[PR #6759] feat(ios/ssh): add ConnectNetBirdPeer, JWT cache, and WireGuard dialer #29866

Open
opened 2026-08-05 08:09:13 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6759
Author: @evgeniyChepelev
Created: 7/13/2026
Status: 🔄 Open

Base: feature/ios-sshHead: feature/ios-ssh-update


📝 Commits (1)

  • 6af65d2 feat(ios/ssh): add ConnectNetBirdPeer, JWT cache, and WireGuard dialer

📊 Changes

2 files changed (+148 additions, -6 deletions)

View changed files

📝 client/ios/NetBirdSDK/client.go (+25 -0)
📝 client/ios/NetBirdSDK/ssh_client.go (+123 -6)

📄 Description

  • Add ConnectNetBirdPeer() method that skips banner detection and authenticates directly via JWT (mirrors NetBird web dashboard flow)
  • Cache JWT token for 8 minutes to avoid OAuth re-auth on every reconnect (SSH servers reject tokens older than DefaultJWTMaxTokenAge = 10 min)
  • Bind SSH sockets to the WireGuard interface via IP_BOUND_IF (Darwin syscall 25) so connections to 100.x.x.x peers route through the tunnel in the iOS Network Extension process
  • Improve auth failure error message with actionable checklist
  • Add base64 JWT claims debug logging for auth troubleshooting

Describe your changes

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6759 **Author:** [@evgeniyChepelev](https://github.com/evgeniyChepelev) **Created:** 7/13/2026 **Status:** 🔄 Open **Base:** `feature/ios-ssh` ← **Head:** `feature/ios-ssh-update` --- ### 📝 Commits (1) - [`6af65d2`](https://github.com/netbirdio/netbird/commit/6af65d295532cde0f028ea2e18baa0caafc4ccf9) feat(ios/ssh): add ConnectNetBirdPeer, JWT cache, and WireGuard dialer ### 📊 Changes **2 files changed** (+148 additions, -6 deletions) <details> <summary>View changed files</summary> 📝 `client/ios/NetBirdSDK/client.go` (+25 -0) 📝 `client/ios/NetBirdSDK/ssh_client.go` (+123 -6) </details> ### 📄 Description - Add ConnectNetBirdPeer() method that skips banner detection and authenticates directly via JWT (mirrors NetBird web dashboard flow) - Cache JWT token for 8 minutes to avoid OAuth re-auth on every reconnect (SSH servers reject tokens older than DefaultJWTMaxTokenAge = 10 min) - Bind SSH sockets to the WireGuard interface via IP_BOUND_IF (Darwin syscall 25) so connections to 100.x.x.x peers route through the tunnel in the iOS Network Extension process - Improve auth failure error message with actionable checklist - Add base64 JWT claims debug logging for auth troubleshooting ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [ ] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:09:13 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29866