diff --git a/mb_secure_bridge/DOCS.md b/mb_secure_bridge/DOCS.md index e747d52..190b051 100644 --- a/mb_secure_bridge/DOCS.md +++ b/mb_secure_bridge/DOCS.md @@ -2,7 +2,9 @@ Configure the local controller address and the installation-specific credentials supplied for your system. Credentials stay inside the app and are never passed to the Home Assistant integration. -For local certificates, `fingerprint` mode requires the expected SHA-256 certificate fingerprint. A certificate change is rejected. `system_ca` uses the standard trust store, while `custom_ca` is reserved for a separately provided local certificate authority. +For local certificates, `fingerprint` mode requires the expected SHA-256 certificate fingerprint. A certificate change is rejected. `system_ca` uses the standard trust store. For `custom_ca`, place the PEM certificate at the configured path inside the app configuration directory. + +The bridge also requires the installation-specific object catalog at the configured path. Place the exported catalog in the app configuration directory as `objects.csv`, or update `object_catalog_path`. The app mounts this directory read-only and does not copy its contents into diagnostics or logs. The bridge API is intended for the internal Home Assistant network and is not exposed on a host port by default. diff --git a/mb_secure_bridge/config.yaml b/mb_secure_bridge/config.yaml index 7bfa66b..a7afbbf 100644 --- a/mb_secure_bridge/config.yaml +++ b/mb_secure_bridge/config.yaml @@ -15,6 +15,9 @@ discovery: - mb_secure ports: {} ports_description: {} +map: + - type: addon_config + read_only: true options: host: "" port: 443 @@ -22,6 +25,8 @@ options: password: "" tls_mode: fingerprint certificate_sha256: "" + custom_ca_path: /config/ca.pem + object_catalog_path: /config/objects.csv reconnect_interval: 10 log_level: info schema: @@ -31,5 +36,7 @@ schema: password: password tls_mode: list(system_ca|custom_ca|fingerprint) certificate_sha256: str + custom_ca_path: str + object_catalog_path: str reconnect_interval: int(1,300) log_level: list(error|warn|info|debug) diff --git a/mb_secure_bridge/translations/en.yaml b/mb_secure_bridge/translations/en.yaml index 1d64d07..e18e353 100644 --- a/mb_secure_bridge/translations/en.yaml +++ b/mb_secure_bridge/translations/en.yaml @@ -17,6 +17,12 @@ configuration: certificate_sha256: name: Certificate SHA-256 fingerprint description: Expected fingerprint when fingerprint verification is selected. + custom_ca_path: + name: Custom CA path + description: Path to a PEM certificate inside the read-only app configuration directory. + object_catalog_path: + name: Object catalog path + description: Path to the installation-specific object catalog inside the read-only app configuration directory. reconnect_interval: name: Reconnect interval description: Initial reconnect delay in seconds.