Files
esh-pfi-infrastructure/stacks/matter-server
vh 8e7ae0675d feat(esh-matter): Matter server (matter.js 1.4.0) on a VLAN-90-only LXC for Home Assistant
For ha-dev (operator-approved 2026-09-26). CT 111 on esh-pve at 10.0.90.20:
Matter/Thread IPv6 (Echo ULA + RA route-information) is link-only, so the
server sits on esh-iot and HA reaches it over routed IPv4 ws :5580.
- playbooks/esh-matter-lxc.yaml: kernel RA (accept_ra=1,
  rt_info_max_plen=64), forwarding off, Docker ip-forward/iptables off;
  nftables admits 5580 from HA 10.0.50.46 only and SSH from mgmt ranges;
  the CT is added to esh-pve's vzdump job (fabric credentials).
- stacks/matter-server: ghcr.io/matter-js/matterjs-server:1.4.0 (digest),
  host networking, /data on the CT.
- Acceptance: fdad:: SLAAC, ping6 thermostat, 2 Thread RIO routes learned, ws
  server_info from inside the HA container; 5580 refused from 10.0.50.45,
  nh3-dev and a temporary VLAN 90 netns vantage.
2026-09-26 13:07:22 -07:00
..

matter-server

The Matter controller for Home Assistant: matter.js server (ghcr.io/matter-js/matterjs-server, 1.4.0, digest-pinned) on esh-matter (CT 111, VLAN 90 only, 10.0.90.20), with host networking. HA's matter integration connects to ws://10.0.90.20:5580/ws.

  • matter.js server is the drop-in successor to python-matter-server (HA has used it since 2026.2), with the same websocket API.
  • /data → /opt/docker/data/matter-server (owned by uid 1000, the image's unprivileged user) holds the fabric root credentials. It is covered by the CT's vzdump backup. Never commit it.
  • :5580 is unauthenticated, so the CT firewall admits HA (10.0.50.46) only.
  • Host requirements (IPv6 RA with route-info, forwarding off) and acceptance results: servers/esh-matter/README.md.

Deploy: scripts/deploy-stack.sh esh-matter matter-server, then on the host cp -n .env.example .env && docker compose config -q && docker compose up -d.