The systemd service unit created by install/blocky-install.sh has
After=network.target and no restart policy. On a container where blocky
binds to a static IP and the interface is not yet configured when the
unit starts, blocky exits once with "bind: cannot assign requested
address" and stays dead. This was observed on Debian 13 LXC / PVE 9
after a host reboot: internal DNS was down until a manual restart.
Two fixes:
1. [Unit] After=/Wants=network-online.target: standard ordering,
prevents the start before the network is usable where a wait-online
provider exists.
2. [Service] Restart=on-failure + RestartSec=5: matches the existing
Restart=on-failure in install/traefik-install.sh; the 5s spacing also
overrides systemd's default start-rate limit (5 starts / 10 s) from
ending retries.
Verification:
1. Container reboot → blocky active with no manual intervention
2. SIGKILL → auto-restart within the restart interval
Co-authored-by: Fidel Ramos <contact.gyldd@8shield.net>