home-assistant: placed directories, the build ace runs, its LAN listens #147
Open
mesh-admin
wants to merge 9 commits from
feat/home-assistant-for-ace into main
pull from: feat/home-assistant-for-ace
merge into: :main
:main
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/jackett-for-ace
:feat/oidc-client-provision
:feat/mosquitto-placed
:feat/nodered-for-ace
:feat/influxdb-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/n8n-for-ace
:feat/letta-for-ace
:feat/baserow-for-ace
:feat/supabase-for-ace
:feat/nzbget-for-ace
:feat/matrix-for-ace
:feat/bazarr-for-ace
:feat/redis-for-ace
:feat/mssql-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/grafana-for-ace
:feat/unifi-for-ace
:feat/icecast-for-ace
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Prepares home-assistant for ace (nothing deployed).
${dir:config},${dir:state}), route binds into${dir:state}(ADR 0112); config dir drops owner 1000:1000 (image runs as root).Verified:
go test ./internal/catalogue/ -run Cataloguewith MESH_CATALOGUE on this tree; pinned image boots on a fresh root-owned 0700 config dir (manifest 200, /api 401 without token); refuses X-Forwarded-For from an untrusted proxy (400) — the route source must be in HA's trusted_proxies.Operator-side notes: the sidecar's
tokenmust be a long-lived access token created in HA andsecret accepted (none exists today); see ACE-MODULE-PLANS.md.The module stated /services/home-assistant/config and bound its route under /var/lib/mesh — novox's layout, a path no definition may carry (ADR 0112). The config dir and the module's state are now placed (${dir:config}, ${dir:state}); the route binds into ${dir:state}. The sidecar no longer mounts Home Assistant's config dir: nothing reads MESH_HOMEASSISTANT_CONFIG_DIR, and the mount handed it the auth store and secrets.yaml for nothing. The config dir loses owner 1000:1000 — the image runs as root, the uid was the predecessor's host-user convention. Two more listens that the software opens by default and LAN devices dial in on, which a converged filter would otherwise close: 1400 (Sonos event callback) and 18555 (bundled go2rtc WebRTC). Host network, so the machine port is the software's. Image pinned to the 2026.9.3 build ace's predecessor runs (2026-09-18); Home Assistant migrates its recorder schema, so older than running is unsafe. Verified: catalogue tests pass with MESH_CATALOGUE on this tree; the pinned image boots on a fresh root-owned 0700 config dir (manifest 200, API 401 without a token), and refuses X-Forwarded-For from an untrusted proxy (400).ombi's definition named /services/ombi/config (a HAL machine path) in three places and pinned an image older than the one ace runs. Ombi migrates its own SQLite schema, so a take onto the older pin (v4.53.10-ls267) would start it on a database the newer build (ls269) already touched. - config is a pathless placed directory, mounted as ${dir:config} - a state directory placed at the assignment root carries route.json - image pinned to the digest ace runs today (v4.53.10-ls269) - the sidecar reaches ombi on the machine port the mesh assigns (${port:3579}) rather than assuming 3579 is free - the sidecar no longer mounts ombi's data directory: MESH_OMBI_CONFIG_DIR is read by no code, and the mount exposed the databases for nothing Verified: catalogue tests (MESH_CATALOGUE set, 6 pass, none skipped); the pinned image starts as PUID 1000 in a 0700 dir and answers /api/v1/Status 200; data owned 1001:2000 (ace's media ids) under a 1000:1000 dir is re-owned by the image's init and serves 200; a minted ApiKey is refused (401) - the api-key secret must be accepted from ombi's own settings.A host-network sidecar reaches its service over the machine's loopback, and the mesh publishes that service on a machine port it assigns (ADR 0038) — so dialling the software's port reaches whatever else holds it. On ace, searxng's sidecar dialled 127.0.0.1:8080 and got unifi's inform port. The same shape in bazarr, bookshelf, lidarr, nzbget, qbittorrent, radarr and sonarr; each now asks with ${port:N} (hq 088). Found in review of ace's module preparation.home-assistant now gets its broker and Sonarr/Radarr/Lidarr from the mesh (merge of #156 in
958a6f4, then31af3f0and1e34ecc)mqtt-topic(contributestopics: ["#"]),sonarr-api,radarr-apiandlidarr-api, plusbindsandsecretsfor each. The sidecar dials127.0.0.1:${port:8123}.provisionsstep is declared last. It restarts on anybound-*orsecret-*change. It writes through Home Assistant's own config flows and never through.storage:homeassistant/#.secret accept … home-assistant <app>-api --provider ….127.0.0.1:8989vsace.internal:8989.test/provisions.test.ts(13 passing). tsc typecheck and build are clean. The catalogue tests pass with #144/#147/#149 merged. A scratch resolution for ace fills every binding (mqtt-topic→ ace.internal:1883 asmesh_ace_hass; sonarr, radarr and lidarr → ace.internal:8989/7878/8686) and every sealed secret, and the step'srestart-onresolves.prov-*, 1938x, all removed):mesh_ace_hass@ace.internal and passed HA's test. Sonarr was reported equivalent. Lidarr's reauth was finished with the bound URL and key. Radarr was refused with the minted key and nothing was written (exit 1).switch.e2e_officeon/off). A fresh HA with no MQTT entry got one made.set_ca_certandset_client_cert, and the step now sends them (fixed in1e34ecc).take. Until they are accepted, the step fails for those apps and leaves HA's entries alone.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.