NetBird v0.79.0: desktop light mode, MDM enforcement in the mobile SDKs, rootless Red Hat UBI image, and a TrustedPeers change self-hosters should read.
Desktop light mode
The desktop app now offers System, Light, and Dark. The light theme covers the connection view, settings, profiles, and dialogs, with native window appearance matched on Windows, macOS, and Linux. (#7344)
Client
- MDM policy bridges and shared enforcement for the iOS and Android SDKs, consistent with the desktop client. MDM booleans delivered as JSON
0/1are now accepted, and managed URLs are compared by normalized endpoint. (#6435, #7471, #7472) - When the resolver can't listen on port 53, the eBPF DNS forwarder is replaced with UDP and TCP DNAT rules, with rollback and cleanup for incomplete redirects. (#7439)
- wireguard-go bumped to
8bf8fa968f1a: fixes keepalive buffer-pool stalls, keeps timer paths non-blocking, makes netstack interface shutdown idempotent. (#7532) - Fixed a relay address race that could advertise a URL and IP from different connections during a reconnect. (#7498)
- System info is refreshed on every management sync reconnect, so local addresses and posture data stay current after network changes. (#7409)
- Android TUN addresses now use host prefixes, so local network protection no longer classifies the whole overlay as a local network. (#7414)
- Fixed a Windows tray deadlock triggered by double-clicking while another window was still being created. (#7449)
Management
- Login expiration now includes offline peers and disconnects expired ones, while protecting peers that just logged in again. (#7467)
- OIDC issuer validation hardened: HTTPS required, credentials/query strings/fragments rejected in issuer URLs, discovery redirects refused, discovery response size capped. (#7435)
- Other users can no longer delete the account owner. (#7456)
- SQLite network map fixes for networks using individual peers as routers with empty or null
peer_groups, and for users with null automatic groups. (#7418, #7425)
Reverse proxy
- New
NB_PROXY_UPSTREAM_HTTP_VERSIONwithauto,1.1, and2.autonegotiates with HTTPS upstreams and falls back to HTTP/1.1 when a negotiated HTTP/2 connection fails at the protocol level. (#7410) - Group access is enforced both when issuing session cookies and when accepting existing sessions. (#7240)
- Custom domains must be validated before creating a service or moving one to that domain. Registrations get a 48-hour validation window; expired pending ones are removed unless services are still attached. (#7341, #7497)
- Loopback, multicast, link-local, and zone-scoped IPv6 addresses are rejected as direct upstreams. (#7400)
Self-hosting
- Rootless Red Hat UBI image for AMD64 and ARM64, tag
0.79.0-rootless-ubi. Arbitrary non-root UIDs without a passwd entry are supported, as OpenShift uses. (#7469, #7440) - RPM packaging updated to meet Red Hat software certification requirements. (#7562, #7573)
- Read this one if you run behind a reverse proxy: peer connection IP extraction now honors configured
TrustedPeers, withX-Forwarded-Fortaking precedence overX-Real-IP. WhenTrustedPeersis empty, all IPv4 and IPv6 sources are still trusted. Set your reverse proxy's address or network to restrict which sources can supply forwarded-IP headers. (#7454, #7589, #7561, #7577) - Deployments using the embedded identity provider are kept on a single account, with stricter config checks and migration handling. (#7380)
Full release notes: https://github.com/netbirdio/netbird/releases/tag/v0.79.0
Changelog: https://github.com/netbirdio/netbird/compare/v0.78.0…v0.79.0
Source: r/netbird · by /u/netbirdio
