Skip to content

Document combined-server disableLegacyPort setting - #1016

Open
josipstojanovic-boop wants to merge 1 commit into
netbirdio:mainfrom
josipstojanovic-boop:document-disable-legacy-port
Open

josipstojanovic-boop wants to merge 1 commit into
netbirdio:mainfrom
josipstojanovic-boop:document-disable-legacy-port

Conversation

@josipstojanovic-boop

@josipstojanovic-boop josipstojanovic-boop commented Oct 2, 2026 •

Copy link
Copy Markdown

Document server.disableLegacyPort for the combined server introduced by netbirdio/netbird#6913. Explain the default compatibility behavior, the prerequisite that clients no longer need the legacy listener, and that the explicitly configured server listener remains active.

This documentation should merge with or after the server change.

Validation: npm run lint:mdx and npm run build passed locally.

Summary by CodeRabbit

  • Documentation
    • Documented the server.disableLegacyPort setting, which disables the legacy management listener on port 33073. It defaults to false; the configured listen address remains active.

@vercel

vercel Bot commented Oct 2, 2026

Copy link
Copy Markdown

@josipstojanovic-boop is attempting to deploy a commit to the NetBird GmbH Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 093703b6-cf4c-415b-a609-b4de38e39afa

📥 Commits

Reviewing files that changed from the base of the PR and between 15fb59d and 499c5fe.

📒 Files selected for processing (1)
  • src/pages/selfhosted/maintenance/configuration-files.mdx

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The config.yaml reference adds server.disableLegacyPort. It documents the default value, the TCP port affected, and how server.listenAddress behaves when configured to use that port.

Changes

Server configuration reference

Layer / File(s) Summary
Document legacy listener setting
src/pages/selfhosted/maintenance/configuration-files.mdx
The Server Settings reference documents server.disableLegacyPort, its default value of false, and the behavior of server.listenAddress when set to TCP port 33073.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 499c5

The reference’s listener behavior is consistent with available server evidence. Confirm the corresponding server change is present before operators rely on the new setting.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 499c5

The documentation clearly distinguishes the compatibility listener from the configured server listener and warns against disabling it while clients still depend on it. No introduced security weakness is established. However, support for the exact setting in the companion server release and the required release ordering remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant operational scope is a self-hosted deployment's management listener and clients that depend on it. The documented primary-listener exception means operators cannot treat this setting alone as a guarantee that TCP 33073 is unreachable.

Trust Boundaries and Controls

  • observed — The reference distinguishes compatibility-listener removal from the explicitly configured server endpoint and states the client-compatibility precondition. These are operator instructions; they do not establish runtime enforcement or support for the key in a particular release.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the documented server.disableLegacyPort setting for the combined server.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/pages/selfhosted/maintenance/configuration-files.mdx

typescript-eslint does not support TS 7.0.
Please see https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/#running-side-by-side-with-typescript-6.0 to run typescript-eslint using the TS 6 API.
See also typescript-eslint/typescript-eslint#10940 for tracking typescript-eslint's support for TS >=7.1

Oops! Something went wrong! :(

ESLint: 9.39.5

Error: typescript-eslint does not support TS 7.0.
at Object. (/.eslint-tmp/node_modules/typescript-eslint/dist/index.js:52:11)
at Module._compile (node:internal/modules/cjs/loader:1830:14)
at Object..js (node:internal/modules/cjs/loader:1961:10)
at Module.load (node:internal/modules/cjs/loader:1553:32)
at Module._load (node:internal/modules/cjs/loader:1355:12)
at wrapModuleLoad (node:internal/modules/cjs/loader:255:19)
at Module.require (node:internal/modules/cjs/loader:1576:12)
at require (node:internal/modules/helpers:153:16)
at Object. (/.eslint-tmp/node_modules/eslint-config-next/dist/index.js:5:64)
at Module._compile (node:internal/modules/cjs/loader:1830:14)


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads the server page
One setting joins the guide
Port thirty-three-zero-seven-three
Its listener can now hide
The configured address stays in stride

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant