github netbirdio/netbird v0.80.0

4 hours ago

Release Notes for v0.80.0

What's New

🔒 Security and Access Control

  • Refused to pin an agent network gateway onto another account's host, adding cross-account validation for gateway assignments. #7519
  • Validated proxy cluster on Agent Network bootstrap, preventing an agent network from bootstrapping onto another account's proxy cluster. #7402
  • Refused HTTP redirects on IdP clients, preventing open redirect attacks against identity provider integrations. #7579
  • Revoked local Dex session on embedded IdP password change, ensuring sessions are properly invalidated when credentials are updated. #7556
  • Added upload URL signing and rate limiting for file upload endpoints. #7502

🖥️ Client Improvements

  • Staged install script downloads in a private temp directory, preventing other processes from tampering with downloaded files before installation. #7534
  • Enforced HTTPS on install script downloads, ensuring all client downloads use secure connections. #7545
  • Fixed peers not being notified when the relay connection drops, which could leave stale peer state after a relay disconnect. #7490
  • Fixed session deadline read under the status read lock, preventing a potential race condition. #7550
  • Removed the empty GPO DNS policy store on Windows teardown, cleaning up leftover DNS policy entries when the client shuts down. #7563
  • Resolved the shared socket source address through a connected UDP probe socket, fixing source address resolution for shared socket mode. #7633
  • Validated saved service parameters and pinned the netsh lookup on Windows, hardening the service configuration path. #7584
  • Used POSIX-style file read/write of JSON on Windows, improving cross-platform config file handling. #7631
  • Raised the daemon IPC receive limit to 16 MB, matching gRPC's default and preventing truncation of large messages. #7676
  • Skipped route firewall rule computation when no firewall is configured, avoiding unnecessary work. #7624
  • Fixed device dump clearing all peer endpoints instead of just the target one, which could disrupt connections to other peers. #7632
  • Fixed Windows IPC privilege check to only treat LocalSystem as a privileged identity by SID. Local Service and Network Service now go through the same checks as any other caller. #7889
  • Bumped Wails to v3.0.0-beta.25 for the desktop UI. #7640

⚙️ Management Improvements

  • Sped up test store setup and summarized unit test runs, improving CI performance. #7518
  • Read X-Real-IP when extracting the peer connection IP, supporting deployments behind reverse proxies. #7561
  • Handled empty trusted peer to avoid errors when no trusted peer is configured. #7589
  • Named the account owner in the pending approval error, making it clear who to contact for account approval. #7533
  • Fixed group resource validation for proper enforcement. #7608
  • Added store support to filter by public ID. #7208
  • Recorded proxy version on connect for tracking and debugging. #7630
  • Split store by table for improved database performance and organization. #7646
  • Prevented deleting custom domains used by services, protecting active proxy configurations from accidental removal. #7515
  • Moved rate limiter to shared package for reuse across services. #7727
  • Let usage_viewer read Agent Network access logs, so users reviewing cost can now see the requests behind usage metrics. #7750

🔀 Reverse Proxy

  • Closed the client connection on private service denials instead of leaving it hanging. #7590
  • Added proxy rate limiter to protect against abuse. #7568
  • Added proxy credentials limiter on management to throttle authentication attempts. #7569
  • Fixed upstream HTTP version applied before cloning transports. #7806
  • Added release-wired UBI image variant for the proxy. #7464
  • Fixed flow auth secret for external Relay migrations. #7731

🏗️ Infrastructure and CI

  • Certified the rootless UBI client image on release for Red Hat ecosystem compliance. #7525
  • Fixed RPM metadata for Red Hat software certification (two rounds of fixes). #7562, #7614
  • Added proxy support to enterprise setup. #7651
  • Built the upload server from source, nonroot on Chainguard for a hardened container image. #7663
  • Built and linted mobile Go code in CI for Android. #7641
  • Bumped workflow actions off the retired Node 20 runtime. #7644
  • Added Pyroscope profiling to management, signal, and proxy services. #7536
  • Pointed the agent-config e2e providers at the mock upstream. #7542
  • Used the Silo image for the S3 upload test. #7619

📝 Misc

  • Pointed bug reports at Discussions and added SUPPORT.md. #7647
  • Added cloud API spec to the public OpenAPI definition with REST client. #7222
  • Loaded AGENTS.md every session and refused attribution trailers. #7544

