fix(esh-docker-vm): /32 route to Home Assistant over macvlan-shim
The shim holds 10.0.50.47/24, which gives two equal connected 10.0.50.0/24 routes, and ens18's wins. Host-to-HA traffic therefore left via the macvlan parent and was dropped. HA lost MQTT to the broker on this host on 2026-08-19, 2026-09-21 and 2026-09-25 (the last lasted two days). This adds an ifupdown if-up.d hook that routes 10.0.50.46/32 via macvlan-shim; /etc/network/interfaces is not edited. Verified: the route resolves via the shim, the host pings HA, HA reaches :1883, and HA reconnected to the broker. Diagnosis by ha-dev. Also corrects the zigbee2mqtt acceptance note, which had wrongly reported HA as connected.
This commit is contained in:
@@ -68,6 +68,13 @@ Like `nh3-docker`, this host runs **Dozzle** and **Beszel** agents that report b
|
||||
## Notes
|
||||
|
||||
- **Macvlan for Home Assistant** — the HA container gets its own LAN IP (`10.0.50.46`) via a macvlan network on `ens18`, avoiding NAT so multicast/mDNS for HA discovery works cleanly.
|
||||
- ⚠ **The host reaches HA only through `macvlan-shim` (10.0.50.47), and only because of a /32 route**
|
||||
(`/etc/network/if-up.d/macvlan-shim-routes`, from `playbooks/esh-docker-vm-macvlan-shim-route.yaml`,
|
||||
2026-09-27). The shim holds a /24, so the host has TWO equal 10.0.50.0/24 routes, and ens18's wins.
|
||||
Without the /32, host→HA traffic leaves via ens18 and macvlan drops it (a parent cannot talk to its
|
||||
children). HA then loses MQTT, because the broker is on this host: 2026-08-19, 2026-09-21, and
|
||||
2026-09-25 for two days. **A new macvlan child needs its own line in that hook.**
|
||||
Check: `ip route get 10.0.50.46` must say `dev macvlan-shim`.
|
||||
- **External Postgres** — Paperless-ngx connects to a DB running elsewhere (`10.0.50.60:5432`), not a sidecar. Paperless creds in that compose file currently look like defaults; rotate before exposing.
|
||||
- **Volume backups already in place** — `paperless-ngx` and `pgadmin` include `offen/docker-volume-backup:latest` sidecars that tar named volumes to `/mnt/backup/docker/esh-vm-docker/<stack>/`. When the fleet-wide restic plan lands, decide whether to subsume these or leave the per-stack sidecars alone.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user