fix(hass): trust pasta's link-local address, and bump to 2026.8.3

assistant.debyl.io returned 400 on every request. With use_x_forwarded_for
set, home assistant hard-fails any request carrying X-Forwarded-For from an
address outside trusted_proxies:

  Received X-Forwarded-For header from an untrusted proxy 169.254.2.1

caddy runs --network host and proxies to localhost:8123, so the source address
is whatever pasta presents inside the container's netns. Rootless podman
switched from slirp4netns to pasta in v5 (this host runs 5.7.1), which moved
that address from 10.0.2.x -- covered by the existing 10.0.0.0/8 entry -- to a
link-local tap0 address that nothing in the list matched. The container has no
10.x address at all any more.

Latent since the pasta migration; it only surfaced when the site was next
opened. Reproduced directly:

  curl -H 'X-Forwarded-For: 1.2.3.4' http://localhost:8123/  ->  400

Bumped to 2026.8.3 in the same pass (identical digest to the stable tag).
The config directory was snapshotted first: the 2026.5.1 -> 2026.8.3 database
migration is not reversible.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Bastian de Byl
2026-08-28 11:38:50 -04:00
co-authored by Claude Opus 5
parent 87a0332a75
commit 9e136ce903
2 changed files with 8 additions and 3 deletions
@@ -9,6 +9,11 @@ http:
use_x_forwarded_for: true
trusted_proxies:
- 127.0.0.1
# Caddy runs on the host network and reaches us through the published
# port, so pasta (rootless podman's default since v5) rewrites the source
# to the container's own link-local tap0 address, not 10.0.2.x as
# slirp4netns used to.
- 169.254.0.0/16
- 10.0.0.0/8
- 192.168.1.0/24