diff --git a/README.md b/README.md index a3162ee9..f89e55bf 100644 --- a/README.md +++ b/README.md @@ -122,10 +122,10 @@ linux/s390x * `FPM_PM_MAX_SPARE_SERVERS`: FPM max spare servers (default: `6`) * `OPCACHE_MEM_SIZE`: PHP OpCache memory consumption (default `128`) * `LISTEN_IPV6`: Enable IPv6 for Nginx (default `true`) -* `REAL_IP_FROM`: Trusted addresses that are known to send correct replacement addresses (default `0.0.0.0/32`) +* `REAL_IP_FROM`: Trusted addresses that are known to send correct replacement addresses, used for the Nginx access log only (default `0.0.0.0/32`). Set `APP_TRUSTED_PROXIES` so LibreNMS sees the client IP and HTTPS scheme. * `REAL_IP_HEADER`: Request header field whose value will be used to replace the client address (default `X-Forwarded-For`) * `LOG_IP_VAR`: Use another variable to retrieve the remote IP address for access [log_format](http://nginx.org/en/docs/http/ngx_http_log_module.html#log_format) on Nginx. (default `remote_addr`) -* `APP_TRUSTED_PROXIES`: IPs or CIDR ranges trusted to set forwarding headers (X-Forwarded-For, X-Forwarded-Proto, etc.). These hosts can spoof any request header, including authentication headers. +* `APP_TRUSTED_PROXIES`: IPs or CIDR ranges of your reverse proxy, trusted to set forwarding headers (X-Forwarded-For, X-Forwarded-Proto, etc.). These hosts can spoof any request header, including authentication headers. * `SESSION_DRIVER`: [Driver to use for session storage](https://github.com/librenms/librenms/blob/master/config/session.php) (default `file`) * `CACHE_DRIVER`: [Driver to use for cache and locks](https://github.com/librenms/librenms/blob/master/config/cache.php) (default `database`) diff --git a/examples/traefik/librenms.env b/examples/traefik/librenms.env index d650129d..f860b672 100644 --- a/examples/traefik/librenms.env +++ b/examples/traefik/librenms.env @@ -2,9 +2,9 @@ MEMORY_LIMIT=256M MAX_INPUT_VARS=1000 UPLOAD_MAX_SIZE=16M OPCACHE_MEM_SIZE=128 -REAL_IP_FROM=0.0.0.0/32 +REAL_IP_FROM=172.28.0.0/16 REAL_IP_HEADER=X-Forwarded-For -LOG_IP_VAR=http_x_forwarded_for +LOG_IP_VAR=remote_addr CACHE_DRIVER=redis SESSION_DRIVER=redis diff --git a/rootfs/tpls/etc/nginx/nginx.conf b/rootfs/tpls/etc/nginx/nginx.conf index 31b0daa3..2da1f904 100644 --- a/rootfs/tpls/etc/nginx/nginx.conf +++ b/rootfs/tpls/etc/nginx/nginx.conf @@ -86,6 +86,9 @@ http { try_files $fastcgi_script_name =404; include fastcgi_params; fastcgi_param SERVER_SOFTWARE ""; + # Pass the real peer address so APP_TRUSTED_PROXIES can validate the proxy + fastcgi_param REMOTE_ADDR $realip_remote_addr; + fastcgi_param REMOTE_PORT $realip_remote_port; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PATH_INFO $path_info; fastcgi_index index.php;