mirror of
https://github.com/alexbelgium/hassio-addons.git
synced 2026-09-30 21:42:42 +02:00
birdnet-go-dev: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH option (#3096)
* birdnet-go: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH (dev) The ingress nginx server in both birdnet-go add-ons listened on the add-on's hassio-network address with no source restriction, so any other add-on container could reach it directly (verified: HTTP 200 from another add-on). Allow only the Supervisor's ingress proxy (172.30.32.2), as Home Assistant requires and as calibre_web already does. birdnet-go-dev gains an INGRESS_SKIP_AUTH option (default false). It is exported as an env var by 00-global_var.sh and read by the fork (alexbelgium/birdnet-go#80) to skip BirdNET-Go's own login for ingress requests only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * birdnet-go: drop stable add-on changes; keep this PR to birdnet-go-dev Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: BirdNET-Go Addon Builder <addon-builder@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,3 +1,6 @@
|
||||
## 20260929.1 (30-09-2026)
|
||||
- New `INGRESS_SKIP_AUTH` option (default `false`): when `true`, BirdNET-Go no longer asks for its own login when opened through the Home Assistant sidebar (ingress), since Home Assistant has already signed you in. Direct access on port 8080 still requires the login.
|
||||
- Security: the ingress web server now only accepts connections from the Home Assistant Supervisor, as Home Assistant requires.
|
||||
## 20260929 (29-09-2026)
|
||||
- Synced with upstream; merged open PRs (conflicts in #62, #63, #79 resolved)
|
||||
## 20260920.2 (19-09-2026)
|
||||
|
||||
@@ -57,6 +57,7 @@ env_vars: [] # extra environment variables to pass to the container
|
||||
TZ: Etc/UTC # timezone, see https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
|
||||
mqtt_auto_config: false # set true to auto-wire the Home Assistant MQTT addon into config.yaml
|
||||
mariadb_auto_config: false # set true to auto-wire the Home Assistant MariaDB addon into config.yaml (also disables SQLite)
|
||||
INGRESS_SKIP_AUTH: false # set true to skip the BirdNET-Go login when opened through the Home Assistant sidebar (ingress)
|
||||
```
|
||||
|
||||
- Config.yaml
|
||||
@@ -97,6 +98,14 @@ In practice it only bites when a single audio source has two or more bird models
|
||||
|
||||
Requires [alexbelgium/birdnet-go#63](https://github.com/alexbelgium/birdnet-go/pull/63).
|
||||
|
||||
#### Skip login through ingress
|
||||
|
||||
With `INGRESS_SKIP_AUTH: true`, BirdNET-Go does not show its own login page when you open it from the Home Assistant sidebar (ingress), because Home Assistant has already signed you in. Access on port 8080, and API access, still require the BirdNET-Go login as before.
|
||||
|
||||
**Off by default.** Every Home Assistant user who can open the add-on panel, including non-administrators, then gets full access to BirdNET-Go, settings included. Changing the option requires an add-on restart.
|
||||
|
||||
Requires [alexbelgium/birdnet-go#80](https://github.com/alexbelgium/birdnet-go/pull/80).
|
||||
|
||||
### MQTT and MariaDB auto-configuration (opt-in)
|
||||
|
||||
If the Home Assistant **MQTT** addon is installed and running and you set `mqtt_auto_config: true` in the addon options, the addon writes the HA Mosquitto credentials directly into BirdNET-Go's `config.yaml` on every startup: `realtime.mqtt.enabled`, `broker`, `username`, and `password` are populated, and the topic defaults to `birdnet`. In addition, it enables BirdNET-Go's **native Home Assistant MQTT auto-discovery** (`realtime.mqtt.homeassistant.enabled`), so the detection sensors show up in Home Assistant automatically — **no manual MQTT sensor YAML required** (the hand-written sensors in [HAINTEGRATION.md](./HAINTEGRATION.md) remain available if you prefer to build your own). Messages are also retained (`realtime.mqtt.retain: true`) so sensor states survive Home Assistant restarts. When the option is `false` (the default), the addon still logs the broker details and reminds you about the option whenever Mosquitto is detected — nothing is written.
|
||||
|
||||
@@ -92,6 +92,7 @@ options:
|
||||
homeassistant_microphone: false
|
||||
mqtt_auto_config: false
|
||||
mariadb_auto_config: false
|
||||
INGRESS_SKIP_AUTH: false
|
||||
panel_admin: false
|
||||
panel_icon: mdi:bird
|
||||
ports:
|
||||
@@ -110,6 +111,7 @@ schema:
|
||||
value: str?
|
||||
BIRDSONGS_FOLDER: str?
|
||||
LOG_MAX_SIZE_MB: int(1,1000)?
|
||||
INGRESS_SKIP_AUTH: bool?
|
||||
LOG_MAX_AGE_DAYS: int(1,365)?
|
||||
TZ: str?
|
||||
cifsdomain: str?
|
||||
@@ -127,5 +129,5 @@ slug: birdnet-go-dev
|
||||
udev: true
|
||||
url: https://github.com/alexbelgium/hassio-addons
|
||||
usb: true
|
||||
version: "20260929"
|
||||
version: "20260929.1"
|
||||
video: true
|
||||
|
||||
@@ -4,6 +4,10 @@ server {
|
||||
include /etc/nginx/includes/proxy_params.conf;
|
||||
|
||||
location / {
|
||||
# Only the Supervisor's ingress proxy may use this server.
|
||||
allow 172.30.32.2;
|
||||
deny all;
|
||||
|
||||
proxy_pass http://localhost:8080/;
|
||||
rewrite ^%%ingress_entry%%/?(.*)$ /$1 break;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user