Repository navigation
Preserve real client IPs through Caddy and external load balancers - #104
Closed
marekmelichercik wants to merge 1 commit into
Closed
marekmelichercik wants to merge 1 commit into
marekmelichercik wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bundled Caddy proxy and an optional external load balancer must provide one verified client IP to Eramba. Configure strict proxy-chain parsing in Caddy, forward its resolved client IP, sanitize untrusted forwarding metadata and PHP-normalized header aliases, and explicitly pass the shared image's proxy settings to the application.
Caddy receives a stable address on the existing internal network. A separate configurable dynamic allocation range prevents MySQL or another earlier-started service from claiming that address. Defaults trust only Caddy; external load balancers require an explicit space-separated IP/CIDR list. Community and Enterprise share the configuration.
Required image and upgrade order
Depends on https://github.com/eramba/eramba/pull/6277 and a published, verified compatible image for each edition. Keep this PR draft until that image is available; the current
latesttag is not proof of compatibility. SaaS uses the separate configuration in https://github.com/eramba/ermb-config/pull/192.Existing installations need the documented maintenance-window migration: preserve project/volume identity, inspect the existing subnet, choose a dynamic subrange excluding Caddy's address, and recreate the network without deleting volumes. Do not copy the default subnet over a running installation.
Validation
git diff --checkpassed. No deployment or volume changes performed.