From 1df2a0b3463af330b9275f5ce3f3f802bac116a6 Mon Sep 17 00:00:00 2001 From: jochens Date: Tue, 29 Sep 2026 23:39:41 +0200 Subject: [PATCH] home-assistant: its directories are placed, and it runs the build in use MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The module stated /services/home-assistant/config and bound its route under /var/lib/mesh — novox's layout, a path no definition may carry (ADR 0112). The config dir and the module's state are now placed (${dir:config}, ${dir:state}); the route binds into ${dir:state}. The sidecar no longer mounts Home Assistant's config dir: nothing reads MESH_HOMEASSISTANT_CONFIG_DIR, and the mount handed it the auth store and secrets.yaml for nothing. The config dir loses owner 1000:1000 — the image runs as root, the uid was the predecessor's host-user convention. Two more listens that the software opens by default and LAN devices dial in on, which a converged filter would otherwise close: 1400 (Sonos event callback) and 18555 (bundled go2rtc WebRTC). Host network, so the machine port is the software's. Image pinned to the 2026.9.3 build ace's predecessor runs (2026-09-18); Home Assistant migrates its recorder schema, so older than running is unsafe. Verified: catalogue tests pass with MESH_CATALOGUE on this tree; the pinned image boots on a fresh root-owned 0700 config dir (manifest 200, API 401 without a token), and refuses X-Forwarded-For from an untrusted proxy (400). --- modules/home-assistant/module.json | 38 +++++++++++++++++++++--------- 1 file changed, 27 insertions(+), 11 deletions(-) diff --git a/modules/home-assistant/module.json b/modules/home-assistant/module.json index 10406c5..15a642f 100644 --- a/modules/home-assistant/module.json +++ b/modules/home-assistant/module.json @@ -18,7 +18,21 @@ "port": 8123, "protocol": "tcp", "from": "mesh", - "why": "the dashboard and the API" + "why": "the dashboard, the API and the companion apps" + }, + { + "name": "sonos-events", + "port": 1400, + "protocol": "tcp", + "from": "mesh", + "why": "the Sonos integration's event callback: speakers push their state changes here" + }, + { + "name": "webrtc", + "port": 18555, + "protocol": "tcp", + "from": "mesh", + "why": "the bundled go2rtc's WebRTC port, which camera streams to a browser use" } ], "resources": [ @@ -28,24 +42,28 @@ "path": "/var/lib/mesh/home-assistant", "mode": "0700" }, + { + "id": "state", + "type": "directory", + "mode": "0700", + "place": "." + }, { "id": "config", "type": "directory", - "path": "/services/home-assistant/config", - "mode": "0700", - "owner": "1000:1000" + "mode": "0700" }, { "id": "server", "type": "container", "name": "home-assistant", - "image": "ghcr.io/home-assistant/home-assistant@sha256:14931c6b13756317849f46da1d01b45937a1150db66c081cfe529d48215943fe", + "image": "ghcr.io/home-assistant/home-assistant@sha256:d8922685169707fd91e8b9729902d975f06157d005e422874d201e0261dda196", "network": "host", "env": { "TZ": "Etc/UTC" }, "volumes": [ - "/services/home-assistant/config:/config" + "${dir:config}:/config" ] }, { @@ -64,15 +82,13 @@ "volumes": [ "/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro", "/var/lib/mesh/home-assistant/token:/run/secrets/token:ro", - "/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro", - "/services/home-assistant/config:/var/lib/home-assistant/config:ro" + "/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123", "MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token", - "MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json", - "MESH_HOMEASSISTANT_CONFIG_DIR": "/var/lib/home-assistant/config" + "MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json" }, "restart-on": [ "runtime-config" @@ -90,7 +106,7 @@ } }, "binds": { - "route": "/var/lib/mesh/home-assistant/route.json" + "route": "${dir:state}/route.json" }, "build": { "on": [