Skip to content

Preserve real client IPs through Caddy and external load balancers - #104

Closed
marekmelichercik wants to merge 1 commit into
1.xfrom
codex/trusted-proxies
Closed

marekmelichercik wants to merge 1 commit into
1.xfrom
codex/trusted-proxies

Conversation

@marekmelichercik

@marekmelichercik marekmelichercik commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

The bundled Caddy proxy and an optional external load balancer must provide one verified client IP to Eramba. Configure strict proxy-chain parsing in Caddy, forward its resolved client IP, sanitize untrusted forwarding metadata and PHP-normalized header aliases, and explicitly pass the shared image's proxy settings to the application.

Caddy receives a stable address on the existing internal network. A separate configurable dynamic allocation range prevents MySQL or another earlier-started service from claiming that address. Defaults trust only Caddy; external load balancers require an explicit space-separated IP/CIDR list. Community and Enterprise share the configuration.

Required image and upgrade order

Depends on https://github.com/eramba/eramba/pull/6277 and a published, verified compatible image for each edition. Keep this PR draft until that image is available; the current latest tag is not proof of compatibility. SaaS uses the separate configuration in https://github.com/eramba/ermb-config/pull/192.

Existing installations need the documented maintenance-window migration: preserve project/volume identity, inspect the existing subnet, choose a dynamic subrange excluding Caddy's address, and recreate the network without deleting volumes. Do not copy the default subnet over a running installation.

Validation

  • 6/6 Compose contract tests pass, including custom subnet/range/address and IPv4/IPv6 external trust through the Enterprise overlay.
  • 23/23 native Caddy 2.8.4 behavioral checks pass: real/private client IP, spoofed chains, trusted/untrusted metadata, all MCP routes, header aliases and invalid configuration. The verified official binary was used because local Docker stopped starting new containers.
  • PR CI passed all 15 Bats tests, including real Docker/Caddy behavior and dynamic-before-static IP allocation. CI job; its broader installation checks are still running separately.
  • Independent review and git diff --check passed. No deployment or volume changes performed.

@marekmelichercik
marekmelichercik deleted the codex/trusted-proxies branch October 7, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant