From 447d02293d1bb79d03983d3973c2ea74359ba873 Mon Sep 17 00:00:00 2001 From: m3ta-chiron Date: Sun, 16 Aug 2026 16:07:01 +0200 Subject: [PATCH] fix(m3-hermes): stable Matrix device + DNS pin for homeserver Root cause chain of recurring Matrix outages (2026-08-16): 1. DNS on m3-hermes resolves exclusively via the Netbird-managed resolver. When the Netbird nameserver group is unreachable (observed 14:03-15:24), matrix.m3ta.dev fails to resolve. 2. A gateway restart during that window fails the Matrix login, and without MATRIX_ACCESS_TOKEN the gateway drops Matrix permanently from its reconnect queue ('no bot credential on queued config'). Recovery happens only on the next restart - with working DNS. 3. The stable-token setup from 2026-08-14 was wiped because it was only written to the regenerated .env, not to the agenix secret. Changes: - Pin matrix.m3ta.dev to the m3-atlas public IP (TLS termination) so the Matrix connection survives Netbird DNS outages. - Declare MATRIX_DEVICE_ID=HERMES01 in the module environment so the device id survives .env regeneration. The matching MATRIX_ACCESS_TOKEN must be added to secrets/hermes-env.age (separate manual step: agenix edit + re-encrypt). --- hosts/m3-hermes/configuration.nix | 12 ++++++++++++ hosts/m3-hermes/services/hermes-agent.nix | 9 +++++++++ 2 files changed, 21 insertions(+) diff --git a/hosts/m3-hermes/configuration.nix b/hosts/m3-hermes/configuration.nix index 34dcebe..55f0560 100644 --- a/hosts/m3-hermes/configuration.nix +++ b/hosts/m3-hermes/configuration.nix @@ -13,6 +13,18 @@ networking.hostName = "m3-hermes"; networking.hostId = "a1b2c3d4"; # TODO: Generate unique hostId networking.networkmanager.enable = true; + + # Matrix homeserver pin: DNS on this host resolves exclusively via the + # Netbird-managed resolver (see /etc/resolv.conf → wt0). When the Netbird + # nameserver group is unreachable, matrix.m3ta.dev fails to resolve and the + # gateway cannot log in (observed 2026-08-16). Pinning the public IP of + # m3-atlas (TLS termination for matrix.m3ta.dev) makes the Matrix connection + # independent of Netbird DNS health. Update here if the m3-atlas public IP + # ever changes. + networking.hosts = { + "152.53.85.162" = ["matrix.m3ta.dev"]; + }; + time.timeZone = "Europe/Berlin"; i18n.defaultLocale = "en_US.UTF-8"; diff --git a/hosts/m3-hermes/services/hermes-agent.nix b/hosts/m3-hermes/services/hermes-agent.nix index 454a7e4..037def7 100644 --- a/hosts/m3-hermes/services/hermes-agent.nix +++ b/hosts/m3-hermes/services/hermes-agent.nix @@ -104,6 +104,15 @@ in { GIT_COMMITTER_EMAIL = "m3ta-chiron@agentmail.to"; GIT_INIT_DEFAULT_BRANCH = "master"; + # ── Matrix: stable device (Fix 0, root cause of ghost-device churn) ── + # Every gateway restart with password login creates a NEW device on the + # homeserver when MATRIX_DEVICE_ID is unset. The matching secret + # MATRIX_ACCESS_TOKEN lives in agenix (secrets/hermes-env.age). The token + # also keeps Matrix in the gateway's reconnect queue: without it, a + # failed startup (e.g. transient DNS outage) permanently drops the + # platform ("no bot credential on queued config"). + MATRIX_DEVICE_ID = "HERMES01"; + # ── API Server (OpenAI-compatible, for Hermes Desktop App) ───────── # Accessible via Netbird mesh VPN — not exposed to the public internet. # Bind to 0.0.0.0 so the Netbird interface can reach it.