Commit Graph
953 Commits
Author SHA1 Message Date
Diego Noguês b81837a364 feat: adding traefik and proxy component to getting-started 2026-02-12 11:16:37 +01:00
Viktor Liu bd47f44c63 Preload services targets 2026-02-12 16:04:55 +08:00
Viktor Liu 381260911b Create unique token per proxy 2026-02-12 15:48:35 +08:00
pascal 418377842e fix tests 2026-02-12 02:00:22 +01:00
pascal 917035f8e8 fix tests 2026-02-12 01:52:30 +01:00
pascal e20b969188 fix linter issues 2026-02-12 01:02:13 +01:00
pascal 1c7059ee67 fix some tests 2026-02-12 00:16:33 +01:00
pascal 22a3365658 fix rename errors and tests 2026-02-11 22:34:50 +01:00
pascal 08ab1e3478 rename reverse proxy to services 2026-02-11 21:39:51 +01:00
pascal ebb1f4007d add id to request log search 2026-02-11 19:25:23 +01:00
pascal e020950cfd concat host and path for search and add a status filter 2026-02-11 17:54:29 +01:00
pascal 5bcdf36377 fix source_ip 2026-02-11 16:50:27 +01:00
pascal 1ffe8deb10 add general search filter 2026-02-11 16:38:31 +01:00
pascal d069145bd1 add more filters 2026-02-11 16:23:52 +01:00
pascal fb4cc37a4a add pagination for access logs 2026-02-11 14:41:52 +01:00
pascal 55b8d89a79 add rate limiting for callback endpoint 2026-02-11 13:42:54 +01:00
pascal b79adb706c add services to permissions list 2026-02-11 10:38:20 +01:00
mlsmaycon eea6120cd0 refactor: add ValidateSession gRPC and streamline test setup
- Add ValidateSession gRPC method for proxy-side user validation
- Move group access validation from REST callback to gRPC layer
- Capture user info in access logs via CapturedData mutable pointer
- Create validate_session_test.go for gRPC validation tests
- Simplify auth_callback_integration_test.go to create accounts
  programmatically instead of using SQL file
- SQL test data file now only used by validate_session_test.go
2026-02-10 20:31:03 +01:00
pascal 0cb02bd906 fix path handling + extract targets to separate table + guard resource/peer deletion 2026-02-10 17:12:34 +01:00
mlsmaycon b16d63643c Add group-based access control for SSO reverse proxy authentication
Implement user group validation during OAuth callback to ensure users
belong to allowed distribution groups before granting access to reverse
proxies. This provides account isolation and fine-grained access control.

Key changes:
- Add ValidateUserGroupAccess to ProxyServiceServer for group membership checks
- Redirect denied users to error page with access_denied parameter
- Handle OAuth error responses in proxy middleware
- Add comprehensive integration tests for auth callback flow
2026-02-10 16:25:00 +01:00
pascal a803f47685 add network map support for clustering 2026-02-10 14:29:20 +01:00
pascal 9e5fa11792 handle multiple path 2026-02-09 19:25:30 +01:00
pascal 1ff75acb31 handle default ports 2026-02-09 19:23:39 +01:00
pascal 1754160686 handle default ports 2026-02-09 19:21:43 +01:00
pascal 423f6266fb handle default ports 2026-02-09 18:18:53 +01:00
pascal 16d1b4a14a handle default ports 2026-02-09 18:15:26 +01:00
pascal 9a67a8e427 send updates on changes 2026-02-09 17:06:04 +01:00
pascal be5f30225a fix embedded exception 2026-02-09 15:28:48 +01:00
pascal 7467e9fb8c use portrange 2026-02-09 14:46:23 +01:00
pascal 2390c2e46e change network map calc to inject proxy policies 2026-02-09 14:41:22 +01:00
mlsmaycon 778c223176 fix api handler path 2026-02-09 02:30:06 +01:00
mlsmaycon 36cd0dd85c temp fix import cycle 2026-02-09 02:10:21 +01:00
mlsmaycon 09a1d5a02d rename endpoint 2026-02-09 01:48:51 +01:00
Viktor Liu 1c8f92a96f Fix management nil pointer 2026-02-08 23:29:16 +08:00
Viktor Liu 2cf00dba58 Fix missing route 2026-02-08 21:36:55 +08:00
Viktor Liu dc26a5a436 Merge branch 'main' into prototype/reverse-proxy 2026-02-08 17:50:16 +08:00
Viktor Liu 7c647dd160 Add peer firewall to the receiving peer 2026-02-08 17:49:03 +08:00
Viktor Liu 0a3a9f977d Add proxy <-> management authentication 2026-02-08 14:33:27 +08:00
mlsmaycon 2f263bf7e6 fix cluster logic for domains and reverse proxy 2026-02-07 11:43:01 +01:00
mlsmaycon f65f4fc280 fix some conflicts regression 2026-02-06 20:39:17 +01:00
Zoltan Papp 3be16d19a0 [management] Feature/grpc debounce msgtype (#5239)
* Add gRPC update debouncing mechanism

Implements backpressure handling for peer network map updates to
efficiently handle rapid changes. First update is sent immediately,
subsequent rapid updates are coalesced, ensuring only the latest
update is sent after a 1-second quiet period.

* Enhance unit test to verify peer count synchronization with debouncing and timeout handling

* Debounce based on type

* Refactor test to validate timer restart after pending update dispatch

* Simplify timer reset for Go 1.23+ automatic channel draining

Remove manual channel drain in resetTimer() since Go 1.23+ automatically
drains the timer channel when Stop() returns false, making the
select-case pattern unnecessary.
2026-02-06 19:47:38 +01:00
Vlad af8f730bda [management] check stream start time for connecting peer (#5267) 2026-02-06 18:00:43 +01:00
pascal 0419834482 add routed exposed services support in nmap 2026-02-06 15:42:13 +01:00
pascal 0e00f1c8f7 Merge remote-tracking branch 'origin/prototype/reverse-proxy-clusters' into prototype/reverse-proxy
# Conflicts:
#	management/internals/modules/reverseproxy/manager/manager.go
#	management/internals/modules/reverseproxy/reverseproxy.go
#	management/internals/server/modules.go
#	management/internals/shared/grpc/proxy.go
#	management/server/http/handler.go
#	management/server/http/testing/testing_tools/channel/channel.go
2026-02-05 15:19:57 +01:00
mlsmaycon 5ccce1ab3f add debug logging for proxy connections and domain resolution
- Log proxy address and cluster info when proxy connects
  - Log connected proxy URLs when GetConnectedProxyURLs is called
  - Log proxy allow list when GetDomains is called
  - Helps debug issues with free domains not appearing in API response
2026-02-05 02:18:38 +01:00
pascal d09c69f303 fix scan sql 2026-02-04 21:05:25 +01:00
pascal 096d4ac529 rewrite peer creation and network map calc [WIP] 2026-02-04 20:01:00 +01:00
Alisdair MacLeod 694ae13418 add stateless proxy sessions 2026-02-04 16:52:35 +00:00
Alisdair MacLeod a0005a604e fix minor potential security issues with OIDC 2026-02-04 12:25:19 +00:00
Alisdair MacLeod 562923c600 management OIDC implementation using pkce 2026-02-04 11:51:46 +00:00