Commit Graph
10 Commits
Author SHA1 Message Date
riccardom acfa65c054 Merge remote-tracking branch 'origin/main' into fix_debug_upload_url_from_mgmt
# Conflicts:
#	management/server/activity/codes.go
#	management/server/store/sql_store.go
#	management/server/store/sql_store_test.go
#	upload-server/server/server.go
2026-09-28 10:56:27 +02:00
Philippe Vaucher 306f642ad3 [misc] Use the Silo image for the S3 upload test (#7619) 2026-09-24 17:53:30 +03:00
Bethuel Mmbaga 0a128cea6f [misc] Add upload URL signing and rate limiting (#7502) 2026-09-24 17:34:58 +03:00
riccardom 7e2b71d7f8 [misc] Bound the upload server's request timeouts
http.Server was built with only Addr and Handler, so every timeout was infinite.
Behind a reverse proxy that is survivable because the proxy has its own; serving
TLS directly, which SERVER_CERT_FILE now allows, it means a slow client can hold
a connection and its goroutine indefinitely.

ReadHeaderTimeout and IdleTimeout are short. ReadTimeout is 10 minutes: it has
to clear a 150 MiB upload on a slow link, so it is a ceiling on a stalled
connection rather than a throughput rule. WriteTimeout is deliberately left
unset for the same reason.

Reported by CodeRabbit (CWE-400) on #7514.
2026-09-14 09:20:03 +02:00
Philippe Vaucher 973173be9c [misc] Pull the MinIO test image from quay.io (#7516)
The minio/minio repository is no longer on Docker Hub: the repo and the
pinned tag both return 404 and anonymous pulls are refused, so
Test_S3HandlerGetUploadURL fails on every Linux CI run with "pull access
denied for minio/minio".

The same release is published at quay.io/minio/minio, digest
sha256:a1ea29fa28355559ef137d71fc570e508a214ec84ff8083e39bc5428980b015e,
so the testcontainers request points there and keeps the pinned tag.
2026-09-12 10:39:57 +02:00
riccardom 08718d072c [upload-server] Serve TLS when a certificate is configured
The clients refuse a plaintext upload service: they ask it for an upload URL and
then PUT the bundle to whatever comes back, so a plaintext hop exposes both. An
operator pointing their deployment at this server therefore needs it to speak
https, and until now it could only do so behind a separate terminator.

SERVER_CERT_FILE and SERVER_KEY_FILE switch it to ListenAndServeTLS. They must
be set together. Unset keeps the current plaintext listener, for a deployment
that does terminate TLS in front of it.
2026-09-10 16:38:41 +02:00
Viktor Liu 205ebcfda2 [management, client] Add IPv6 overlay support (#5631) 2026-05-07 11:33:37 +02:00
Pascal Fischer cd8c686339 [misc] add path traversal and file size protections (#5755) 2026-04-01 14:23:24 +02:00
Viktor Liu 9aaa05e8ea Replace discontinued LocalStack image with MinIO in S3 test (#5680) 2026-03-25 15:51:29 +08:00
Maycon Santos 2f44fe2e23 [client] Feature/upload bundle (#3734)
Add an upload bundle option with the flag --upload-bundle; by default, the upload will use a NetBird address, which can be replaced using the flag --upload-bundle-url.

The upload server is available under the /upload-server path. The release change will push a docker image to netbirdio/upload image repository.

The server supports using s3 with pre-signed URL for direct upload and local file for storing bundles.
2025-04-29 00:43:50 +02:00