Two more: nextcloud and home-assistant

Nextcloud is the first consumer of two provisions at once: a database
from the mesh's postgres and primary storage in a bucket from the
mesh's own object store — which is how the arrangement being replaced
ran it, minus the bundled MariaDB it no longer needs. Every credential
in one env file the host writes; the manifest holds placeholders and
the mesh holds nothing readable.

Home automation runs on the machine's own network, because discovering
devices is the point and a bridge would hide them — so nothing is
published, the declared port is the bound port, and the rule set opens
exactly it. The case MachineSide was corrected for, in the catalogue.

Both pinned by real digests, resolved on this workstation today.
This commit is contained in:
2026-09-01 23:09:40 +02:00
parent c0107b8572
commit 0ba52d03a3
2 changed files with 112 additions and 0 deletions
+37
View File
@@ -0,0 +1,37 @@
{
"module": "home-assistant",
"version": "1",
"capabilities": [
"container-runtime"
],
"listens": [
{
"port": 8123,
"protocol": "tcp",
"from": "mesh",
"why": "the dashboard and the API"
}
],
"resources": [
{
"id": "config",
"type": "directory",
"path": "/services/home-assistant/config",
"mode": "0700",
"owner": "1000:1000"
},
{
"id": "server",
"type": "container",
"name": "home-assistant",
"image": "ghcr.io/home-assistant/home-assistant@sha256:14931c6b13756317849f46da1d01b45937a1150db66c081cfe529d48215943fe",
"network": "host",
"env": {
"TZ": "Etc/UTC"
},
"volumes": [
"/services/home-assistant/config:/config"
]
}
]
}