rootless port-forward (pasta) loses real client IPs before Caddy #81
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#81
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Found during the v16 upgrade's BC1 verification (#73): real client IPs never reach Caddy at all — rootless Podman's port forwarding (pasta) rewrites the source of inbound connections to the container network, so Caddy logs
remote_ip = 10.89.0.15(its own address) for every external request, and forwards that inX-Forwarded-For.Evidence (2026-07-17):
access.logshowsremote_ip: 10.89.0.15, no incoming XFF.X-Forwarded-For: 9.9.9.9→ Forgejo resolves and logs9.9.9.9:0, proving the new v16[security] REVERSE_PROXY_TRUSTED_PROXIESconfig works; the internal IP in logs is inherited from Caddy, not a Forgejo config problem.Consequences: Forgejo audit logs, Forgejo/Caddy rate limiting (#48 edge rate limiting is blocked by this — it would rate-limit all external traffic as one client!), and Loki access-log analytics have never had real client IPs.
Fix candidates:
[Socket]support + Caddy'sbindon inherited fds.supernaut refererade till detta ärende2026-07-21 19:29:42 +00:00