mirror of
https://github.com/netbirdio/netbird-kubeapi-proxy.git
synced 2026-09-23 09:34:58 -07:00
The request rewriter applies a header allowlist and deletes everything else, including Connection, Upgrade, and the Sec-Websocket-* headers. net/http/httputil's ReverseProxy reads the upgrade type from the rewritten outbound header, finds none, and forwards a plain request, so the API server rejects it with "Upgrade request required". This breaks kubectl exec/attach/port-forward/cp over both WebSocket and SPDY. Allow the Sec-Websocket-* negotiation headers (not hop-by-hop, so the proxy does not restore them) and reconstruct Connection/Upgrade from the inbound request. Reconstructing rather than allowlisting the client's Connection header keeps a client from naming proxy-set headers (Authorization, Impersonate-*) as hop-by-hop to have them stripped.