From c334d6a35caea4509c188f7e5003a9f50f822b28 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ren=C3=A9=20Bachmann?= Date: Wed, 9 Sep 2026 12:31:46 +0200 Subject: [PATCH] Prepare multi-architecture test app --- mb_secure_bridge/DOCS.md | 8 ++++++++ mb_secure_bridge/README.md | 2 +- mb_secure_bridge/apparmor.txt | 20 ++++++++++++++++++++ 3 files changed, 29 insertions(+), 1 deletion(-) create mode 100644 mb_secure_bridge/apparmor.txt diff --git a/mb_secure_bridge/DOCS.md b/mb_secure_bridge/DOCS.md index 190b051..7f1864b 100644 --- a/mb_secure_bridge/DOCS.md +++ b/mb_secure_bridge/DOCS.md @@ -1,5 +1,11 @@ # Configuration +## Test installation + +Add `https://git.bahmcloud.de/bahmcloud/home-assistant-addons` as a custom repository in the Home Assistant app store, refresh the store, and install **MB-Secure Bridge**. + +Install the MB-Secure custom integration before starting the app so that Supervisor discovery can offer the integration automatically. + Configure the local controller address and the installation-specific credentials supplied for your system. Credentials stay inside the app and are never passed to the Home Assistant integration. For local certificates, `fingerprint` mode requires the expected SHA-256 certificate fingerprint. A certificate change is rejected. `system_ca` uses the standard trust store. For `custom_ca`, place the PEM certificate at the configured path inside the app configuration directory. @@ -8,6 +14,8 @@ The bridge also requires the installation-specific object catalog at the configu The bridge API is intended for the internal Home Assistant network and is not exposed on a host port by default. +For the first live test, verify connectivity, discovered topology, and read-only state updates before operating areas or outputs. + When running under Home Assistant Supervisor, the app advertises and registers the local Bridge API through Supervisor discovery. The runtime-provided internal host name and the dedicated local bridge token are sent only to Supervisor. The diff --git a/mb_secure_bridge/README.md b/mb_secure_bridge/README.md index 9aa8e7d..bd4b5e6 100644 --- a/mb_secure_bridge/README.md +++ b/mb_secure_bridge/README.md @@ -2,4 +2,4 @@ The MB-Secure Bridge provides a local, vendor-neutral API for the MB-Secure Home Assistant integration. -This app is not affiliated with or endorsed by the device manufacturer. An installable container image is not available yet. +This app is not affiliated with or endorsed by the device manufacturer. Version 0.1.0 is an initial test release for `amd64` and `aarch64` Home Assistant systems. diff --git a/mb_secure_bridge/apparmor.txt b/mb_secure_bridge/apparmor.txt new file mode 100644 index 0000000..3c22083 --- /dev/null +++ b/mb_secure_bridge/apparmor.txt @@ -0,0 +1,20 @@ +#include + +profile mb_secure_bridge flags=(attach_disconnected,mediate_deleted) { + #include + #include + + signal, + + network inet stream, + network inet6 stream, + network inet dgram, + network inet6 dgram, + + /usr/local/bin/mb-secure-bridge rix, + /etc/ssl/certs/ca-certificates.crt r, + /data/ rw, + /data/** rwk, + /config/ r, + /config/** r, +}