Skip to content

fix: PROXY protocol should share postscreen cache - #187

Merged
cfis merged 1 commit into
masterfrom
fix/proxy-protocol-postscreen-cache
Sep 22, 2025
Merged

cfis merged 1 commit into
masterfrom
fix/proxy-protocol-postscreen-cache

Conversation

@polarathene

Copy link
Copy Markdown
Member

Implements a fix based on findings at: #186 (comment)

This was observed earlier back in April 2025 and pointed out as not aligned with our docs guidance. Managing the setting via user-patches.sh as I've contributed here is better than the current DMS docs advice with postfix-main.cf, so I'll update that over there too.

This approach to share the postscreen cache is motivated from this DMS issue.

  • Technically depending how it's leveraged privately, perhaps there could be some overlap with public entries in the cache that could be exploited?
  • Without further investigating how the cache is managed and putting more thought into it, I'm not able to weigh in much on that concern, or any other risks.

Should it be an issue, separate cache maps can be configured and proxy_write_maps should be updated as per #186 (comment)


Fixes: #186

@rich0

rich0 commented Sep 20, 2025

Copy link
Copy Markdown

I can confirm that this works for me running chart version 4.2.4 with this change to user-patches.sh added to my values.yaml, over my traefik-ingress proxy.

@cfis

cfis commented Sep 22, 2025

Copy link
Copy Markdown
Collaborator

Great - thanks you both!

@cfis
cfis merged commit 2229467 into master Sep 22, 2025
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Chart version 4.2.3 generates fatal postscreen/proxywrite error and fails to accept non-authenticated connections

3 participants