The module stated /services/home-assistant/config and bound its route under
/var/lib/mesh — novox's layout, a path no definition may carry (ADR 0112).
The config dir and the module's state are now placed (${dir:config},
${dir:state}); the route binds into ${dir:state}.
The sidecar no longer mounts Home Assistant's config dir: nothing reads
MESH_HOMEASSISTANT_CONFIG_DIR, and the mount handed it the auth store and
secrets.yaml for nothing. The config dir loses owner 1000:1000 — the image
runs as root, the uid was the predecessor's host-user convention.
Two more listens that the software opens by default and LAN devices dial in
on, which a converged filter would otherwise close: 1400 (Sonos event
callback) and 18555 (bundled go2rtc WebRTC). Host network, so the machine
port is the software's.
Image pinned to the 2026.9.3 build ace's predecessor runs (2026-09-18);
Home Assistant migrates its recorder schema, so older than running is unsafe.
Verified: catalogue tests pass with MESH_CATALOGUE on this tree; the pinned
image boots on a fresh root-owned 0700 config dir (manifest 200, API 401
without a token), and refuses X-Forwarded-For from an untrusted proxy (400).
133 lines
3.0 KiB
JSON
133 lines
3.0 KiB
JSON
{
|
|
"module": "home-assistant",
|
|
"version": "1",
|
|
"slug": "hass",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"state.changed"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/home-assistant/broker",
|
|
"token": "/var/lib/mesh/home-assistant/token"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 8123,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the dashboard, the API and the companion apps"
|
|
},
|
|
{
|
|
"name": "sonos-events",
|
|
"port": 1400,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the Sonos integration's event callback: speakers push their state changes here"
|
|
},
|
|
{
|
|
"name": "webrtc",
|
|
"port": 18555,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the bundled go2rtc's WebRTC port, which camera streams to a browser use"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/home-assistant",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "home-assistant",
|
|
"image": "ghcr.io/home-assistant/home-assistant@sha256:d8922685169707fd91e8b9729902d975f06157d005e422874d201e0261dda196",
|
|
"network": "host",
|
|
"env": {
|
|
"TZ": "Etc/UTC"
|
|
},
|
|
"volumes": [
|
|
"${dir:config}:/config"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/home-assistant/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-home-assistant",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/home-assistant/token:/run/secrets/token:ro",
|
|
"/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123",
|
|
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
|
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "home-assistant",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|