What's Changed

  • [management] Speed up test store setup and summarize the unit test run by @mlsmaycon in #7518
  • [management] Refuse to pin an agent network gateway onto another account's host by @mlsmaycon in #7519
  • [management] Validate the proxy cluster an agent network bootstraps onto by @mlsmaycon in #7402
  • [management] Point the agent-config e2e providers at the mock upstream by @mlsmaycon in #7542
  • [client] Stage install script downloads in a private temp directory by @riccardomanfrin in #7534
  • [client] Read the session deadline under the status read lock by @pappz in #7550
  • [client] Enforce HTTPS on install script downloads by @riccardomanfrin in #7545
  • [misc] Load AGENTS.md every session and refuse attribution trailers by @mlsmaycon in #7544
  • [client] Fix - Add RPM metadata required for Red Hat software certification by @braginini in #7562
  • [management] Read X-Real-IP when extracting the peer connection IP by @bcmmbaga in #7561
  • [management] Handle empty trusted peer by @bcmmbaga in #7589
  • [proxy] Close the client connection on private service denials by @mlsmaycon in #7590
  • [management] Name the account owner in the pending approval error by @heisbrot in #7533
  • [proxy] add proxy rate limiter by @pascal-fischer in #7568
  • [management] Add proxy credentials limiter on management by @pascal-fischer in #7569
  • [client] Fix peers not being notified when the relay connection drops by @pappz in #7490
  • [management] fix group resource validation by @pascal-fischer in #7608
  • [client] Remove the empty GPO DNS policy store on Windows teardown by @lixmal in #7563
  • [management] add store support to filter by public id by @pascal-fischer in #7208
  • [client,management] Skip route firewall rule computation when no firewall by @riccardomanfrin in #7624
  • [management] record proxy version on connect by @pascal-fischer in #7630
  • [management,signal,proxy] add pyroscope profiling by @pascal-fischer in #7536
  • [client] Validate the saved service parameters and pin the netsh lookup by @riccardomanfrin in #7584
  • [client] Use POSIX style file read/write of json for windows by @theodorsm in #7631
  • [client] Fix RPM metadata for Red Hat certification by @braginini in #7614
  • [misc] Bump workflow actions off the retired Node 20 runtime by @heisbrot in #7644
  • [misc] Add upload URL signing and rate limiting by @bcmmbaga in #7502
  • [misc] Use the Silo image for the S3 upload test by @Silex in #7619
  • [management] split store by table by @pascal-fischer in #7646
  • [management] Refuse HTTP redirects on IdP clients by @bcmmbaga in #7579
  • [management] Revoke local Dex session on embedded IdP password change by @bcmmbaga in #7556
  • [misc, android] Build and lint the mobile Go code in CI by @riccardomanfrin in #7641
  • [client] Raise the daemon IPC receive limit gRPC's to 16 MB by @riccardomanfrin in #7676
  • [misc] Build the upload server from source, nonroot on Chainguard by @bison in #7663
  • [infrastructure] Certify the rootless UBI client image on release by @braginini in #7525
  • [client] Resolve the shared socket source address through a connected UDP probe socket by @lixmal in #7633
  • [proxy] Add a release-wired UBI image variant by @jnfrati in #7464
  • [infrastructure] Add proxy support to enterprise setup by @bcmmbaga in #7651
  • [doc] Point bug reports at Discussions and add SUPPORT.md by @thomashacker in #7647
  • [management] Prevent deleting custom domains used by services by @mlsmaycon in #7515
  • [management] move rate limiter to shared package by @pascal-fischer in #7727
  • [client] Bump wails to v3.0.0-beta.25 by @pappz in #7640
  • [client] Stop dumping the whole device to clear one peer endpoint by @lixmal in #7632
  • [infrastructure] Fix flow auth secret for external Relay migrations by @braginini in #7731
  • [proxy] Apply the upstream HTTP version before cloning transports by @mlsmaycon in #7806
  • [management] Let usage_viewer read Agent Network access logs by @jnfrati in #7750
  • [client] Only treat LocalSystem as a privileged identity by SID on Windows by @lixmal in #7889

New Contributors

Full Changelog: v0.79.0...v0.80.0

Don't miss a new netbird release

NewReleases is sending notifications on new releases.