 17:28:58 +02:00
Maycon Santos
507a40bd7f
Fix decompress zip path ( #2755 )
...
Since 0.30.2 the decompressed binary path from the signed package has changed
now it doesn't contain the arch suffix
this change handles that
2024-10-17 20:39:59 +02:00
Maycon Santos
ccd4ae6315
Fix domain information is up to date check ( #2754 )
2024-10-17 19:21:35 +02:00
Maycon Santos
cee95461d1
[client] Add universal bin build and update sign workflow version ( #2738 )
...
* Add universal binaries build for macOS
* update sign pipeline version
* handle info.plist in sign workflow
2024-10-15 15:03:17 +02:00
Maycon Santos
da3a053e2b
[management] Refactor getAccountIDWithAuthorizationClaims ( #2715 )
...
This change restructures the getAccountIDWithAuthorizationClaims method to improve readability, maintainability, and performance.
- have dedicated methods to handle possible cases
- introduced Store.UpdateAccountDomainAttributes and Store.GetAccountUsers methods
- Remove GetAccount and SaveAccount dependency
- added tests
2024-10-12 08:35:51 +02:00
Maycon Santos
6ce09bca16
Add support to envsub go management configurations ( #2708 )
...
This change allows users to reference environment variables using Go template format, like {{ .EnvName }}
Moved the previous file test code to file_suite_test.go.
2024-10-09 20:46:23 +02:00
Maycon Santos
8934453b30
Update management base docker image ( #2687 )
2024-10-02 19:29:51 +03:00
Maycon Santos
b7b0828133
[client] Adjust relay worker log level and message ( #2683 )
2024-10-02 15:14:09 +02:00
Maycon Santos
a3a479429e
Use the pkgs to get the latest version ( #2682 )
...
* Use the pkgs to get the latest version
* disable fail fast
2024-10-02 11:48:42 +02:00
Maycon Santos
5932298ce0
Add log setting to Caddy container ( #2684 )
...
This avoids full disk on busy systems
2024-10-02 11:48:09 +02:00
Maycon Santos
e27f85b317
Update docker creds ( #2677 )
2024-09-30 20:07:21 +02:00
Maycon Santos
5bc601111d
[relay] Add health check attempt threshold ( #2609 )
...
* Add health check attempt threshold for receiver
* Add health check attempt threshold for sender
2024-09-17 10:04:17 +02:00
Maycon Santos
fa7767e612
Fix get management and signal state race condition ( #2570 )
...
* Fix get management and signal state race condition
* fix get full status lock
2024-09-15 16:07:26 +02:00
Maycon Santos
f6d57e7a96
[misc] Support configurable max log size with var NB_LOG_MAX_SIZE_MB ( #2592 )
...
* Support configurable max log size with var NB_LOG_MAX_SIZE_MB
* add better logs
2024-09-12 19:56:55 +02:00
Maycon Santos
4c130a0291
Update Go version to 1.23 ( #2588 )
2024-09-12 13:46:28 +02:00
Maycon Santos
afb9673bc4
[misc] Update core github actions ( #2584 )
2024-09-11 21:49:05 +02:00
Maycon Santos
c59a39d27d
Update service package version ( #2582 )
2024-09-11 19:05:10 +02:00
Maycon Santos
47adb976f8
Remove pre-release step from workflow ( #2583 )
2024-09-11 18:59:19 +02:00
Maycon Santos and snyk-bot
51e1d3ab8f
fix: client/Dockerfile to reduce vulnerabilities ( #2548 )
...
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-ALPINE319-OPENSSL-7895536
- https://snyk.io/vuln/SNYK-ALPINE319-OPENSSL-7895536
Co-authored-by: snyk-bot <snyk-bot@snyk.io >
2024-09-09 18:44:37 +02:00
Maycon Santos
28248ea9f4
add TestRecreation test ( #2558 )
2024-09-09 14:44:46 +02:00
Maycon Santos
a7e46bf7b1
Reduce test logs ( #2550 )
2024-09-06 16:28:19 +02:00
Maycon Santos
a33b11946d
[misc] Update slack url ( #2544 )
...
* Update slack url
* correct url
2024-09-05 22:28:31 +02:00
Maycon Santos
bdbd1db843
[client] Avoid panic when there is no conn client ( #2541 )
2024-09-05 15:09:46 +02:00
Maycon Santos
c52b406afa
[client] Avoid deadlock when auto connect and early exit ( #2528 )
2024-09-04 19:22:33 +02:00
Maycon Santos
95174d4619
Update route API doc with max domain number ( #2516 )
2024-09-02 17:40:34 +02:00
Maycon Santos
880b81154f
Use new sign pipeline ( #2490 )
2024-08-28 14:46:35 +02:00
Maycon Santos
7efaf7eadb
[client] Use static requested GUID when creating Windows interface ( #2479 )
...
RequestedGUID is the GUID of the created network adapter, which then influences NLA generation deterministically.
With this change, NetBird should not generate multiple interfaces in every restart on Windows.
2024-08-27 19:21:14 +02:00
Maycon Santos
63a75d72fc
[misc] Test infrastructure files generation with postgres store ( #2478 )
2024-08-27 16:38:42 +02:00
Maycon Santos
be6bc46bcd
Update sign pipeline version to 0.0.13 ( #2477 )
2024-08-23 19:37:20 +02:00
Maycon Santos and Viktor Liu
ddea001170
[client] Refactor free port function ( #2455 )
...
