Files
deploy_home/ansible/roles/podman/files/hass/configuration.yaml
T
Bastian de BylandClaude Opus 5 9e136ce903 fix(hass): trust pasta's link-local address, and bump to 2026.8.3
assistant.debyl.io returned 400 on every request. With use_x_forwarded_for
set, home assistant hard-fails any request carrying X-Forwarded-For from an
address outside trusted_proxies:

  Received X-Forwarded-For header from an untrusted proxy 169.254.2.1

caddy runs --network host and proxies to localhost:8123, so the source address
is whatever pasta presents inside the container's netns. Rootless podman
switched from slirp4netns to pasta in v5 (this host runs 5.7.1), which moved
that address from 10.0.2.x -- covered by the existing 10.0.0.0/8 entry -- to a
link-local tap0 address that nothing in the list matched. The container has no
10.x address at all any more.

Latent since the pasta migration; it only surfaced when the site was next
opened. Reproduced directly:

  curl -H 'X-Forwarded-For: 1.2.3.4' http://localhost:8123/  ->  400

Bumped to 2026.8.3 in the same pass (identical digest to the stable tag).
The config directory was snapshotted first: the 2026.5.1 -> 2026.8.3 database
migration is not reversible.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-28 11:38:50 -04:00

32 lines
723 B
YAML

# Configure a default setup of Home Assistant (frontend, api, etc)
default_config:
# Text to speech
tts:
- platform: google_translate
api:
http:
use_x_forwarded_for: true
trusted_proxies:
- 127.0.0.1
# Caddy runs on the host network and reaches us through the published
# port, so pasta (rootless podman's default since v5) rewrites the source
# to the container's own link-local tap0 address, not 10.0.2.x as
# slirp4netns used to.
- 169.254.0.0/16
- 10.0.0.0/8
- 192.168.1.0/24
homeassistant:
time_zone: America/New_York
media_dirs:
media: /share
automation: !include automations.yaml
input_boolean:
tv_mode:
name: TV Mode
initial: off
icon: mdi:television