fix(esh-docker-vm): /32 route to Home Assistant over macvlan-shim

The shim holds 10.0.50.47/24, which gives two equal connected 10.0.50.0/24 routes,
and ens18's wins. Host-to-HA traffic therefore left via the macvlan parent and was
dropped. HA lost MQTT to the broker on this host on 2026-08-19, 2026-09-21 and
2026-09-25 (the last lasted two days). This adds an ifupdown if-up.d hook that
routes 10.0.50.46/32 via macvlan-shim; /etc/network/interfaces is not edited.
Verified: the route resolves via the shim, the host pings HA, HA reaches :1883,
and HA reconnected to the broker. Diagnosis by ha-dev.

Also corrects the zigbee2mqtt acceptance note, which had wrongly reported HA as
connected.
This commit is contained in:
vh
2026-09-27 12:50:05 -07:00
parent c7b32418e1
commit 0b8632a7ed
5 changed files with 59 additions and 3 deletions
+7
View File
@@ -68,6 +68,13 @@ Like `nh3-docker`, this host runs **Dozzle** and **Beszel** agents that report b
## Notes
- **Macvlan for Home Assistant** — the HA container gets its own LAN IP (`10.0.50.46`) via a macvlan network on `ens18`, avoiding NAT so multicast/mDNS for HA discovery works cleanly.
- ⚠ **The host reaches HA only through `macvlan-shim` (10.0.50.47), and only because of a /32 route**
(`/etc/network/if-up.d/macvlan-shim-routes`, from `playbooks/esh-docker-vm-macvlan-shim-route.yaml`,
2026-09-27). The shim holds a /24, so the host has TWO equal 10.0.50.0/24 routes, and ens18's wins.
Without the /32, host→HA traffic leaves via ens18 and macvlan drops it (a parent cannot talk to its
children). HA then loses MQTT, because the broker is on this host: 2026-08-19, 2026-09-21, and
2026-09-25 for two days. **A new macvlan child needs its own line in that hook.**
Check: `ip route get 10.0.50.46` must say `dev macvlan-shim`.
- **External Postgres** — Paperless-ngx connects to a DB running elsewhere (`10.0.50.60:5432`), not a sidecar. Paperless creds in that compose file currently look like defaults; rotate before exposing.
- **Volume backups already in place** — `paperless-ngx` and `pgadmin` include `offen/docker-volume-backup:latest` sidecars that tar named volumes to `/mnt/backup/docker/esh-vm-docker/<stack>/`. When the fleet-wide restic plan lands, decide whether to subsume these or leave the per-stack sidecars alone.