[PR #6886] [management] Read reverse-proxy service and target columns in Postgres path #29196

Closed
opened 2026-08-05 08:07:38 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/6886

State: closed
Merged: Yes


Describe your changes

The Postgres read path in getServices (sql_store.go) hand-writes the column list and row scan, and had drifted from the gorm model. Several service and target columns were absent from the SELECT and scan, so on Postgres those fields came back zero-valued while SQLite and MySQL loaded them correctly. This adds the missing columns and a test that prevents the lists from drifting again.

  • Load service access restrictions (allowed/blocked CIDRs and countries, CrowdSec mode) on the Postgres path
  • Load the service meta_last_renewed_at timestamp used for ephemeral service expiry
  • Load target proxy_protocol and the full embedded target options (TLS skip, timeouts, path rewrite, custom headers, direct upstream, capture settings, middlewares, agent-network flags)
  • Move the service/target column lists into shared constants and split the loader into smaller helpers
  • Add a test that fails when a gorm column is missing from the Postgres column list, plus a round-trip test that fails on Postgres without the fix

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Internal storage-layer parity fix with no user-facing or API change.

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes
    • Improved reliability of service loading so metadata (including renewal timestamps), restrictions, and related fields are consistently preserved.
    • Enhanced target option loading for timeouts, TLS behavior, path rewrite mode, custom headers/middleware, capture limits/content types, agent-network settings, and access-log preferences.
    • More robust JSON handling with better error clarity and safer validation of numeric fields.
  • Tests
    • Added round-trip test coverage for service/target options across supported database engines.
    • Added a Postgres pgx vs ORM column parity check to prevent accidentally omitted columns.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/6886 **State:** closed **Merged:** Yes --- ## Describe your changes The Postgres read path in `getServices` (`sql_store.go`) hand-writes the column list and row scan, and had drifted from the gorm model. Several service and target columns were absent from the `SELECT` and scan, so on Postgres those fields came back zero-valued while SQLite and MySQL loaded them correctly. This adds the missing columns and a test that prevents the lists from drifting again. - Load service access restrictions (allowed/blocked CIDRs and countries, CrowdSec mode) on the Postgres path - Load the service `meta_last_renewed_at` timestamp used for ephemeral service expiry - Load target `proxy_protocol` and the full embedded target options (TLS skip, timeouts, path rewrite, custom headers, direct upstream, capture settings, middlewares, agent-network flags) - Move the service/target column lists into shared constants and split the loader into smaller helpers - Add a test that fails when a gorm column is missing from the Postgres column list, plus a round-trip test that fails on Postgres without the fix ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) - [x] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Internal storage-layer parity fix with no user-facing or API change. ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved reliability of service loading so metadata (including renewal timestamps), restrictions, and related fields are consistently preserved. * Enhanced target option loading for timeouts, TLS behavior, path rewrite mode, custom headers/middleware, capture limits/content types, agent-network settings, and access-log preferences. * More robust JSON handling with better error clarity and safer validation of numeric fields. * **Tests** * Added round-trip test coverage for service/target options across supported database engines. * Added a Postgres pgx vs ORM column parity check to prevent accidentally omitted columns. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 08:07:38 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29196