feat(caddy-local): backends via published loopback ports #12

Merged
Faris merged 1 commit from fix/caddy-local-dns into main 2026-10-02 22:49:16 +01:00
Owner

Problem

The rootless podman fleet is netns-isolated: every container lives in its own network namespace behind the internal_net bridge (podman2), which is held alive only by the aardvark-dns process — the host has no bridge interface and no route into 10.89.1.0/24. A rootful process can reach the fleet only via published ports. The old caddy-local worked because it ran as a podman container inside that namespace.

Fix

  • Every caddy backend quadlet publishes its internal port on 127.0.0.1 (26 edits across home/podman; loopback only — no new LAN exposure)
  • Port scheme: internal + 20000; repeated internal ports bump +10000 per occurrence (8080→28080/38080/48080/58080/68080/78080; 80→20080/30080/40080/50080; 8000→28000/38000/48000)
  • caddy-local.nix virtualHosts retargeted to 127.0.0.1:<port>; the inner resolv.conf override stays (ACME + fallback DNS still needed)
  • pve still dials the LAN directly; kuma monitors unchanged (same vhost names)

Verified: toplevel evals clean; all target ports free on the host (audited against ss -tln).

## Problem The rootless podman fleet is **netns-isolated**: every container lives in its own network namespace behind the `internal_net` bridge (`podman2`), which is held alive only by the aardvark-dns process — the host has no bridge interface and no route into `10.89.1.0/24`. A rootful process can reach the fleet **only via published ports**. The old caddy-local worked because it ran as a podman container inside that namespace. ## Fix - Every caddy backend quadlet publishes its internal port on `127.0.0.1` (26 edits across home/podman; loopback only — no new LAN exposure) - Port scheme: internal + 20000; repeated internal ports bump +10000 per occurrence (8080→28080/38080/48080/58080/68080/78080; 80→20080/30080/40080/50080; 8000→28000/38000/48000) - `caddy-local.nix` virtualHosts retargeted to `127.0.0.1:<port>`; the inner resolv.conf override stays (ACME + fallback DNS still needed) - pve still dials the LAN directly; kuma monitors unchanged (same vhost names) Verified: toplevel evals clean; all target ports free on the host (audited against ss -tln).
feat(caddy-local): backends via published loopback ports
All checks were successful
eval / eval (pull_request) Successful in 22s
e1797edcb1
The rootless fleet is netns-isolated — the host has no route into
internal_net, so a rootful caddy can only reach published ports. Each
backend quadlet now publishes its internal port on 127.0.0.1
(internal+20000; repeated ports bump +10000) and the virtualHosts dial
127.0.0.1:<port>. ACME still DNS-01; pve still dials the LAN direct.
Faris merged commit 545fc49f4d into main 2026-10-02 22:49:16 +01:00
Faris deleted branch fix/caddy-local-dns 2026-10-02 22:49:16 +01:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Faris/nixos!12
No description provided.