feat(esphome): pin 2026.8.2, relocate config into backup coverage, rotate creds
ha-dev requested all three on esh-docker-vm (operator-authorized); the stack had no canonical copy, so it is added to stacks/ rather than edited in place. Pinned ghcr.io/esphome/esphome:2026.8.2 — it was bare, which is exactly how it sat on 2025.8.2 for a year: docker pulled latest once at container creation (2026-04-20, from a layer cached 2025-08-29) and never re-pulled. Every current Everything Presence sensor failed config validation on that build. Verified after: esphome version reports 2026.8.2 and the vendor's own Pro package now validates clean (exit 0, 'Configuration is valid!'), which is the item that unblocks the six waiting sensors. Relocated /path/to/esphome/config (the upstream template placeholder, taken literally by docker) to /opt/docker/conf/esphome, matching the mosquitto pattern. Copied and checksum-verified all 5763 files before removing the original, with a tarball kept at /root/pre-change-archive/. Credentials moved off test/ChangeMe to the vaulted 32-char secret (esh-docker-vm/esphome-dashboard), passed via a host-only .env so nothing plaintext enters git. Three things the job surfaced that were not in the request: The directory is 538 MB, not the 3 KB reported — .esphome/platformio is 508 MB of PlatformIO toolchain and .esphome/build another 31 MB, both regenerable. Relocating as-asked would have inflated restic's /opt/docker source ~45x against its own ~12 MB budget, so both subtrees are excluded in /etc/restic/profiles.yaml. The 3 KB of actual config is now covered, which was the point. 2026.8.2 logs a DEPRECATION for the bare USERNAME/PASSWORD env names and says they will stop working in a future release — a silent auth loss on some later bump, on a privileged host-network container that can flash any ESP device on the LAN. Switched to ESPHOME_USERNAME/ESPHOME_PASSWORD; the warning is gone. Device Builder 1.0.0 opens a NEW listener on 0.0.0.0:6055 (remote-build peer-link) that 2025.8.2 did not have. Also fixes deploy-stack.sh: plain 'rsync -a' makes rsync chgrp the destination as the deploy identity, which since the 2026-09-14 root:docker normalisation is not root. It failed with 'Operation not permitted' and exit 23 AFTER transferring content — a loud error on a deploy that had succeeded. --no-o --no-g lets the setgid bit assign the group instead.
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
# ESPHome Device Builder — IoT firmware dashboard for the ESH ESP32/ESP8266 fleet.
|
||||
# Host: esh-docker-vm (10.0.50.45). UI: http://10.0.50.45:6052
|
||||
#
|
||||
# ⚠ privileged + network_mode: host are REQUIRED and must not be "hardened" away:
|
||||
# USB flashing needs the former, mDNS device discovery the latter. Removing
|
||||
# either breaks adoption and OTA.
|
||||
#
|
||||
# ⚠ The image tag is pinned deliberately. A bare `ghcr.io/esphome/esphome`
|
||||
# drifted this container a full year: docker pulled `latest` once when the
|
||||
# container was created (2026-04-20, from a layer already cached 2025-08-29) and
|
||||
# never re-pulled, leaving it on 2025.8.2 — twelve releases behind — which
|
||||
# silently failed config validation for every current Everything Presence
|
||||
# sensor. Bump this line on purpose; do not un-pin it.
|
||||
services:
|
||||
esphome:
|
||||
container_name: esphome
|
||||
image: ghcr.io/esphome/esphome:2026.8.2
|
||||
volumes:
|
||||
# Was /path/to/esphome/config — the upstream template placeholder, taken
|
||||
# literally by docker. Nothing was broken (compose and the container
|
||||
# agreed) but /path/to is in none of restic's sources, so the configs and
|
||||
# secrets.yaml were absent from file-level backup. Moved 2026-09-14 to
|
||||
# match the sibling mosquitto pattern.
|
||||
- /opt/docker/conf/esphome:/config
|
||||
- /etc/localtime:/etc/localtime:ro
|
||||
restart: always
|
||||
privileged: true
|
||||
network_mode: host
|
||||
environment:
|
||||
# Values live in .env beside this file on the host (root:docker 0640) and
|
||||
# in Vaultwarden at esh-docker-vm/esphome-dashboard. Never inline them
|
||||
# here — this file is git-tracked.
|
||||
#
|
||||
# ⚠ Use the ESPHOME_-prefixed names, not bare USERNAME / PASSWORD. 2026.8.2
|
||||
# still honours the bare names but logs a DEPRECATION on every start and
|
||||
# says they "will stop working in a future release" — i.e. a silent auth
|
||||
# loss on some later bump, on a privileged host-network container that can
|
||||
# flash firmware to anything on the LAN. Observed in the container log on
|
||||
# the 2025.8.2 -> 2026.8.2 upgrade, 2026-09-14.
|
||||
- ESPHOME_USERNAME=${ESPHOME_USERNAME}
|
||||
- ESPHOME_PASSWORD=${ESPHOME_PASSWORD}
|
||||
labels:
|
||||
- homepage.group=Apps
|
||||
- homepage.name=ESPHome
|
||||
- homepage.icon=si-esphome
|
||||
- homepage.description=IoT firmware dashboard (ESP32/ESP8266)
|
||||
- homepage.href=http://10.0.50.45:6052
|
||||
Reference in New Issue
Block a user