Commit Graph
2969 Commits
Author SHA1 Message Date
riccardom 61b5b6b1a1 Introduces support for darwing plist loading 2026-06-08 18:06:02 +02:00
riccardom b8818adc41 Adds dep for reading plist files 2026-06-08 18:06:02 +02:00
riccardom 83430c39e4 [UI] Fix for "hide" not working when propagating to parent with children 2026-06-08 18:06:02 +02:00
riccardom 47d438976e Pins feat profile retrieval to notif event 2026-06-08 18:06:02 +02:00
riccardom 3bef0fec5b [UI] Removes --disable-advanced-settings 2026-06-08 18:06:02 +02:00
riccardom be3fe6edd6 [PROTO] Removes --disable-advanced-settings 2026-06-08 18:06:02 +02:00
riccardom 04998f6a1c Removes --disable-advanced-settings
It was a typo in our meetings. the actual thing is --disable-update-settings
2026-06-08 18:06:02 +02:00
riccardom e55b64f2f7 Fixup: MDM wins. always 2026-06-08 18:06:02 +02:00
riccardom d6780522ea [UI] Aligns to "enable/disable once on change only" 2026-06-08 18:06:02 +02:00
riccardom 01a4c245a7 Enforces disable networks 2026-06-08 18:06:02 +02:00
riccardom 6355a24deb [UI] Fixup for profile enable/disable toggle
We need to align the initial state to evaluate the delta in case.

The initial state has to be "true" since the profile starts visible.
Then we receive MDM and transition the cache bool value to the actual
MDM imposed state
2026-06-08 18:06:02 +02:00
riccardom 3d4240b979 [UI] Fixup for preshared key 2026-06-08 18:06:02 +02:00
riccardom 2be7ef4929 [UI] Fixup advanced Settings 2026-06-08 18:06:02 +02:00
riccardom 6509174400 Evaluate disable-update-settings errors only when there's an actual override 2026-06-08 18:06:02 +02:00
riccardom b200f47e6d Adds Gate Login as well when --disable-update-settings=true is given to service
This commit tries to settle things with an old PR-4237 which had relaxed
the case where the SetConfig returned an `Unavailable` code error.

Under this circumnstance the PR allowed the upFunc to just emit a warning and
progress further with the login gRPC. Since the login call is consuming
the --management-url coming from the `up` command, it might be possible
to abuse the "Unavailable" code to inject a management URL that is different
from the configured one even though the --disable-update-settings is set
to true (?)
2026-06-08 18:06:02 +02:00
riccardom 1b477d39a8 Adds support for disabling of Profiles and UpdateSettings feature flags 2026-06-08 18:06:02 +02:00
riccardom 7570c5c911 Toggle gray in/out for Advanced Settings 2026-06-08 18:06:02 +02:00
riccardom bf8c8b0ea3 Apply MDM locks 2026-06-08 18:06:02 +02:00
riccardom 362efb832c Fixup presharedkey 2026-06-08 18:06:02 +02:00
riccardom 1543d43a20 Advanced Settings locking 2026-06-08 18:06:02 +02:00
riccardom cee17ebc36 Lock toggle Settngs 2026-06-08 18:06:02 +02:00
riccardom aab1a3e150 UI behavior conflicts relaxation
UI sends full config snapshot with all values. It doesn't
make sense to block it if the values are aligned with the
values constrained by the MDM policy. It's just simplier
to allow values that are compliant. (this goes for the CLI
as well at this point)
2026-06-08 18:06:02 +02:00
riccardom 1100cea6a4 Add events to resync UI to actual config
This also provide fixup for UI no aligning to changed config when coming from cli up with config flags.
2026-06-08 18:06:02 +02:00
riccardom 029e69279c Publishes event for UI to sync upon MDM changes 2026-06-08 18:06:02 +02:00
riccardom c759aed3a3 Adds also up/start after cancel 2026-06-08 18:06:02 +02:00
riccardom c36bf3a171 Adds MDM 1m diff checker & reloader 2026-06-08 18:06:02 +02:00
riccardom 08966adf30 Adds debug config cobra command
This can be useful for troubleshooting and checking config
now that its resolution is not trivial

