Files
localthings/docker-compose.yml
T
Jack Nagy caf195ea1a Ship setup_cert.py to repo root, auto-fetch all CA materials
Closes #2.

Previously the cert minting script lived in local-tools/ (gitignored)
and the README pointed at a cert-only source that didn't include the
private key or upstream chain.

setup_cert.py now lives at the repo root and live-fetches both the
peer UUID (from the relevant TLS server cert subject DN) and the
full AC14K_M + upstream chain bundle (RemoteAccessCA + CECA + ROOTCA)
from a public mirror. Each fetch has an inline workaround if the
network is restricted (UUID=..., AC14K_M_CERT_BUNDLE=...,
BRAYSTORM_URL=...). Modulus-pair check catches a wrong-key mistake
before signing. bootstrap.py removed -- imported a package that was
renamed in commit b00c2fd.

Output files use neutral client.* names. README, .env.example,
docker-compose.yml, deploy.sh, and config.py updated to match.

Provenance receipts in local-tools/cert_provenance.md.
2026-06-30 19:27:24 +01:00

21 lines
702 B
YAML

services:
smartthings-local:
build: .
container_name: smartthings-local
restart: unless-stopped
# Bridge is outbound-only (DTLS UDP to each appliance, MQTT to the
# broker on 1883). No ports to expose.
volumes:
# Holds the client cert + key. APPDATA_DIR comes from .env;
# on Unraid this is typically /mnt/user/appdata/smartthings-local/.
# Bare-metal dev falls back to ./certs alongside this compose file.
- ${APPDATA_DIR:-./certs}:/config:ro
# All runtime config is in .env. env_file passes every variable
# straight into the container, so adding a new appliance is a
# .env edit only — no compose change.
env_file:
- .env