Home Assistant reached mosquitto and the three Servarr apps at 127.0.0.1 and a port typed into its own storage. It now requires mqtt-topic (asking for every topic: discovery and the devices' topics are its job), sonarr-api, radarr-api and lidarr-api, and a run-once `provisions` step — declared last, restarted when a binding or pair credential changes — makes Home Assistant's config entries say what the mesh bound, through Home Assistant's own config flows and never its .storage: - MQTT: the broker is asked first whether it takes the delivered login; then the integration's reconfigure flow sets broker, port, username and password, every other setting sent back as Home Assistant pre-filled it, and Home Assistant's own connection test must pass. A digest of what was written makes a rerun "already as the mesh says". Refused anywhere, nothing is written and Home Assistant keeps the login it has. - Sonarr/Radarr/Lidarr: the bound key is tried against the app (a minted key is never written; the failure names the `secret accept`); no entry is made through the user flow; a reauth Home Assistant started is finished with the bound key (and URL where the integration asks); an entry already at the bound URL, or at another URL reaching the same running app, is left as it is. These integrations have no reconfigure flow, so a working entry elsewhere is refused loudly — the step never removes an entry. The sidecar's URL now uses the port it was given.
197 lines
5.2 KiB
JSON
197 lines
5.2 KiB
JSON
{
|
|
"module": "home-assistant",
|
|
"version": "1",
|
|
"slug": "hass",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"state.changed"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/home-assistant/broker",
|
|
"token": "/var/lib/mesh/home-assistant/token"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 8123,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the dashboard, the API and the companion apps"
|
|
},
|
|
{
|
|
"name": "sonos-events",
|
|
"port": 1400,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the Sonos integration's event callback: speakers push their state changes here"
|
|
},
|
|
{
|
|
"name": "webrtc",
|
|
"port": 18555,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the bundled go2rtc's WebRTC port, which camera streams to a browser use"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/home-assistant",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "written",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "home-assistant",
|
|
"image": "ghcr.io/home-assistant/home-assistant@sha256:d8922685169707fd91e8b9729902d975f06157d005e422874d201e0261dda196",
|
|
"network": "host",
|
|
"env": {
|
|
"TZ": "Etc/UTC"
|
|
},
|
|
"volumes": [
|
|
"${dir:config}:/config"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/home-assistant/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-home-assistant",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/home-assistant/token:/run/secrets/token:ro",
|
|
"/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:${port:8123}",
|
|
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
|
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
},
|
|
{
|
|
"id": "provisions",
|
|
"type": "container",
|
|
"name": "mesh-home-assistant-provisions",
|
|
"network": "host",
|
|
"run-once": true,
|
|
"volumes": [
|
|
"/var/lib/mesh/home-assistant/token:/run/secrets/token:ro",
|
|
"${dir:written}:/var/lib/home-assistant-provisions",
|
|
"${dir:state}/mqtt-topic.json:/run/provisions/mqtt-topic.json:ro",
|
|
"${dir:state}/mqtt-topic.secret:/run/provisions/mqtt-topic.secret:ro",
|
|
"${dir:state}/sonarr-api.json:/run/provisions/sonarr-api.json:ro",
|
|
"${dir:state}/sonarr-api.secret:/run/provisions/sonarr-api.secret:ro",
|
|
"${dir:state}/radarr-api.json:/run/provisions/radarr-api.json:ro",
|
|
"${dir:state}/radarr-api.secret:/run/provisions/radarr-api.secret:ro",
|
|
"${dir:state}/lidarr-api.json:/run/provisions/lidarr-api.json:ro",
|
|
"${dir:state}/lidarr-api.secret:/run/provisions/lidarr-api.secret:ro"
|
|
],
|
|
"env": {
|
|
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:${port:8123}",
|
|
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
|
"MESH_PROVISIONS_DIR": "/run/provisions",
|
|
"MESH_WRITTEN_DIR": "/var/lib/home-assistant-provisions"
|
|
},
|
|
"args": [
|
|
"run",
|
|
"/app/modules/home-assistant/dist/provisions/index.js"
|
|
],
|
|
"restart-on": [
|
|
"bound-mqtt-topic",
|
|
"secret-mqtt-topic",
|
|
"bound-sonarr-api",
|
|
"secret-sonarr-api",
|
|
"bound-radarr-api",
|
|
"secret-radarr-api",
|
|
"bound-lidarr-api",
|
|
"secret-lidarr-api"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"requires": [
|
|
"lidarr-api",
|
|
"mqtt-topic",
|
|
"radarr-api",
|
|
"route",
|
|
"sonarr-api"
|
|
],
|
|
"contributes": {
|
|
"mqtt-topic": {
|
|
"topics": [
|
|
"#"
|
|
]
|
|
},
|
|
"route": {
|
|
"label": "home-assistant",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json",
|
|
"mqtt-topic": "${dir:state}/mqtt-topic.json",
|
|
"sonarr-api": "${dir:state}/sonarr-api.json",
|
|
"radarr-api": "${dir:state}/radarr-api.json",
|
|
"lidarr-api": "${dir:state}/lidarr-api.json"
|
|
},
|
|
"secrets": {
|
|
"mqtt-topic": "${dir:state}/mqtt-topic.secret",
|
|
"sonarr-api": "${dir:state}/sonarr-api.secret",
|
|
"radarr-api": "${dir:state}/radarr-api.secret",
|
|
"lidarr-api": "${dir:state}/lidarr-api.secret"
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|