fix(esh-docker-vm): /32 route to Home Assistant over macvlan-shim

The shim holds 10.0.50.47/24, which gives two equal connected 10.0.50.0/24 routes,
and ens18's wins. Host-to-HA traffic therefore left via the macvlan parent and was
dropped. HA lost MQTT to the broker on this host on 2026-08-19, 2026-09-21 and
2026-09-25 (the last lasted two days). This adds an ifupdown if-up.d hook that
routes 10.0.50.46/32 via macvlan-shim; /etc/network/interfaces is not edited.
Verified: the route resolves via the shim, the host pings HA, HA reaches :1883,
and HA reconnected to the broker. Diagnosis by ha-dev.

Also corrects the zigbee2mqtt acceptance note, which had wrongly reported HA as
connected.
This commit is contained in:
vh
2026-09-27 12:50:05 -07:00
parent c7b32418e1
commit 0b8632a7ed
5 changed files with 59 additions and 3 deletions
@@ -0,0 +1,29 @@
# esh-docker-vm: persist + apply a /32 host route to Home Assistant (10.0.50.46) over macvlan-shim,
# as an ifupdown if-up.d hook (the file carries the why). Rerunnable; `ip route replace` is idempotent.
# /etc/network/interfaces is deliberately NOT edited.
# scripts/elway infra-ops@10.0.50.45 --playbook playbooks/esh-docker-vm-macvlan-shim-route.yaml
steps:
- name: Install the if-up.d hook
upload:
src: playbooks/files/esh-docker-vm-macvlan-shim-route.sh
dest: /etc/network/if-up.d/macvlan-shim-routes
mode: "0755"
sudo: true
- name: Apply the route now (same command the hook runs at ifup)
shell: IFACE=macvlan-shim /etc/network/if-up.d/macvlan-shim-routes
sudo: true
changed_when: "false"
verify:
- name: The host routes 10.0.50.46 over the shim
shell: ip route get 10.0.50.46 | grep -q 'dev macvlan-shim'
changed_when: "false"
- name: The host reaches Home Assistant
shell: ping -c2 -W2 10.0.50.46 >/dev/null
changed_when: "false"
- name: Home Assistant reaches the broker on this host (TCP 1883)
shell: docker exec homeassistant python3 -c "import socket; socket.create_connection(('10.0.50.45', 1883), 3).close()"
changed_when: "false"
@@ -0,0 +1,12 @@
#!/bin/sh
# esh-docker-vm: route the host's traffic for macvlan children over the shim (ifupdown if-up.d hook).
#
# Home Assistant sits on a macvlan (10.0.50.46, parent ens18). A macvlan parent cannot talk to its
# own children, so the host reaches HA only through macvlan-shim (10.0.50.47, a macvlan sibling).
# The shim holds a /24, which gives TWO equal connected 10.0.50.0/24 routes; ens18's is listed first
# and wins, so host->HA traffic left via ens18 and was dropped. HA lost MQTT (the broker is on
# this host) on 2026-08-19, 2026-09-21 and 2026-09-25, the last for two days. A /32 via the shim is
# more specific than either /24, so the choice no longer depends on route order.
# Installed by playbooks/esh-docker-vm-macvlan-shim-route.yaml. Add a line per macvlan child.
[ "$IFACE" = "macvlan-shim" ] || exit 0
ip route replace 10.0.50.46/32 dev macvlan-shim # homeassistant