From 25c67a79c6b956d8d93575bb099fe5e785c1c0f9 Mon Sep 17 00:00:00 2001 From: dtoro Date: Mon, 6 Jul 2026 13:31:51 +0200 Subject: [PATCH] Add Caddy route for oikos.hubris.network; fix loopback-bind bug MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Pushed dtoro/caddy-conf@c195142: oikos.hubris.network -> 192.168.8.205:8091, Authentik-gated (matches paperless.hubris.network's live pattern — confirmed exact snippet syntax against the real Caddyfile rather than trusting the paraphrase in the original README, which turned out to have the wrong forward_auth target: the live snippet points at 127.0.0.1:8099 on Caddy's own LXC, not 192.168.8.6:9000 as containers/106-auth-outpost.md's older text suggested). Reload verified clean — an unrelated existing route stayed healthy through it. Found and fixed a real deploy-blocking bug in the process: oikos-console.service bound 127.0.0.1 only, but Caddy runs on a different host (121) and can only reach apps (105) over the LAN — the console would have been completely unreachable once deployed. Now binds 0.0.0.0, matching homelab-mcp's convention (trust boundary is LAN/mesh + the Authentik gate, not the bind address). Encountered and deliberately left alone: a pre-existing local clone at /tmp/caddy-conf with an unpushed commit + uncommitted diff about jellyfin's auth gating, from before this clone fell 12 commits behind origin. That work turned out to be superseded (origin already reached the same conclusion — SSO plugin handles jellyfin auth, no forward-auth gate — via a different, already-merged path). Didn't touch it; used a fresh clone instead to avoid any risk of losing or corrupting that state. Co-Authored-By: Claude Fable 5 --- ledger/2026-07.jsonl | 1 + oikos/console/deploy/README.md | 29 +++++++++++++--------- oikos/console/deploy/oikos-console.service | 11 +++++--- 3 files changed, 25 insertions(+), 16 deletions(-) diff --git a/ledger/2026-07.jsonl b/ledger/2026-07.jsonl index f56f394..0d8b4e9 100644 --- a/ledger/2026-07.jsonl +++ b/ledger/2026-07.jsonl @@ -1,2 +1,3 @@ {"ts": "2026-07-06T11:05:35+00:00", "agent": "mac-mini", "entity": "host:teddycloud", "action": "activate", "risk": "config_mutation", "verification": "homelab node teddycloud relations", "result": "ok"} {"ts": "2026-07-06T11:15:04+00:00", "agent": "mac-mini", "entity": "repo:Homelab-Docs", "action": "register-webhook", "risk": "config_mutation", "result": "ok", "notes": "webhook id 14 for oikos-console deploy"} +{"ts": "2026-07-06T11:29:56+00:00", "agent": "mac-mini", "entity": "service:caddy", "action": "add-site-block", "risk": "config_mutation", "verification": "curl -s https://git.hubris.network (unrelated route still healthy after reload)", "result": "ok", "notes": "oikos.hubris.network -> 192.168.8.205:8091, Authentik-gated, in dtoro/caddy-conf@c195142"} diff --git a/oikos/console/deploy/README.md b/oikos/console/deploy/README.md index 9be98d8..8124c48 100644 --- a/oikos/console/deploy/README.md +++ b/oikos/console/deploy/README.md @@ -23,7 +23,15 @@ webhook on `dtoro/Homelab-Docs`, port :9831. **skip its random-secret generation** — instead run `homelab secret oikos-console-deploy-secret` on apps and write the `webhook_secret` value into `/etc/oikos-console-deploy/secret` yourself. -- **Caddy route: not yet done.** +- **Caddy route: done.** Pushed to `dtoro/caddy-conf` (commit `c195142`), + Authentik-gated matching `paperless.hubris.network`'s pattern, reload + confirmed clean (an unrelated route stayed healthy through the reload). + **Found and fixed a real bug while wiring this up:** `oikos-console.service` + originally bound `127.0.0.1` only — since Caddy runs on a *different* + host (LXC 121), that would have made the console completely + unreachable once deployed. Now binds `0.0.0.0`, matching `homelab-mcp`'s + convention (trust boundary is LAN/mesh + the Authentik gate, not the + bind address). - **DNS entry: not yet done.** ## One-time setup on apps (105) @@ -37,15 +45,12 @@ cd /opt/oikos-console systemctl enable --now oikos-console.service oikos-console-deploy.service ``` -## Caddy route — NOT in this repo, needs manual addition to `dtoro/caddy-conf` +## Caddy route — done (2026-07-06), in `dtoro/caddy-conf`, not this repo -The console binds `127.0.0.1:8091` on apps only (see `oikos-console.service` — -`ProtectSystem=strict`, no LAN listener); Caddy on LXC 121 reaches it via -apps' **LAN IP**, not loopback (they're different hosts). Site block, -forward-auth gated the same way other LAN-only services are (confirmed -syntax per `containers/121-caddy.md`: `import authentik`, no parens in -the import statement itself — the snippet is *defined* as `(authentik)` -but *imported* as `authentik`): +Live in `dtoro/caddy-conf` as of commit `c195142`, Authentik-gated +(confirmed syntax against the live Caddyfile: `import authentik`, no +parens in the import itself — the snippet is *defined* as `(authentik)` +but *imported* as `authentik`), same pattern as `paperless.hubris.network`: ```caddyfile oikos.hubris.network { @@ -54,9 +59,9 @@ oikos.hubris.network { } ``` -Add `oikos.hubris.network` to the split-horizon DNS zone (Technitium, -LXC 107) pointing at Caddy's LAN IP, same as every other `*.hubris.network` -host. +Still needed: add `oikos.hubris.network` to the split-horizon DNS zone +(Technitium, LXC 107) pointing at Caddy's LAN IP, same as every other +`*.hubris.network` host — see the DNS section below. ## Authentik step-up re-auth on approval actions — deferred, needs live Authentik diff --git a/oikos/console/deploy/oikos-console.service b/oikos/console/deploy/oikos-console.service index 9bd82b9..6cc1ecd 100644 --- a/oikos/console/deploy/oikos-console.service +++ b/oikos/console/deploy/oikos-console.service @@ -7,12 +7,15 @@ Wants=network-online.target Type=simple WorkingDirectory=/opt/oikos-console Environment=HOMELAB_CONTEXT_DIR=/opt/homelab-context -ExecStart=/opt/oikos-console/.venv/bin/uvicorn oikos.console.app:app --host 127.0.0.1 --port 8091 +ExecStart=/opt/oikos-console/.venv/bin/uvicorn oikos.console.app:app --host 0.0.0.0 --port 8091 Restart=on-failure RestartSec=5 -# Stay confined. Bound to loopback only — Caddy (dtoro/caddy-conf) is the -# one that terminates TLS + forward-auth and proxies to 127.0.0.1:8091; -# this unit never listens on the LAN interface directly. +# Caddy runs on a DIFFERENT host (LXC 121) and reaches this over the LAN +# at 192.168.8.205:8091 (dtoro/caddy-conf's oikos.hubris.network block) — +# binding loopback-only would make this unreachable from Caddy entirely. +# Same bind convention as homelab-mcp (0.0.0.0, trust boundary enforced +# by LAN/mesh + the Authentik forward-auth gate in front, not by bind +# address). No public exposure: only reachable via LAN/mesh. ProtectSystem=strict ProtectHome=true PrivateTmp=true