`ip route get 1.1.1.1` returns the tunnel address on servers running a full-tunnel WireGuard/Tailscale/ZeroTier client, so phones got a QR code and URL pointing at an address they can't reach. Detection now uses the main-table default route's interface if it is real hardware (/sys/class/net/<if>/device), else the first physical NIC with an IPv4, else `hostname -I` as a last resort (the installer shows it for confirmation). .env.example says HOST_IP must be the physical LAN address. Tested with a stubbed `ip` + fake sysfs in Debian: wg-quick full tunnel, tunnel owning the default route, no default route and WiFi-only all pick the physical address; full install.sh scenarios unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
25 lines
751 B
Bash
25 lines
751 B
Bash
# Registry
|
|
REGISTRY=registry.bonamin.gr
|
|
VERSION=0.1.0
|
|
|
|
# Backend runtime secrets (get SITE_ID and SITE_KEY from the sysadmin panel)
|
|
SITE_ID=your-site-id
|
|
SITE_KEY=your-site-key
|
|
CLOUD_URL=https://xenia-admin.bonamin.gr
|
|
SECRET_KEY=generate-with-openssl-rand-hex-32
|
|
LICENSE_GRACE_HOURS=24
|
|
|
|
# This machine's LAN IP on the PHYSICAL network (Ethernet/WiFi) — the address
|
|
# phones open (http://<HOST_IP>) and the pairing QR code encodes. Never a VPN
|
|
# address (WireGuard/Tailscale/ZeroTier). install.sh detects it; reserve it in
|
|
# the router's DHCP.
|
|
HOST_IP=
|
|
|
|
# Break-glass support account (leave blank to disable)
|
|
MASTER_USERNAME=
|
|
MASTER_PASSWORD=
|
|
|
|
# Volumes — absolute paths on the client machine
|
|
DATA_PATH=/opt/xenia/data
|
|
LOGO_PATH=/opt/xenia/logo.png
|