mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-09 23:19:11 +02:00
* [management,signal] Make the Let's Encrypt challenge listener address configurable With Let's Encrypt enabled and --port set to something other than 443, signal and management also opened a separate challenge listener that was hard-coded to :443. Non-root deployments, such as the UBI images, could not start that listener. Add --letsencrypt-listen-address to both. It defaults to :443, so current behavior is unchanged. An empty value disables the separate listener for setups that forward public port 443 to --port, where the main TLS listener already answers TLS-ALPN-01 challenges. Signal now fails on startup when the challenge listener cannot bind, and exits non-zero when a server stops unexpectedly instead of exiting 0. A failure reported before the run loop waited was previously dropped. Management no longer opens a new :443 listener on shutdown just to close it. * [management,signal] Keep the challenge listener change additive Remove the Signal fail-fast changes from this PR. They change the behavior that existing installations see after an upgrade, so they move to a separate PR. If the challenge listener cannot bind, Signal now logs the error and continues. The main TLS listener still answers TLS-ALPN-01 challenges. Management keeps its previous behavior and stops with an error. The check for an empty address moves to the caller, so the function does not return a nil listener with a nil error. Also add assertion messages, guard a nil listener in a test cleanup, and add the flag to the Signal README.
56 lines
1.7 KiB
Go
56 lines
1.7 KiB
Go
package server
|
|
|
|
import (
|
|
"context"
|
|
"net"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
"golang.org/x/crypto/acme/autocert"
|
|
|
|
nbconfig "github.com/netbirdio/netbird/management/internals/server/config"
|
|
)
|
|
|
|
func newLetsEncryptTestServer(address string) *BaseServer {
|
|
srv := NewServer(&Config{NbConfig: &nbconfig.Config{}, MgmtPort: 8443, LetsEncryptListenAddress: address})
|
|
srv.certManager = &autocert.Manager{}
|
|
return srv
|
|
}
|
|
|
|
func TestServeLetsEncryptChallenges_Disabled(t *testing.T) {
|
|
srv := newLetsEncryptTestServer("")
|
|
|
|
require.NoError(t, srv.serveLetsEncryptChallenges(context.Background()))
|
|
require.Nil(t, srv.certListener, "no challenge listener should be created when the address is empty")
|
|
}
|
|
|
|
func TestServeLetsEncryptChallenges_CustomAddress(t *testing.T) {
|
|
srv := newLetsEncryptTestServer("127.0.0.1:0")
|
|
ctx, cancel := context.WithCancel(context.Background())
|
|
t.Cleanup(func() {
|
|
cancel()
|
|
if srv.certListener != nil {
|
|
_ = srv.certListener.Close()
|
|
}
|
|
srv.wg.Wait()
|
|
})
|
|
|
|
require.NoError(t, srv.serveLetsEncryptChallenges(ctx))
|
|
require.NotNil(t, srv.certListener, "challenge listener should be created on the configured address")
|
|
|
|
conn, err := net.DialTimeout("tcp", srv.certListener.Addr().String(), time.Second)
|
|
require.NoError(t, err)
|
|
require.NoError(t, conn.Close())
|
|
}
|
|
|
|
func TestServeLetsEncryptChallenges_BindFailure(t *testing.T) {
|
|
occupied, err := net.Listen("tcp", "127.0.0.1:0")
|
|
require.NoError(t, err)
|
|
t.Cleanup(func() { _ = occupied.Close() })
|
|
srv := newLetsEncryptTestServer(occupied.Addr().String())
|
|
|
|
require.Error(t, srv.serveLetsEncryptChallenges(context.Background()))
|
|
require.Nil(t, srv.certListener, "no challenge listener should be stored when the bind fails")
|
|
}
|