Rely on net.ListenUDP to get an available port for wireguard in case the configured one is in use
---------
Co-authored-by: Viktor Liu <17948409+lixmal@users.noreply.github.com >
2024-08-21 19:24:40 +02:00
Maycon Santos
5d6dfe5938
Add test for SetFlagsFromEnvVars ( #2460 )
2024-08-21 12:11:45 +02:00
Maycon Santos
a6c59601f9
Update Slack invite link ( #2445 )
2024-08-18 14:19:31 +02:00
Maycon Santos
9716be854d
[client] Upgrade fyne version to fix freezing routes window ( #2417 )
2024-08-13 16:20:06 +02:00
Maycon Santos
af1b42e538
[client] Parse data from setup key ( #2411 )
...
refactor functions and variable assignment
2024-08-09 20:38:58 +02:00
Maycon Santos
54d896846b
Skip network map check if not regular user ( #2402 )
...
when getting all peers we don't need to calculate network map when not a regular user
2024-08-07 10:22:12 +02:00
Maycon Santos
1802e51213
Fix windows binary version ( #2390 )
2024-08-05 11:03:14 +02:00
Maycon Santos
059fc7c3a2
Use docker compose command ( #2382 )
...
replace calls to docker-compose with docker compose
2024-08-03 20:15:19 +02:00
Maycon Santos
e6f7222034
Fix Windows file version ( #2380 )
...
Systems that validates the binary version didn't like the build number as we set
This fixes the versioning and will use a static build number
2024-08-02 18:07:57 +02:00
Maycon Santos
bfc33a3f6f
Move Bundle to before netbird down ( #2377 )
...
This allows to get interface and route information added by the agent
2024-08-02 14:54:37 +02:00
Maycon Santos
cbf9f2058e
Use accountID retrieved from the sync call to acquire read lock sooner ( #2369 )
...
Use accountID retrieved from the sync call to acquire read lock sooner and avoiding extra DB calls.
- Use the account ID across sync calls
- Moved account read lock
- Renamed CancelPeerRoutines to OnPeerDisconnected
- Added race tests
2024-08-01 16:21:43 +02:00
Maycon Santos
5ee9c77e90
Move write peer lock ( #2364 )
...
Moved the write peer lock to avoid latency caused by disk access
Updated the method CancelPeerRoutines to use the peer public key
2024-07-31 21:51:45 +02:00
Maycon Santos
165988429c
Add write lock for peer when saving its connection status ( #2359 )
2024-07-31 14:53:32 +02:00
Maycon Santos
da39c8bbca
Refactor login with store.SavePeer ( #2334 )
...
This pull request refactors the login functionality by integrating store.SavePeer. The changes aim to improve the handling of peer login processes, particularly focusing on synchronization and error handling.
Changes:
- Refactored login logic to use store.SavePeer.
- Added checks for login without lock for login necessary checks from the client and utilized write lock for full login flow.
- Updated error handling with status.NewPeerLoginExpiredError().
- Moved geoIP check logic to a more appropriate place.
- Removed redundant calls and improved documentation.
- Moved the code to smaller methods to improve readability.
2024-07-29 13:30:27 +02:00
Maycon Santos
ea3205643a
Save daemon address on service install ( #2328 )
2024-07-26 16:33:20 +02:00
Maycon Santos
1f48fdf6ca
Add SavePeer method to prevent a possible account inconsistency ( #2296 )
...
SyncPeer was storing the account with a simple read lock
This change introduces the SavePeer method to the store to be used in these cases
2024-07-26 07:49:05 +02:00
Maycon Santos
45fd1e9c21
add save peer status test for connected peers ( #2321 )
2024-07-25 16:22:04 +02:00
Maycon Santos
268e801ec5
Ignore network monitor checks for software interfaces ( #2302 )
...
ignore checks for Teredo and ISATAP interfaces
2024-07-22 19:44:15 +02:00
Maycon Santos
788f130941
Retry management connection only on context canceled ( #2301 )
2024-07-22 15:49:25 +02:00
Maycon Santos
926e11b086
Remove default allow for UDP on unmatched packet ( #2300 )
...
This fixes an issue where UDP rules were ineffective for userspace clients (Windows/macOS)
2024-07-22 15:35:17 +02:00
Maycon Santos
c815ad86fd
Fix macOS DNS unclean shutdown restore call on startup ( #2286 )
...
previously, we called the restore method from the startup when there was an unclean shutdown. But it never had the state keys to clean since they are stored in memory
this change addresses the issue by falling back to default values when restoring the host's DNS
2024-07-18 18:06:09 +02:00
Maycon Santos
c900fa81bb
Remove copy functions from signal ( #2285 )
...
remove migration function for wiretrustee directories to netbird
2024-07-18 12:15:14 +02:00
Maycon Santos
9a6de52dd0
Check if route interface is a Microsoft ISATAP device ( #2282 )
...
check if the nexthop interfaces are Microsoft ISATAP devices and ignore their suffixes when comparing them
2024-07-17 23:49:09 +02:00
Maycon Santos and Viktor Liu
19147f518e
Add faster availability DNS probe and update test domain to .com ( #2280 )
...
* Add faster availability DNS probe and update test domain to .com
- Count success queries and compare it before doing after network map probes.
- Reduce the first dns probe to 500ms
- Updated test domain with com instead of . due to Palo alto DNS proxy server issues
* use fqdn
* Update client/internal/dns/upstream.go
Co-authored-by: Viktor Liu <17948409+lixmal@users.noreply.github.com >
---------
Co-authored-by: Viktor Liu <17948409+lixmal@users.noreply.github.com >
2024-07-17 23:48:37 +02:00
Maycon Santos
668d229b67
Fix metric label typo ( #2278 )
2024-07-16 16:55:57 +02:00
Maycon Santos
7c595e8493
Add get_registration_delay_milliseconds metric ( #2275 )
2024-07-16 15:36:51 +02:00