My reverse proxy suddenly stopped to work, why?

I use HA behind a reverse proxy for years and suddenly (after restarting the service today) the reverse proxy stopped working. HA version is 2023.1.7

I run HA in a docker, it is bound to the host network via network_mode: host. The host IP is 192.168.10.2.

The proxy is a caddy container and the reverse proxying is defined (the FQDN is reacted to example.com) as

https://hass.example.com {
	log {
		level ERROR
	}
	reverse_proxy 192.168.10.2:8123
}

When starting HA I get a ongoing stream of errors:

domotique-hass-1  | 2023-01-29 11:18:04.474 ERROR (MainThread) [homeassistant.components.http.forwarded] Received X-Forwarded-For header from an untrusted proxy 172.18.0.10

172.18.0.10 is the docker IP of caddy

HA is setup for proxies via

http:
  trusted_proxies:
    - 192.168.10.2
    - 172.18.0.10
  use_x_forwarded_for: true

I tried all kinds of combinations with network masks and without - to no avail.

What worries me in that error message is that the incoming traffic to HA seems to come from the docker IP of Caddy, but the setup is supposed to be browser → hass.example.com (that resolves to 192.168.10.2 - which is where Caddy exposes its port 443) → caddy → proxy to 192.168.10.2:8123. At no point was the internal docker network needed.

I can connect to http://192.168.10.2:8123

OK, found it.

I was experimenting with scripts and had a problem in my YAML file - this threw HA into safe mode. Safe mode disabled the rest of the configuration and thus the error.

I am leaving the question and answer instead of deleting it - as someone may have a similar dumb problem as me someday and panicking because the lights may no work and family life is in danger :slight_smile:

When using docker network i prefer using the containers hostname vs docker network IP since hostname never changes. Ive had docker network IP change after container recreation.

https://docs.docker.com/config/containers/container-networking/

In the same way, a container’s hostname defaults to be the container’s ID in Docker. You can override the hostname using `--hostname` . When connecting to an existing network using

Yes, I always use the hostname resolved internally by docker. I do not know without inspecting the network what the IP assignments are.

The case of HA is special because I want it to use the native networking of the host, to be in the same broadcast network (discovery, …).

The IP I used in my attempts was the one provided by the log (I wanted to get back to a working HA ASAP, and think afterward :)). I whitelist the whole docker network anyway.