[PR #6872] [MERGED] [management] Force routing-peer DNS resolution for reverse-proxy domain targets #29177

Closed
opened 2026-08-05 08:07:35 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6872
Author: @lixmal
Created: 7/23/2026
Status: Merged
Merged: 7/28/2026
Merged by: @lixmal

Base: mainHead: force-routing-peer-dns-reverse-proxy


📝 Commits (3)

  • 753d80f Force routing-peer DNS resolution for reverse-proxy domain targets
  • 7e44f7f Only force DNS resolution for domain-type resources
  • 18f1df4 Merge branch 'main' into force-routing-peer-dns-reverse-proxy

📊 Changes

9 files changed (+170 additions, -6 deletions)

View changed files

📝 management/internals/shared/grpc/components_envelope_response.go (+1 -1)
📝 management/internals/shared/grpc/conversion.go (+4 -4)
📝 management/internals/shared/grpc/conversion_test.go (+34 -0)
📝 management/internals/shared/grpc/server.go (+1 -1)
📝 management/server/types/account.go (+48 -0)
📝 management/server/types/account_components.go (+2 -0)
📝 management/server/types/account_test.go (+68 -0)
📝 shared/management/types/network.go (+5 -0)
📝 shared/management/types/networkmap_components.go (+7 -0)

📄 Description

Describe your changes

Reverse-proxy services that target a domain network resource rely on DNS resolution happening on the routing peer, but that only occurs when the account-global "DNS via routing peer" setting is enabled. This forces routing-peer DNS resolution on per-peer for the peers involved in a reverse-proxy domain target, so the feature works without requiring the account-wide setting.

  • Force the flag on for embedded reverse-proxy client peers so they route domain DNS to the resolving peer instead of resolving locally
  • Force the flag on for peers that route a domain network resource targeted by an enabled reverse-proxy service, so their DNS forwarder starts
  • Carry the decision on the per-peer network map so both the streaming and initial-sync paths emit it, leaving the account-global setting untouched

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Internal behavior change: no user-facing setting or API surface is added; the existing account setting is unchanged.

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • New Features

    • Routing peers can now automatically enable DNS resolution when required for reverse-proxy domain targets.
    • DNS resolution behavior is propagated through network maps and generated peer configuration in sync/login responses.
    • A new per-network-map override can force DNS resolution beyond the account-wide setting.
  • Bug Fixes

    • Improved DNS resolution behavior for embedded peers and explicitly routed scenarios.
  • Tests

    • Added unit tests covering combinations of global/override settings, embedded behavior, and domain-targeted resources.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6872 **Author:** [@lixmal](https://github.com/lixmal) **Created:** 7/23/2026 **Status:** ✅ Merged **Merged:** 7/28/2026 **Merged by:** [@lixmal](https://github.com/lixmal) **Base:** `main` ← **Head:** `force-routing-peer-dns-reverse-proxy` --- ### 📝 Commits (3) - [`753d80f`](https://github.com/netbirdio/netbird/commit/753d80f28048915314d8e9c8bab098218562979e) Force routing-peer DNS resolution for reverse-proxy domain targets - [`7e44f7f`](https://github.com/netbirdio/netbird/commit/7e44f7f91895b19f4f629de8a001575c667fc51d) Only force DNS resolution for domain-type resources - [`18f1df4`](https://github.com/netbirdio/netbird/commit/18f1df4d5a43679bd1fc81159d7aee0e049c6c0e) Merge branch 'main' into force-routing-peer-dns-reverse-proxy ### 📊 Changes **9 files changed** (+170 additions, -6 deletions) <details> <summary>View changed files</summary> 📝 `management/internals/shared/grpc/components_envelope_response.go` (+1 -1) 📝 `management/internals/shared/grpc/conversion.go` (+4 -4) 📝 `management/internals/shared/grpc/conversion_test.go` (+34 -0) 📝 `management/internals/shared/grpc/server.go` (+1 -1) 📝 `management/server/types/account.go` (+48 -0) 📝 `management/server/types/account_components.go` (+2 -0) 📝 `management/server/types/account_test.go` (+68 -0) 📝 `shared/management/types/network.go` (+5 -0) 📝 `shared/management/types/networkmap_components.go` (+7 -0) </details> ### 📄 Description ## Describe your changes Reverse-proxy services that target a domain network resource rely on DNS resolution happening on the routing peer, but that only occurs when the account-global "DNS via routing peer" setting is enabled. This forces routing-peer DNS resolution on per-peer for the peers involved in a reverse-proxy domain target, so the feature works without requiring the account-wide setting. - Force the flag on for embedded reverse-proxy client peers so they route domain DNS to the resolving peer instead of resolving locally - Force the flag on for peers that route a domain network resource targeted by an enabled reverse-proxy service, so their DNS forwarder starts - Carry the decision on the per-peer network map so both the streaming and initial-sync paths emit it, leaving the account-global setting untouched ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Internal behavior change: no user-facing setting or API surface is added; the existing account setting is unchanged. ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6872"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787414293&installation_model_id=427504&pr_number=6872&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6872&signature=71f4142d96e7800c5f39482b3eec964cd90ba8f3adedded69c51a4bb33d0c1ff"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>@codesmith-bot</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Routing peers can now automatically enable DNS resolution when required for reverse-proxy domain targets. * DNS resolution behavior is propagated through network maps and generated peer configuration in sync/login responses. * A new per-network-map override can force DNS resolution beyond the account-wide setting. * **Bug Fixes** * Improved DNS resolution behavior for embedded peers and explicitly routed scenarios. * **Tests** * Added unit tests covering combinations of global/override settings, embedded behavior, and domain-targeted resources. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:07:35 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29177