Prepare multi-architecture test app

This commit is contained in:
2026-09-09 12:31:46 +02:00
parent 083624379b
commit c334d6a35c
3 changed files with 29 additions and 1 deletions
+8
View File
@@ -1,5 +1,11 @@
# Configuration # Configuration
## Test installation
Add `https://git.bahmcloud.de/bahmcloud/home-assistant-addons` as a custom repository in the Home Assistant app store, refresh the store, and install **MB-Secure Bridge**.
Install the MB-Secure custom integration before starting the app so that Supervisor discovery can offer the integration automatically.
Configure the local controller address and the installation-specific credentials supplied for your system. Credentials stay inside the app and are never passed to the Home Assistant integration. Configure the local controller address and the installation-specific credentials supplied for your system. Credentials stay inside the app and are never passed to the Home Assistant integration.
For local certificates, `fingerprint` mode requires the expected SHA-256 certificate fingerprint. A certificate change is rejected. `system_ca` uses the standard trust store. For `custom_ca`, place the PEM certificate at the configured path inside the app configuration directory. For local certificates, `fingerprint` mode requires the expected SHA-256 certificate fingerprint. A certificate change is rejected. `system_ca` uses the standard trust store. For `custom_ca`, place the PEM certificate at the configured path inside the app configuration directory.
@@ -8,6 +14,8 @@ The bridge also requires the installation-specific object catalog at the configu
The bridge API is intended for the internal Home Assistant network and is not exposed on a host port by default. The bridge API is intended for the internal Home Assistant network and is not exposed on a host port by default.
For the first live test, verify connectivity, discovered topology, and read-only state updates before operating areas or outputs.
When running under Home Assistant Supervisor, the app advertises and registers When running under Home Assistant Supervisor, the app advertises and registers
the local Bridge API through Supervisor discovery. The runtime-provided internal the local Bridge API through Supervisor discovery. The runtime-provided internal
host name and the dedicated local bridge token are sent only to Supervisor. The host name and the dedicated local bridge token are sent only to Supervisor. The
+1 -1
View File
@@ -2,4 +2,4 @@
The MB-Secure Bridge provides a local, vendor-neutral API for the MB-Secure Home Assistant integration. The MB-Secure Bridge provides a local, vendor-neutral API for the MB-Secure Home Assistant integration.
This app is not affiliated with or endorsed by the device manufacturer. An installable container image is not available yet. This app is not affiliated with or endorsed by the device manufacturer. Version 0.1.0 is an initial test release for `amd64` and `aarch64` Home Assistant systems.
+20
View File
@@ -0,0 +1,20 @@
#include <tunables/global>
profile mb_secure_bridge flags=(attach_disconnected,mediate_deleted) {
#include <abstractions/base>
#include <abstractions/nameservice>
signal,
network inet stream,
network inet6 stream,
network inet dgram,
network inet6 dgram,
/usr/local/bin/mb-secure-bridge rix,
/etc/ssl/certs/ca-certificates.crt r,
/data/ rw,
/data/** rwk,
/config/ r,
/config/** r,
}