mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-03 03:59:07 +02:00
* [management] Require a private proxy cluster for cluster and direct upstream targets Cluster targets and direct upstream targets make the proxy dial the upstream from its own host network instead of through the embedded NetBird client. Only clusters running in private mode are meant to do that, but the service API accepted these targets on any cluster. Service create and update now reject such targets unless the service's proxy cluster reports the private capability. An unreported capability is treated as unsupported. * [management] Require every proxy in the cluster to be private The private capability is aggregated as any-true, so a cluster where only one proxy runs in private mode passed the check. The mapping is delivered to every proxy in the cluster, so the non-private ones would serve cluster and direct upstream targets from their host network too. Validate these targets against a unanimous aggregation instead. The existing any-true lookup stays as is for the dashboard flags and the agent network gateway.
48 lines
2.2 KiB
Go
48 lines
2.2 KiB
Go
package proxy
|
|
|
|
//go:generate go tool mockgen -package proxy -destination=manager_mock.go -source=./manager.go -build_flags=-mod=mod
|
|
|
|
import (
|
|
"context"
|
|
"time"
|
|
|
|
"github.com/netbirdio/netbird/shared/management/proto"
|
|
)
|
|
|
|
// Manager defines the interface for proxy operations
|
|
type Manager interface {
|
|
Connect(ctx context.Context, proxyID, sessionID, clusterAddress, ipAddress, version string, accountID *string, capabilities *Capabilities) (*Proxy, error)
|
|
Disconnect(ctx context.Context, proxyID, sessionID string) error
|
|
Heartbeat(ctx context.Context, p *Proxy) error
|
|
GetActiveClusterAddresses(ctx context.Context) ([]string, error)
|
|
GetActiveClusterAddressesForAccount(ctx context.Context, accountID string) ([]string, error)
|
|
ClusterSupportsCustomPorts(ctx context.Context, clusterAddr string) *bool
|
|
ClusterRequireSubdomain(ctx context.Context, clusterAddr string) *bool
|
|
ClusterSupportsCrowdSec(ctx context.Context, clusterAddr string) *bool
|
|
ClusterSupportsPrivate(ctx context.Context, clusterAddr string) *bool
|
|
ClusterAllProxiesPrivate(ctx context.Context, clusterAddr string) *bool
|
|
ClusterSupportsSessionCode(ctx context.Context, clusterAddr string) bool
|
|
CleanupStale(ctx context.Context, inactivityDuration time.Duration) error
|
|
GetAccountProxy(ctx context.Context, accountID string) (*Proxy, error)
|
|
CountAccountProxies(ctx context.Context, accountID string) (int64, error)
|
|
IsClusterAddressAvailable(ctx context.Context, clusterAddress, accountID string) (bool, error)
|
|
DeleteAccountCluster(ctx context.Context, clusterAddress, accountID string) error
|
|
}
|
|
|
|
// OIDCValidationConfig contains the OIDC configuration needed for token validation.
|
|
type OIDCValidationConfig struct {
|
|
Issuer string
|
|
Audiences []string
|
|
KeysLocation string
|
|
MaxTokenAgeSeconds int64
|
|
}
|
|
|
|
// Controller is responsible for managing proxy clusters and routing service updates.
|
|
type Controller interface {
|
|
SendServiceUpdateToCluster(ctx context.Context, accountID string, update *proto.ProxyMapping, clusterAddr string)
|
|
GetOIDCValidationConfig() OIDCValidationConfig
|
|
RegisterProxyToCluster(ctx context.Context, clusterAddr, proxyID string) error
|
|
UnregisterProxyFromCluster(ctx context.Context, clusterAddr, proxyID string) error
|
|
GetProxiesForCluster(clusterAddr string) []string
|
|
}
|