defaults > config > env cars > CLI/UI > MDM
2026-06-08 18:06:02 +02:00
riccardom 0db22debaf Prefix every log with MDM 2026-06-08 14:37:10 +02:00
riccardom 0594f76655 Adds some log 2026-06-08 14:37:10 +02:00
riccardom 5271df5962 Align split tunnel code 2026-06-08 14:37:10 +02:00
riccardom 2d7949adfe Cleanup setupKey to align to linear 2026-06-08 14:37:10 +02:00
riccardom 451fa5e142 Adds missing WGPort config 2026-06-08 14:37:10 +02:00
riccardom 22edfdd52b Implements windows loading of MDM policy 2026-06-08 14:37:10 +02:00
riccardom df9e216370 MDM Name scoping for clarity 2026-06-08 14:37:10 +02:00
riccardom 293a93910e gRPC MDM changes 2026-06-08 14:37:10 +02:00
riccardom 66e807cc05 Adds initial 101 MDM policy business logic testing 2026-06-08 14:37:10 +02:00
riccardom 5255f5111b Add ManagedFields to returned config over GetConfig 2026-06-08 14:37:10 +02:00
riccardom 978a392453 Return error if trying to modify any config that is gated by MDM 2026-06-08 14:37:10 +02:00
riccardom 78fe7fc510 Helpers business logic 2026-06-08 14:37:10 +02:00
riccardom 3ad961c9a7 Unit tests 2026-06-08 14:37:10 +02:00
riccardom 607cb56515 Applies MDM override 2026-06-08 14:37:10 +02:00
riccardom ce0750b73a Initial scaffolding 2026-06-08 14:37:10 +02:00
Maycon Santos 60d2fa08b0 [client] Mask sensitive data in debug bundle creation (#6364)
* [client] Mask sensitive data in debug bundle creation

* Avoid nil reference in turn and use masked constant
2026-06-08 13:17:04 +02:00
Maycon Santos 1e7b16db0a [management] resolve private services on custom domains in synthesized DNS zones (#6348)
private services on a custom domain didn't resolve on clients — the synthesized DNS zone was anchored to the cluster, and the account's custom domains weren't even
  loaded.

- account.go — SynthesizePrivateServiceZones now keys zones by a resolved apex (privateServiceDomainZone): cluster suffix → registered account.Domains (filtered by matching
  TargetCluster, longest wins) → skip if none. One zone per apex; custom-domain services group under their registered domain.
- sql_store.go — GetAccount now loads account.Domains on both loaders (gorm Preload("Domains") + pgx goroutine via ListCustomDomains; errChan buffer bumped 12→16). This was
  the reason the deploy didn't work — the relation was empty in prod.
- Tests — custom-domain zone synthesis cases (apex resolution, free+custom separation, sibling collapse, cluster mismatch, mixed cluster/custom/public) + GetAccount
  domain-preload tests on sqlite and Postgres.
v0.72.2
2026-06-06 12:56:01 +02:00
Maycon Santos b377d99933 [management] Copy private field on shallowCloneMapping (#6347)
* [management] Copy private field on shallowCloneMapping

added test to ensure clone handles new fields

* Remove unnecessary debug logs from proxy service

* Increase Wasm binary size limit to 60MB in build validation
v0.72.1
2026-06-05 22:45:49 +02:00
Theodor Midtlien 512899d82d [client] Prevent corruption from competing log rotation and improve debug bundle (#6214)
* Adds heuristic to detect an edge case on Linux where a system has configured logrotate as a separate service to rotate log files which would mangle our client log files. If we detect logrotate being configured for netbird, we disable our rotation.

* Adds new env var to disable log rotation: NB_LOG_DISABLE_ROTATION

* Adds compressed and plain logrotate files to debug bundle.

* Replaces lumberjack with timberjack (maintained fork with bug fixes and extra features).

* Clarifies which daemon version is running in the bundle stats.

* Change logging for client service status to console
v0.72.0
2026-06-04 17:36:45 +02:00
Theodor Midtlien 5993ec6e43 [client] Allow wireguard port to be zero in UI and show port in status command (#6158)
* Allow wireguard port to be set to 0 in UI

* Add wireguard port to cmd status

* Correct protoc version
2026-06-04 15:04:11 +02:00
Maycon Santos eac6d501c3 [infrastructure] allow docker image overrides for getting started (#6335)
* [infrastructure] allow docker image overrides for getting started

Make dashboard and server image configurations overrideable via environment variables

* [infrastructure] update Traefik gRPC rule to include ProxyService PathPrefix

* make Traefik and CrowdSec images configurable via environment variables
2026-06-04 11:24:47 +02:00
Maycon Santos deeae30612 [misc] Add Codecov integration and coverage reporting across workflows (#6333) 2026-06-03 19:08:45 +02:00
Bethuel Mmbaga f3cdf163e1 [management] Export ResolveDomain (#6334) 2026-06-03 19:53:57 +03:00