mirror of
https://github.com/YuzuZensai/netbird-kubernetes-operator.git
synced 2026-09-13 10:49:15 +00:00
e752d1587f0af8d2f138f44cd327fe3b5f6581ee
e752d1587f
Bump github.com/netbirdio/netbird from 0.72.4 to 0.74.7 (#376)
Bumps [github.com/netbirdio/netbird](https://github.com/netbirdio/netbird) from 0.72.4 to 0.74.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/netbirdio/netbird/releases">github.com/netbirdio/netbird's releases</a>.</em></p> <blockquote> <h2>v0.74.7</h2> <h2>What's Changed</h2> <ul> <li>[relay] Handle QUIC connections concurrently to prevent handshake head-of-line blocking by <a href="https://github.com/lixmal"><code>@lixmal</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6784">netbirdio/netbird#6784</a></li> <li>[client] Reject leading hyphen in getent input to prevent flag injection by <a href="https://github.com/lixmal"><code>@lixmal</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6787">netbirdio/netbird#6787</a></li> <li>[client] Sanitize peer FQDN/hostname in generated SSH config by <a href="https://github.com/riccardomanfrin"><code>@riccardomanfrin</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6805">netbirdio/netbird#6805</a></li> <li>[client] Disable gVisor TCP RACK loss detection on Windows by <a href="https://github.com/lixmal"><code>@lixmal</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6808">netbirdio/netbird#6808</a></li> <li>[client] Rename isValidAccessToken to reflect audience-only check by <a href="https://github.com/riccardomanfrin"><code>@riccardomanfrin</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6806">netbirdio/netbird#6806</a></li> <li>[client] Bind netstack SOCKS5 proxy to 127.0.0.1 by default by <a href="https://github.com/riccardomanfrin"><code>@riccardomanfrin</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6812">netbirdio/netbird#6812</a></li> <li>[client] Evaluate IP fragments against firewall ACLs by <a href="https://github.com/lixmal"><code>@lixmal</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6781">netbirdio/netbird#6781</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/netbirdio/netbird/compare/v0.74.6...v0.74.7">https://github.com/netbirdio/netbird/compare/v0.74.6...v0.74.7</a></p> <h2>v0.74.6</h2> <h2>What's Changed</h2> <ul> <li>[client] ios: preserve WireGuard key on interactive re-login (<a href="https://redirect.github.com/netbirdio/netbird/issues/6777">#6777</a>)</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/netbirdio/netbird/compare/v0.74.5...v0.74.6">https://github.com/netbirdio/netbird/compare/v0.74.5...v0.74.6</a></p> <h2>v0.74.5</h2> <h2>What's Changed</h2> <ul> <li>[proxy] enforce model allowlist for URL-routed providers (Bedrock/Vertex) by <a href="https://github.com/mlsmaycon"><code>@mlsmaycon</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6764">netbirdio/netbird#6764</a></li> <li>[management] Remove proxy peer stale deduplication logic by <a href="https://github.com/mlsmaycon"><code>@mlsmaycon</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6768">netbirdio/netbird#6768</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/netbirdio/netbird/compare/v0.74.4...v0.74.5">https://github.com/netbirdio/netbird/compare/v0.74.4...v0.74.5</a></p> <h2>v0.74.4</h2> <h2>What's Changed</h2> <ul> <li>[management] fix: prevent reverse proxy domain from being pushed as DNS search domain by <a href="https://github.com/blaugrau90"><code>@blaugrau90</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6498">netbirdio/netbird#6498</a></li> <li>[client] Recover from rosenpass key desync by <a href="https://github.com/lixmal"><code>@lixmal</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6714">netbirdio/netbird#6714</a></li> <li>[client] Bump golang.org/x/crypto to v0.54.0 by <a href="https://github.com/lixmal"><code>@lixmal</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6709">netbirdio/netbird#6709</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/blaugrau90"><code>@blaugrau90</code></a> made their first contribution in <a href="https://redirect.github.com/netbirdio/netbird/pull/6498">netbirdio/netbird#6498</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/netbirdio/netbird/compare/v0.74.3...v0.74.4">https://github.com/netbirdio/netbird/compare/v0.74.3...v0.74.4</a></p> <h2>v0.74.3</h2> <h2>What's Changed</h2> <ul> <li>[client] fix MDM managementURL conflict on default-port URL echo by <a href="https://github.com/riccardomanfrin"><code>@riccardomanfrin</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6672">netbirdio/netbird#6672</a></li> <li>[client] Update gopsutil to v4 by <a href="https://github.com/mlsmaycon"><code>@mlsmaycon</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6688">netbirdio/netbird#6688</a></li> <li>[client] Fix hanging status command during relay dial by <a href="https://github.com/theodorsm"><code>@theodorsm</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6694">netbirdio/netbird#6694</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/netbirdio/netbird/compare/v0.74.2...v0.74.3">https://github.com/netbirdio/netbird/compare/v0.74.2...v0.74.3</a></p> <h2>v0.74.2</h2> <h2>What's