[PR #6396] [MERGED] [management] fix L4 service update when no custom port #28161

Closed
opened 2026-08-05 08:05:53 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6396
Author: @mlsmaycon
Created: 6/10/2026
Status: Merged
Merged: 6/10/2026
Merged by: @mlsmaycon

Base: mainHead: fix/l4-service-update-when-no-custom-ports


📝 Commits (2)

  • 4c11737 [management] fix L4 service update when no custom port
  • e4778ed Use svc suffix

📊 Changes

2 files changed (+219 additions, -5 deletions)

View changed files

📝 management/internals/modules/reverseproxy/service/manager/l4_port_test.go (+189 -0)
📝 management/internals/modules/reverseproxy/service/manager/manager.go (+30 -5)

📄 Description

Describe your changes

This fixes an issue where L4 service update is not possible when proxy clusters don't support custom ports

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes

    • Preserve existing L4 listen ports during updates when custom ports aren’t supported
    • Reject disallowed listen-port changes on unsupported clusters while allowing unchanged ports
    • Allow TLS (SNI-routed) services to change ports despite cluster restrictions
    • Detect and reject port conflicts; auto-assign ports when none provided
  • Tests

    • Added comprehensive L4 port validation tests covering preservation, rejection, TLS exemption, conflict rejection, auto-assignment, and table-driven capability cases

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6396 **Author:** [@mlsmaycon](https://github.com/mlsmaycon) **Created:** 6/10/2026 **Status:** ✅ Merged **Merged:** 6/10/2026 **Merged by:** [@mlsmaycon](https://github.com/mlsmaycon) **Base:** `main` ← **Head:** `fix/l4-service-update-when-no-custom-ports` --- ### 📝 Commits (2) - [`4c11737`](https://github.com/netbirdio/netbird/commit/4c11737e5c59ab9795f8fdc22d821d4f462724aa) [management] fix L4 service update when no custom port - [`e4778ed`](https://github.com/netbirdio/netbird/commit/e4778ed5263b566f8f7dd49d16fb1d9fa411dd51) Use svc suffix ### 📊 Changes **2 files changed** (+219 additions, -5 deletions) <details> <summary>View changed files</summary> 📝 `management/internals/modules/reverseproxy/service/manager/l4_port_test.go` (+189 -0) 📝 `management/internals/modules/reverseproxy/service/manager/manager.go` (+30 -5) </details> ### 📄 Description ## Describe your changes This fixes an issue where L4 service update is not possible when proxy clusters don't support custom ports ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Preserve existing L4 listen ports during updates when custom ports aren’t supported * Reject disallowed listen-port changes on unsupported clusters while allowing unchanged ports * Allow TLS (SNI-routed) services to change ports despite cluster restrictions * Detect and reject port conflicts; auto-assign ports when none provided * **Tests** * Added comprehensive L4 port validation tests covering preservation, rejection, TLS exemption, conflict rejection, auto-assignment, and table-driven capability cases <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:05:53 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28161