fix(install): detect HOST_IP from physical NICs only, never a VPN tunnel

`ip route get 1.1.1.1` returns the tunnel address on servers running a
full-tunnel WireGuard/Tailscale/ZeroTier client, so phones got a QR code and
URL pointing at an address they can't reach. Detection now uses the
main-table default route's interface if it is real hardware
(/sys/class/net/<if>/device), else the first physical NIC with an IPv4,
else `hostname -I` as a last resort (the installer shows it for
confirmation). .env.example says HOST_IP must be the physical LAN address.

Tested with a stubbed `ip` + fake sysfs in Debian: wg-quick full tunnel,
tunnel owning the default route, no default route and WiFi-only all pick
the physical address; full install.sh scenarios unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-28 15:46:51 +03:00
co-authored by Claude Opus 5.5
parent 0f3237f125
commit 034106918d
2 changed files with 31 additions and 9 deletions
+4 -2
View File
@@ -9,8 +9,10 @@ CLOUD_URL=https://xenia-admin.bonamin.gr
SECRET_KEY=generate-with-openssl-rand-hex-32
LICENSE_GRACE_HOURS=24
# This machine's LAN IP — the address phones open (http://<HOST_IP>) and the
# pairing QR code encodes. install.sh detects it; reserve it in the router's DHCP.
# This machine's LAN IP on the PHYSICAL network (Ethernet/WiFi) — the address
# phones open (http://<HOST_IP>) and the pairing QR code encodes. Never a VPN
# address (WireGuard/Tailscale/ZeroTier). install.sh detects it; reserve it in
# the router's DHCP.
HOST_IP=
# Break-glass support account (leave blank to disable)