feat(caddy-local): backends via published loopback ports #12
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/caddy-local-dns"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The rootless podman fleet is netns-isolated: every container lives in its own network namespace behind the
internal_netbridge (podman2), which is held alive only by the aardvark-dns process — the host has no bridge interface and no route into10.89.1.0/24. A rootful process can reach the fleet only via published ports. The old caddy-local worked because it ran as a podman container inside that namespace.Fix
127.0.0.1(26 edits across home/podman; loopback only — no new LAN exposure)caddy-local.nixvirtualHosts retargeted to127.0.0.1:<port>; the inner resolv.conf override stays (ACME + fallback DNS still needed)Verified: toplevel evals clean; all target ports free on the host (audited against ss -tln).