fix(monitoring): socket-activate the monitoring Caddy for real client IPs (#100) #154
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!154
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/100-monitoring-caddy-socket-activation"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
#100 — monitoring VM Caddy also loses real client IPs to pasta
Follow-up to #81/#94 (which fixed the services-host Caddy). The monitoring VM's Caddy (fronting grafana/stats/ntfy) still used
PublishPort, so pasta rewrote inbound source addresses — access logs → Loki and GoatCounter analytics onstats.gitborg.sesaw the container-bridge IP, not the real client.Fix — mirror the #81 socket-activation pattern onto the monitoring role
caddy.socket(user unit): binds 443 (fd/3) + 80 (fd/4) on the host, passes them into the container as fds.caddy.container: drop the threePublishPortlines;Requires=/After=caddy.socket.auto_https disable_redirectsin globals, a(socket_bind)snippet (bind fd/3h1/h2) imported by all three hosts, and an explicithttp://server onfd/4for redirects + ACME HTTP-01.daemon_reload+ enable/start it (before the container, whichRequiresit).PublishPort=443:443/udpis dropped (UDP/443 fallback churn isn't worth it).Validation
ansible-lint (production),
--check --diffrenders clean (0 failed).caddy validateruns at apply-time on the monitoring VM (existing task) before the restart. (A first-run--checkwould show a benign "caddy.socket not found" for the net-new unit — guarded withwhen: not ansible_check_mode, since check mode can't pre-write the unit; the prod caddy role's check is clean only because its socket already exists.)Apply + verify (careful — monitoring front door)
--tags monitoring. After:systemctl --user status caddy.socketactive on the monitoring VM; grafana/stats/ntfy all respond over HTTPS; a fresh external request shows a publicremote_ipin the monitoring Caddy access log; GoatCounter records the real client. Rollback: revert +--tags monitoringrestoresPublishPort.Closes #100.
571e9d2bd2daf7a5ff6ddaf7a5ff6d290c5fa60f