birdnet-go-dev: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH option (#3096)

* birdnet-go: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH (dev)

The ingress nginx server in both birdnet-go add-ons listened on the add-on's
hassio-network address with no source restriction, so any other add-on
container could reach it directly (verified: HTTP 200 from another add-on).
Allow only the Supervisor's ingress proxy (172.30.32.2), as Home Assistant
requires and as calibre_web already does.

birdnet-go-dev gains an INGRESS_SKIP_AUTH option (default false). It is
exported as an env var by 00-global_var.sh and read by the fork
(alexbelgium/birdnet-go#80) to skip BirdNET-Go's own login for ingress
requests only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* birdnet-go: drop stable add-on changes; keep this PR to birdnet-go-dev

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: BirdNET-Go Addon Builder <addon-builder@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Alexandre
2026-09-30 13:27:54 +02:00
committed by GitHub
parent 449f147bc9
commit 4501a7e330
4 changed files with 19 additions and 1 deletions

View File

@@ -1,3 +1,6 @@
## 20260929.1 (30-09-2026)
- New `INGRESS_SKIP_AUTH` option (default `false`): when `true`, BirdNET-Go no longer asks for its own login when opened through the Home Assistant sidebar (ingress), since Home Assistant has already signed you in. Direct access on port 8080 still requires the login.
- Security: the ingress web server now only accepts connections from the Home Assistant Supervisor, as Home Assistant requires.
## 20260929 (29-09-2026)
- Synced with upstream; merged open PRs (conflicts in #62, #63, #79 resolved)
## 20260920.2 (19-09-2026)

View File

@@ -57,6 +57,7 @@ env_vars: [] # extra environment variables to pass to the container
TZ: Etc/UTC # timezone, see https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
mqtt_auto_config: false # set true to auto-wire the Home Assistant MQTT addon into config.yaml
mariadb_auto_config: false # set true to auto-wire the Home Assistant MariaDB addon into config.yaml (also disables SQLite)
INGRESS_SKIP_AUTH: false # set true to skip the BirdNET-Go login when opened through the Home Assistant sidebar (ingress)
```
- Config.yaml
@@ -97,6 +98,14 @@ In practice it only bites when a single audio source has two or more bird models
Requires [alexbelgium/birdnet-go#63](https://github.com/alexbelgium/birdnet-go/pull/63).
#### Skip login through ingress
With `INGRESS_SKIP_AUTH: true`, BirdNET-Go does not show its own login page when you open it from the Home Assistant sidebar (ingress), because Home Assistant has already signed you in. Access on port 8080, and API access, still require the BirdNET-Go login as before.
**Off by default.** Every Home Assistant user who can open the add-on panel, including non-administrators, then gets full access to BirdNET-Go, settings included. Changing the option requires an add-on restart.
Requires [alexbelgium/birdnet-go#80](https://github.com/alexbelgium/birdnet-go/pull/80).
### MQTT and MariaDB auto-configuration (opt-in)
If the Home Assistant **MQTT** addon is installed and running and you set `mqtt_auto_config: true` in the addon options, the addon writes the HA Mosquitto credentials directly into BirdNET-Go's `config.yaml` on every startup: `realtime.mqtt.enabled`, `broker`, `username`, and `password` are populated, and the topic defaults to `birdnet`. In addition, it enables BirdNET-Go's **native Home Assistant MQTT auto-discovery** (`realtime.mqtt.homeassistant.enabled`), so the detection sensors show up in Home Assistant automatically — **no manual MQTT sensor YAML required** (the hand-written sensors in [HAINTEGRATION.md](./HAINTEGRATION.md) remain available if you prefer to build your own). Messages are also retained (`realtime.mqtt.retain: true`) so sensor states survive Home Assistant restarts. When the option is `false` (the default), the addon still logs the broker details and reminds you about the option whenever Mosquitto is detected — nothing is written.

View File

@@ -92,6 +92,7 @@ options:
homeassistant_microphone: false
mqtt_auto_config: false
mariadb_auto_config: false
INGRESS_SKIP_AUTH: false
panel_admin: false
panel_icon: mdi:bird
ports:
@@ -110,6 +111,7 @@ schema:
value: str?
BIRDSONGS_FOLDER: str?
LOG_MAX_SIZE_MB: int(1,1000)?
INGRESS_SKIP_AUTH: bool?
LOG_MAX_AGE_DAYS: int(1,365)?
TZ: str?
cifsdomain: str?
@@ -127,5 +129,5 @@ slug: birdnet-go-dev
udev: true
url: https://github.com/alexbelgium/hassio-addons
usb: true
version: "20260929"
version: "20260929.1"
video: true

View File

@@ -4,6 +4,10 @@ server {
include /etc/nginx/includes/proxy_params.conf;
location / {
# Only the Supervisor's ingress proxy may use this server.
allow 172.30.32.2;
deny all;
proxy_pass http://localhost:8080/;
rewrite ^%%ingress_entry%%/?(.*)$ /$1 break;