fix(monitoring): socket-activate the monitoring Caddy for real client IPs (#100) #154

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/100-monitoring-caddy-socket-activation in i main 2026-07-19 21:17:11 +00:00
Ägare

#100 — monitoring VM Caddy also loses real client IPs to pasta

Follow-up to #81/#94 (which fixed the services-host Caddy). The monitoring VM's Caddy (fronting grafana/stats/ntfy) still used PublishPort, so pasta rewrote inbound source addresses — access logs → Loki and GoatCounter analytics on stats.gitborg.se saw the container-bridge IP, not the real client.

Fix — mirror the #81 socket-activation pattern onto the monitoring role

  • New caddy.socket (user unit): binds 443 (fd/3) + 80 (fd/4) on the host, passes them into the container as fds.
  • caddy.container: drop the three PublishPort lines; Requires=/After=caddy.socket.
  • Caddyfile: auto_https disable_redirects in globals, a (socket_bind) snippet (bind fd/3 h1/h2) imported by all three hosts, and an explicit http:// server on fd/4 for redirects + ACME HTTP-01.
  • tasks: install the socket unit, daemon_reload + enable/start it (before the container, which Requires it).
  • No HTTP/3 — mirror the services host (#101): the old PublishPort=443:443/udp is dropped (UDP/443 fallback churn isn't worth it).

Validation

ansible-lint (production), --check --diff renders clean (0 failed). caddy validate runs at apply-time on the monitoring VM (existing task) before the restart. (A first-run --check would show a benign "caddy.socket not found" for the net-new unit — guarded with when: not ansible_check_mode, since check mode can't pre-write the unit; the prod caddy role's check is clean only because its socket already exists.)

Apply + verify (careful — monitoring front door)

--tags monitoring. After: systemctl --user status caddy.socket active on the monitoring VM; grafana/stats/ntfy all respond over HTTPS; a fresh external request shows a public remote_ip in the monitoring Caddy access log; GoatCounter records the real client. Rollback: revert + --tags monitoring restores PublishPort.

Closes #100.

## #100 — monitoring VM Caddy also loses real client IPs to pasta Follow-up to #81/#94 (which fixed the services-host Caddy). The monitoring VM's Caddy (fronting grafana/stats/ntfy) still used `PublishPort`, so pasta rewrote inbound source addresses — access logs → Loki and GoatCounter analytics on `stats.gitborg.se` saw the container-bridge IP, not the real client. ## Fix — mirror the #81 socket-activation pattern onto the monitoring role - **New `caddy.socket`** (user unit): binds 443 (fd/3) + 80 (fd/4) on the host, passes them into the container as fds. - **`caddy.container`**: drop the three `PublishPort` lines; `Requires=`/`After=caddy.socket`. - **Caddyfile**: `auto_https disable_redirects` in globals, a `(socket_bind)` snippet (`bind fd/3` h1/h2) imported by all three hosts, and an explicit `http://` server on `fd/4` for redirects + ACME HTTP-01. - **tasks**: install the socket unit, `daemon_reload` + enable/start it (before the container, which `Requires` it). - **No HTTP/3** — mirror the services host (#101): the old `PublishPort=443:443/udp` is dropped (UDP/443 fallback churn isn't worth it). ## Validation ansible-lint (production), `--check --diff` renders clean (0 failed). `caddy validate` runs at apply-time on the monitoring VM (existing task) before the restart. (A first-run `--check` would show a benign "caddy.socket not found" for the net-new unit — guarded with `when: not ansible_check_mode`, since check mode can't pre-write the unit; the prod caddy role's check is clean only because its socket already exists.) ## Apply + verify (careful — monitoring front door) `--tags monitoring`. After: `systemctl --user status caddy.socket` active on the monitoring VM; grafana/stats/ntfy all respond over HTTPS; a fresh external request shows a **public** `remote_ip` in the monitoring Caddy access log; GoatCounter records the real client. Rollback: revert + `--tags monitoring` restores `PublishPort`. Closes #100.
supernaut tvångsskickade fix/100-monitoring-caddy-socket-activation från 571e9d2bd2
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m16s
till daf7a5ff6d
Väntande kontroller
ci / ci (pull_request) Has started running
2026-07-19 21:07:31 +00:00
Jämför
supernaut tvångsskickade fix/100-monitoring-caddy-socket-activation från daf7a5ff6d
Väntande kontroller
ci / ci (pull_request) Has started running
till 290c5fa60f
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m25s
2026-07-19 21:08:46 +00:00
Jämför
supernaut sammanfogade incheckning 55a3b16850 till main 2026-07-19 21:17:11 +00:00
supernaut tog bort grenen fix/100-monitoring-caddy-socket-activation 2026-07-19 21:17:12 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!154
Ingen beskrivning angiven.