Skip to content
DnsLister Forum

Where domain hunters compare notes

NetBird v0.79.0 is here – Light mode, rootless Red Hat UBI, MDM improvements and more!

NetBird v0.79.0: desktop light mode, MDM enforcement in the mobile SDKs, rootless Red Hat UBI image, and a TrustedPeers change self-hosters should read.

Desktop light mode

The desktop app now offers System, Light, and Dark. The light theme covers the connection view, settings, profiles, and dialogs, with native window appearance matched on Windows, macOS, and Linux. (#7344)

https://preview.redd.it/04k4jol8tbqh1.png?width=2022&format=png&auto=webp&s=baf7a4519ef555d1f1c48d6c42280c2a5ca813a6

Client

  • MDM policy bridges and shared enforcement for the iOS and Android SDKs, consistent with the desktop client. MDM booleans delivered as JSON 0/1 are now accepted, and managed URLs are compared by normalized endpoint. (#6435, #7471, #7472)
  • When the resolver can't listen on port 53, the eBPF DNS forwarder is replaced with UDP and TCP DNAT rules, with rollback and cleanup for incomplete redirects. (#7439)
  • wireguard-go bumped to 8bf8fa968f1a: fixes keepalive buffer-pool stalls, keeps timer paths non-blocking, makes netstack interface shutdown idempotent. (#7532)
  • Fixed a relay address race that could advertise a URL and IP from different connections during a reconnect. (#7498)
  • System info is refreshed on every management sync reconnect, so local addresses and posture data stay current after network changes. (#7409)
  • Android TUN addresses now use host prefixes, so local network protection no longer classifies the whole overlay as a local network. (#7414)
  • Fixed a Windows tray deadlock triggered by double-clicking while another window was still being created. (#7449)

Management

  • Login expiration now includes offline peers and disconnects expired ones, while protecting peers that just logged in again. (#7467)
  • OIDC issuer validation hardened: HTTPS required, credentials/query strings/fragments rejected in issuer URLs, discovery redirects refused, discovery response size capped. (#7435)
  • Other users can no longer delete the account owner. (#7456)
  • SQLite network map fixes for networks using individual peers as routers with empty or null peer_groups, and for users with null automatic groups. (#7418, #7425)

Reverse proxy

  • New NB_PROXY_UPSTREAM_HTTP_VERSION with auto, 1.1, and 2. auto negotiates with HTTPS upstreams and falls back to HTTP/1.1 when a negotiated HTTP/2 connection fails at the protocol level. (#7410)
  • Group access is enforced both when issuing session cookies and when accepting existing sessions. (#7240)
  • Custom domains must be validated before creating a service or moving one to that domain. Registrations get a 48-hour validation window; expired pending ones are removed unless services are still attached. (#7341, #7497)
  • Loopback, multicast, link-local, and zone-scoped IPv6 addresses are rejected as direct upstreams. (#7400)

Self-hosting

  • Rootless Red Hat UBI image for AMD64 and ARM64, tag 0.79.0-rootless-ubi. Arbitrary non-root UIDs without a passwd entry are supported, as OpenShift uses. (#7469, #7440)
  • RPM packaging updated to meet Red Hat software certification requirements. (#7562, #7573)
  • Read this one if you run behind a reverse proxy: peer connection IP extraction now honors configured TrustedPeers, with X-Forwarded-For taking precedence over X-Real-IP. When TrustedPeers is empty, all IPv4 and IPv6 sources are still trusted. Set your reverse proxy's address or network to restrict which sources can supply forwarded-IP headers. (#7454, #7589, #7561, #7577)
  • Deployments using the embedded identity provider are kept on a single account, with stricter config checks and migration handling. (#7380)

Full release notes: https://github.com/netbirdio/netbird/releases/tag/v0.79.0

Changelog: https://github.com/netbirdio/netbird/compare/v0.78.0…v0.79.0

Source: r/netbird · by /u/netbirdio

Leave a Reply

Your email address will not be published. Required fields are marked *