Changed</h2> <ul> <li>[management] Add vLLM e2e test by <a href="https://github.com/braginini"><code>@braginini</code></a> in <a href="https://redirect.github.com/netbirdio/netbird/pull/6649">netbirdio/netbird#6649</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/netbirdio/netbird/commit/a1c9427d8004576e2cbb9e546d409847fa9df318"><code>a1c9427</code></a> [client] Evaluate IP fragments against firewall ACLs (<a href="https://redirect.github.com/netbirdio/netbird/issues/6781">#6781</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/b7b0d5796e988ac5f369d51d3a16b162d5fb9522"><code>b7b0d57</code></a> [client] Bind netstack SOCKS5 proxy to 127.0.0.1 by default (<a href="https://redirect.github.com/netbirdio/netbird/issues/6812">#6812</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/3f8c4473783424e1642d2991b896add973249d97"><code>3f8c447</code></a> [client] Rename isValidAccessToken to reflect audience-only check (<a href="https://redirect.github.com/netbirdio/netbird/issues/6806">#6806</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/6e3f4d8722d1c3f4482c44aec725aaba80c4512c"><code>6e3f4d8</code></a> [client] Disable gVisor TCP RACK loss detection on Windows (<a href="https://redirect.github.com/netbirdio/netbird/issues/6808">#6808</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/099ae4bc6cc8ab95ef16343acb87c33b8197711c"><code>099ae4b</code></a> [client] Sanitize peer FQDN/hostname in generated SSH config (<a href="https://redirect.github.com/netbirdio/netbird/issues/6805">#6805</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/63d60ba490794eebd0ad5ce77e4d31269e9c793b"><code>63d60ba</code></a> [client] Reject leading hyphen in getent input to prevent flag injection (<a href="https://redirect.github.com/netbirdio/netbird/issues/6787">#6787</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/62fc8d254e636c3053ae8a21c4ea075558a8273f"><code>62fc8d2</code></a> [relay] Handle QUIC connections concurrently to prevent handshake head-of-lin...</li> <li><a href="https://github.com/netbirdio/netbird/commit/3a2f773d655d88d16ed953fc2a114a4e690a1b08"><code>3a2f773</code></a> [client] preserve WireGuard key on interactive re-login (<a href="https://redirect.github.com/netbirdio/netbird/issues/6777">#6777</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/f0eed7564f3a9138962da1408986e4666d7137b5"><code>f0eed75</code></a> [management] Remove proxy peer stale deduplication logic (<a href="https://redirect.github.com/netbirdio/netbird/issues/6768">#6768</a>)</li> <li><a href="https://github.com/netbirdio/netbird/commit/277d8e4c5352950e1ec4fbd21a3266f0412b09fe"><code>277d8e4</code></a> [proxy] enforce model allowlist for URL-routed providers (Bedrock/Vertex) (<a href="https://redirect.github.com/netbirdio/netbird/issues/6">#6</a>...</li> <li>Additional commits viewable in <a href="https://github.com/netbirdio/netbird/compare/v0.72.4...v0.74.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/kubernetes-operator/pr/376"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787085769&installation_id=146802194&pr_number=376&repository=netbirdio%2Fkubernetes-operator&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fkubernetes-operator%2Fpull%2F376&signature=2f50a4b5245bbba3f14f2249365f03c700d30db07e15709056766b6a716394dd"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>/codesmith</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
NetBird Kubernetes Operator
The NetBird Kubernetes Operator automates the provisioning of NetBird network access for services running in your cluster. It extends the Kubernetes API with CRDs, letting you manage NetBird peers, routes, and groups declaratively, the same way you manage the rest of your infrastructure.
Features
- Declarative peer management - define NetBird peers as Kubernetes resources and let the operator handle provisioning and lifecycle
- Automatic secret management - setup keys and credentials are stored and rotated as Kubernetes secrets
- Namespace-scoped or cluster-wide - deploy per-namespace for multi-tenant clusters or cluster-wide for full coverage
- Works with any NetBird deployment - compatible with NetBird Cloud and self-hosted instances
Getting Started
For full setup instructions, see the Getting Started documentation.
Once your secret is configured, install the operator with Helm.
helm upgrade --install --create-namespace -n netbird netbird-operator oci://ghcr.io/netbirdio/helm-charts/netbird-operator
API
| Kind | API Version |
|---|---|
| SetupKey | netbird.io/v1alpha1 |
| Group | netbird.io/v1alpha1 |
| NetworkRouter | netbird.io/v1alpha1 |
| NetworkResource | netbird.io/v1alpha1 |
| NetworkEgress | netbird.io/v1alpha1 |
| SidecarProfile | netbird.io/v1alpha1 |
| ClusterProxy | netbird.io/v1alpha1 |
Languages
Go
97.8%
Makefile
1.2%
Go Template
0.9%
Dockerfile
0.1%