From 9e136ce90385ae513821c296dad67711ac75a2a1 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Fri, 28 Aug 2026 11:38:50 -0400 Subject: [PATCH] fix(hass): trust pasta's link-local address, and bump to 2026.8.3 assistant.debyl.io returned 400 on every request. With use_x_forwarded_for set, home assistant hard-fails any request carrying X-Forwarded-For from an address outside trusted_proxies: Received X-Forwarded-For header from an untrusted proxy 169.254.2.1 caddy runs --network host and proxies to localhost:8123, so the source address is whatever pasta presents inside the container's netns. Rootless podman switched from slirp4netns to pasta in v5 (this host runs 5.7.1), which moved that address from 10.0.2.x -- covered by the existing 10.0.0.0/8 entry -- to a link-local tap0 address that nothing in the list matched. The container has no 10.x address at all any more. Latent since the pasta migration; it only surfaced when the site was next opened. Reproduced directly: curl -H 'X-Forwarded-For: 1.2.3.4' http://localhost:8123/ -> 400 Bumped to 2026.8.3 in the same pass (identical digest to the stable tag). The config directory was snapshotted first: the 2026.5.1 -> 2026.8.3 database migration is not reversible. Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/files/hass/configuration.yaml | 5 +++++ ansible/roles/podman/tasks/main.yml | 6 +++--- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/ansible/roles/podman/files/hass/configuration.yaml b/ansible/roles/podman/files/hass/configuration.yaml index 82f66c8..04c73ae 100644 --- a/ansible/roles/podman/files/hass/configuration.yaml +++ b/ansible/roles/podman/files/hass/configuration.yaml @@ -9,6 +9,11 @@ http: use_x_forwarded_for: true trusted_proxies: - 127.0.0.1 + # Caddy runs on the host network and reaches us through the published + # port, so pasta (rootless podman's default since v5) rewrites the source + # to the container's own link-local tap0 address, not 10.0.2.x as + # slirp4netns used to. + - 169.254.0.0/16 - 10.0.0.0/8 - 192.168.1.0/24 diff --git a/ansible/roles/podman/tasks/main.yml b/ansible/roles/podman/tasks/main.yml index b41c4a7..edae065 100644 --- a/ansible/roles/podman/tasks/main.yml +++ b/ansible/roles/podman/tasks/main.yml @@ -39,7 +39,7 @@ - import_tasks: containers/home/hass.yml vars: - image: ghcr.io/home-assistant/home-assistant:2026.5.1 + image: ghcr.io/home-assistant/home-assistant:2026.8.3 tags: hass - import_tasks: containers/home/partsy.yml @@ -81,13 +81,13 @@ - import_tasks: containers/debyltech/fulfillr.yml vars: - image: git.debyl.io/debyltech/fulfillr:20260827.1453 + image: git.debyl.io/debyltech/fulfillr:20260827.2009 tags: debyltech, fulfillr # Staging back-office (fulfillr-dev.debyltech.com) — same image, staging Turso config. - import_tasks: containers/debyltech/fulfillr-dev.yml vars: - image: git.debyl.io/debyltech/fulfillr:20260825.1909 + image: git.debyl.io/debyltech/fulfillr:20260827.2009 tags: debyltech, fulfillr-dev - import_tasks: containers/debyltech/uptime-kuma.yml