fix(caddy-local): force the inner resolv.conf (aardvark + router) #11

Merged
Faris merged 2 commits from fix/caddy-local-dns into main 2026-10-02 22:16:29 +01:00
Owner

The nspawn start script copies the host resolv.conf into the container before boot (hardcoded), so the inner networking.nameservers never landed — caddy resolved authelia/open-webui/etc through the router (NXDOMAIN) and returned 502 for every vhost while TLS itself was fine.

Fix: manage /etc/resolv.conf directly via environment.etc (rewritten by the inner activation after the copy) with aardvark 10.89.1.1 first, router fallback; networking.resolvconf.enable = false per the eval assertion.

Deploy effect: container@caddy-local restarts, caddy resolves internal_net names, the 31 vhosts answer again.

The nspawn start script copies the **host** resolv.conf into the container before boot (hardcoded), so the inner `networking.nameservers` never landed — caddy resolved `authelia`/`open-webui`/etc through the router (NXDOMAIN) and returned 502 for every vhost while TLS itself was fine. Fix: manage `/etc/resolv.conf` directly via `environment.etc` (rewritten by the inner activation *after* the copy) with aardvark `10.89.1.1` first, router fallback; `networking.resolvconf.enable = false` per the eval assertion. Deploy effect: `container@caddy-local` restarts, caddy resolves internal_net names, the 31 vhosts answer again.
The container start script copies the host's resolv.conf over the
container's before boot, so networking.nameservers never landed and
caddy 502'd every vhost (container names only exist in aardvark).
environment.etc rewrites it during inner activation, after the copy.
fix(caddy-local): resolvconf.enable = false for the managed resolv.conf
All checks were successful
eval / eval (pull_request) Successful in 22s
55ca4b02c0
Faris merged commit 71ddeb46fb into main 2026-10-02 22:16:29 +01:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Faris/nixos!11
No description provided.