assistant.debyl.io returned 400 on every request. With use_x_forwarded_for set, home assistant hard-fails any request carrying X-Forwarded-For from an address outside trusted_proxies: Received X-Forwarded-For header from an untrusted proxy 169.254.2.1 caddy runs --network host and proxies to localhost:8123, so the source address is whatever pasta presents inside the container's netns. Rootless podman switched from slirp4netns to pasta in v5 (this host runs 5.7.1), which moved that address from 10.0.2.x -- covered by the existing 10.0.0.0/8 entry -- to a link-local tap0 address that nothing in the list matched. The container has no 10.x address at all any more. Latent since the pasta migration; it only surfaced when the site was next opened. Reproduced directly: curl -H 'X-Forwarded-For: 1.2.3.4' http://localhost:8123/ -> 400 Bumped to 2026.8.3 in the same pass (identical digest to the stable tag). The config directory was snapshotted first: the 2026.5.1 -> 2026.8.3 database migration is not reversible. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Deploy Home
There's no place like home!
Just as Dorothy managed the simple task of clicking her heels together, the desire for an equally simple one-button push deployment was in my heart. Thus, this repository was made.
Ansible
Ansible, along with double encrypted secrets, deploys the necessary configurations to make the home fit for certain needs and desires. Namely, having access to my home from anywhere, securely, and a self-hosted CI server that easily ties into existing workflows.
Makefile
The makefile is primarily used as a wrapper script to ensure that necessary
files, such as the secret vault password file, are provisioned as part of this.
One such addition to the task is utilizing dependency pinning through the
utilization of Python's virtualenv to lock down the specific dependency
versions within the requirements.txt file. This, ideally, prevents any
deployment issues with dependency version woes (e.g. version conflicts, major
updates in newest versions, etc.)
| Target Name | Description |
|---|---|
lint |
(default) Runs yamllint and ansible-lint on all YAML files in ansible/ |
deploy |
Deploys everything, or only tasks specified in TAGS= environment variable |
check |
Runs deploy in a "dry-run", showing diff-style outputs on tasks indicating changes |
vault |
Opens the Ansible vault file for editing |