fix(homeassistant): trust k3s pod/service CIDRs as X-Forwarded-For proxies
HA runs with hostNetwork on roger-nucbox-evo-x2 while Traefik runs on the raspberrypi node, so requests arrive at HA from 10.88.20.11. The previous trusted_proxies entry (10.88.88.0/24) did not include this address, causing HA to reject X-Forwarded-For and return 400 on every ingress request.
This commit is contained in:
@@ -32,7 +32,9 @@ data:
|
||||
http:
|
||||
use_x_forwarded_for: true
|
||||
trusted_proxies:
|
||||
- 10.88.88.0/24
|
||||
- 10.42.0.0/16 # k3s pod CIDR (Traefik pod lives here)
|
||||
- 10.43.0.0/16 # k3s service CIDR
|
||||
- 10.88.20.0/24 # node subnet (Traefik runs hostNetwork-ish, forwards from 10.88.20.11)
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
|
||||
Reference in New Issue
Block a user