I fully agree with this request, it could even use the trusted networks from postfix config by default imho. Nginx proxy in front of bluemind isn’t the solution, it’s typically a security problem within the app.
Regarding the suggested workaround, isn’t it possible to use /etc/nginx/bm-local.d/ config files so it’s not overwritten with update ?