Hannu Teulahti cd03662096 Preserve connection-upgrade headers for kubectl streaming
The request rewriter applies a header allowlist and deletes everything
else, including Connection, Upgrade, and the Sec-Websocket-* headers.
net/http/httputil's ReverseProxy reads the upgrade type from the
rewritten outbound header, finds none, and forwards a plain request, so
the API server rejects it with "Upgrade request required". This breaks
kubectl exec/attach/port-forward/cp over both WebSocket and SPDY.

Allow the Sec-Websocket-* negotiation headers (not hop-by-hop, so the
proxy does not restore them) and reconstruct Connection/Upgrade from the
inbound request. Reconstructing rather than allowlisting the client's
Connection header keeps a client from naming proxy-set headers
(Authorization, Impersonate-*) as hop-by-hop to have them stripped.
2026-06-11 15:37:03 +03:00
2026-05-26 10:53:36 +02:00
2026-05-26 10:53:36 +02:00
2026-05-26 10:53:36 +02:00
2026-06-01 11:49:02 +02:00
2026-06-11 13:29:04 +02:00
2026-06-11 13:29:04 +02:00
2026-06-11 13:29:04 +02:00
2026-06-11 13:29:04 +02:00
2026-06-01 11:49:02 +02:00
2026-05-26 12:02:19 +02:00

NetBird Kubernetes API Proxy

Warning

This project is experimental and under active development. Expect breaking changes.

A Kubernetes API server proxy which uses NetBird connection identities to resolve authentication. Enables NetBird users to access Kubernetes clusters without tokens.

S
Description
No description provided
Readme AGPL-3.0
308 KiB
Languages
Go 91.1%
Makefile 5.6%
Dockerfile 3.3%