[PR #5583] [proxy] Wildcard certificate support #28164

Closed
opened 2026-08-05 08:05:54 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/5583

State: closed
Merged: Yes


Describe your changes

With this change it is not possible to pass a directory path for wildcard certificates to the proxy with NB_PROXY_WILDCARD_CERT_DIR or --wildcard-cert-dir.

The proxy will read all the certificates in that folder and cache for the domains matching SNI.

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • New Features

    • New CLI flag to point the server at a directory of wildcard TLS certificate pairs; matching wildcard certificates are loaded and served immediately.
    • Wildcard domains served from provided certificates bypass external provisioning when applicable.
    • Background monitoring reloads updated wildcard certificates without restarting the server.
  • Tests

    • Expanded coverage for wildcard parsing, matching, loading, serving, and related edge cases.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/5583 **State:** closed **Merged:** Yes --- ## Describe your changes With this change it is not possible to pass a directory path for wildcard certificates to the proxy with `NB_PROXY_WILDCARD_CERT_DIR` or `--wildcard-cert-dir`. The proxy will read all the certificates in that folder and cache for the domains matching SNI. ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * New CLI flag to point the server at a directory of wildcard TLS certificate pairs; matching wildcard certificates are loaded and served immediately. * Wildcard domains served from provided certificates bypass external provisioning when applicable. * Background monitoring reloads updated wildcard certificates without restarting the server. * **Tests** * Expanded coverage for wildcard parsing, matching, loading, serving, and related edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 08:05:54 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28164