Hserver Failure Notes: Authentication and Ingress · advanced

Machine APIs Need Machine Credentials, Not Browser Redirects

A firmware client cannot solve an interactive login flow, and treating the redirect as success hides the real authentication failure.

Current. Current engineering note based on recent hserver deployment, debugging, recovery, and production-hardening work in September 2026.

Only the exact machine endpoints bypass Authelia, and those endpoints remain protected by device-specific Bearer credentials in the OTA API. Human routes stay behind two-factor SSO.

Public OTA device calls initially shared an ingress domain with human administration. If interactive SSO intercepted a heartbeat, the firmware received HTML or a redirect instead of the API response it expected. The ingress policy had not separated human identity from device identity. Both are authentication problems, but they use different credentials and interaction models.

Protocol boundaries should preserve the client's native authentication model. API gateways should not translate an unauthorized machine call into an unrelated browser flow.

External verification should assert status semantics, content type and redirect behavior so future proxy changes cannot silently route device traffic through the human login path. The concrete hserver evidence is commit 8940954, so this note is tied to an actual production change rather than a hypothetical failure.

Quick navigationEsc