Your Gateway Broke on v3.5.0: The Proxy Middleware's New SSRF Policy
You bump Fiber from v3.4.0 to v3.5.0, the tests pass, the deploy goes out, and
every request to /api/users comes back as a 500. The body of that response
tells anyone who asks exactly what went wrong:
proxy: upstream host resolves to a blocked address: localhost -> 127.0.0.1
In a Docker Compose or Kubernetes setup the hostname is users or
users.default.svc and the IP starts with 10. or 172., but the message is
the same. If the upstream in your proxy.Balancer config is an IP literal, you
do not even get that far: the process panics at startup with proxy: upstream host resolves to a blocked address: 127.0.0.1.
This is not a regression. Fiber v3.5.0 hardened the proxy middleware (#4405), and its new default policy rejects upstreams on loopback, private, link-local and similar addresses. That default is right for code that forwards requests to URLs it did not choose, and inconvenient for the most common use of the middleware, an API gateway in front of internal services. This post shows how to give each kind of proxying the policy it needs, with one gateway that does both, built and tested against Fiber v3.5.0.
