Closes #2.
Previously the cert minting script lived in local-tools/ (gitignored)
and the README pointed at a cert-only source that didn't include the
private key or upstream chain.
setup_cert.py now lives at the repo root and live-fetches both the
peer UUID (from the relevant TLS server cert subject DN) and the
full AC14K_M + upstream chain bundle (RemoteAccessCA + CECA + ROOTCA)
from a public mirror. Each fetch has an inline workaround if the
network is restricted (UUID=..., AC14K_M_CERT_BUNDLE=...,
BRAYSTORM_URL=...). Modulus-pair check catches a wrong-key mistake
before signing. bootstrap.py removed -- imported a package that was
renamed in commit 709fdf4.
Output files use neutral client.* names. README, .env.example,
docker-compose.yml, deploy.sh, and config.py updated to match.
Provenance receipts in local-tools/cert_provenance.md.
63 lines
2.0 KiB
Bash
63 lines
2.0 KiB
Bash
# SmartThings-Local Bridge config.
|
|
# Copy to `.env` and fill in. Never commit `.env`.
|
|
|
|
# =============================================================
|
|
# Appliances — one process supervises N appliances over DTLS.
|
|
# =============================================================
|
|
# APPLIANCE_COUNT defines how many entries to read. Per-appliance
|
|
# keys are 1-indexed (APPLIANCE_1_*, APPLIANCE_2_*, …).
|
|
APPLIANCE_COUNT=1
|
|
|
|
# Appliance 1 — Samsung dryer
|
|
APPLIANCE_1_CLASS=dryer
|
|
APPLIANCE_1_IP=192.168.1.100
|
|
# Leave OCF_PORT blank to inherit the descriptor's default
|
|
# (dryer=49155, oven=49154).
|
|
APPLIANCE_1_OCF_PORT=
|
|
APPLIANCE_1_TOPIC=samsung_dryer
|
|
APPLIANCE_1_NAME=Samsung Dryer
|
|
|
|
# Future:
|
|
# APPLIANCE_2_CLASS=oven
|
|
# APPLIANCE_2_IP=192.168.1.101
|
|
# APPLIANCE_2_OCF_PORT=
|
|
# APPLIANCE_2_TOPIC=samsung_oven
|
|
# APPLIANCE_2_NAME=Samsung Oven
|
|
# (Don't forget to bump APPLIANCE_COUNT=2.)
|
|
|
|
# --- Cert paths ---
|
|
# Defaults work for Docker (mount as /config) and bare-metal (drop
|
|
# into ./certs). The client cert + key are built by setup_cert.py.
|
|
# CERT_PATH=./certs/client_fullchain.pem
|
|
# KEY_PATH=./certs/client.key
|
|
|
|
# --- MQTT broker (HA Mosquitto add-on or any broker) ---
|
|
MQTT_BROKER=192.168.1.5
|
|
MQTT_PORT=1883
|
|
MQTT_USER=samsung_bridge
|
|
MQTT_PASS=
|
|
|
|
# HA discovery prefix — must match the MQTT integration's setting in HA
|
|
# (default `homeassistant`).
|
|
HA_DISCOVERY_PREFIX=homeassistant
|
|
|
|
# Bridge timers (seconds).
|
|
# HEALTH_INTERVAL_S — how often <prefix>/bridge/health republishes.
|
|
# PING_INTERVAL_S — CoAP empty-CON ping cadence (DTLS-layer
|
|
# liveness). Three consecutive failures publish
|
|
# availability=offline.
|
|
# State freshness itself comes from the in-bridge PollScheduler whose
|
|
# tier cadences are declared in the appliance descriptor — there is
|
|
# no top-level heartbeat env var to tune.
|
|
HEALTH_INTERVAL_S=60
|
|
PING_INTERVAL_S=25
|
|
|
|
# Container TZ.
|
|
TZ=Europe/London
|
|
|
|
|
|
# --- Deploy (deploy.sh — tar + ssh docker compose) ---
|
|
SSH_HOST=user@your-server
|
|
REMOTE_DIR=/mnt/user/compose/smartthings-local
|
|
APPDATA_DIR=/mnt/user/appdata/smartthings-local
|