From 71b041efbf69ccdab02f1be1ba5debcfea7a4143 Mon Sep 17 00:00:00 2001 From: Collin Diekvoss Date: Thu, 20 Aug 2026 14:26:03 -0500 Subject: [PATCH] fix(router): explicitly bind public Caddy sites to router.ip too Caddy groups vhosts into separate HTTP servers by their exact set of listen addresses. Private (diekvoss.net) sites bind 127.0.0.1/[::1]/ router.ip explicitly; public (toyvo.dev) sites only bound 0.0.0.0/[::]. Since a specific IP bind wins over the 0.0.0.0 wildcard for connections addressed to that exact IP, any request straight to router.ip with SNI for a public host (e.g. git.toyvo.dev) landed in the private server, which has no matching route, and Caddy answered 200 with an empty body. Traffic via Cloudflare hit the WAN IP instead, which only the public server's wildcard bind covers, so it worked - masking this for months. Add router.ip to the public listenAddresses so public sites are present in whichever server ends up owning that address. --- configurations/nixos/router/virtual-hosts.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/configurations/nixos/router/virtual-hosts.nix b/configurations/nixos/router/virtual-hosts.nix index c9fe22d..cb5b92b 100644 --- a/configurations/nixos/router/virtual-hosts.nix +++ b/configurations/nixos/router/virtual-hosts.nix @@ -38,6 +38,12 @@ [ "0.0.0.0" "[::]" + # Private-domain sites explicitly bind router.ip too, which + # otherwise steals connections addressed to that specific IP + # into their own server (no route -> empty 200) since Caddy + # groups sites into servers by exact listenAddresses set and + # a specific bind wins over the 0.0.0.0 wildcard for that IP. + homelab.router.ip ] else [ -- 2.51.2