fix(install): detect HOST_IP from physical NICs only, never a VPN tunnel
`ip route get 1.1.1.1` returns the tunnel address on servers running a full-tunnel WireGuard/Tailscale/ZeroTier client, so phones got a QR code and URL pointing at an address they can't reach. Detection now uses the main-table default route's interface if it is real hardware (/sys/class/net/<if>/device), else the first physical NIC with an IPv4, else `hostname -I` as a last resort (the installer shows it for confirmation). .env.example says HOST_IP must be the physical LAN address. Tested with a stubbed `ip` + fake sysfs in Debian: wg-quick full tunnel, tunnel owning the default route, no default route and WiFi-only all pick the physical address; full install.sh scenarios unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+4
-2
@@ -9,8 +9,10 @@ CLOUD_URL=https://xenia-admin.bonamin.gr
|
||||
SECRET_KEY=generate-with-openssl-rand-hex-32
|
||||
LICENSE_GRACE_HOURS=24
|
||||
|
||||
# This machine's LAN IP — the address phones open (http://<HOST_IP>) and the
|
||||
# pairing QR code encodes. install.sh detects it; reserve it in the router's DHCP.
|
||||
# This machine's LAN IP on the PHYSICAL network (Ethernet/WiFi) — the address
|
||||
# phones open (http://<HOST_IP>) and the pairing QR code encodes. Never a VPN
|
||||
# address (WireGuard/Tailscale/ZeroTier). install.sh detects it; reserve it in
|
||||
# the router's DHCP.
|
||||
HOST_IP=
|
||||
|
||||
# Break-glass support account (leave blank to disable)
|
||||
|
||||
Reference in New Issue
Block a user