Compare commits

...

19 Commits

Author SHA1 Message Date
github-actions
bc3801f290 GitHub bot: changelog [nobuild] 2026-06-04 14:37:20 +00:00
Alexandre
1e66d635f3 Update config.yaml 2026-06-04 16:34:32 +02:00
GitHub Actions
a8dbdabc40 Revert "Update config.yaml"
This reverts commit cd5ce11c37.
2026-06-04 14:12:17 +00:00
Alexandre
cd5ce11c37 Update config.yaml 2026-06-04 16:09:35 +02:00
Alexandre
f77964e501 Update 99-run.sh 2026-06-04 16:09:26 +02:00
Alexandre
a8d67aa4a6 Merge pull request #2761 from alexbelgium/claude/ente-addon-review-lM4Zu
ente: fix SIGPIPE (exit 141) on startup from tr|head -c /dev/urandom …
2026-06-04 15:46:26 +02:00
Claude
b91c5c056a ente: fix SIGPIPE (exit 141) on startup from tr|head -c /dev/urandom pattern
tr reads from the infinite /dev/urandom stream; head exits after N bytes,
closing the pipe, which sends SIGPIPE to tr (exit 141). With set -euo pipefail
at the top of 99-run.sh, pipefail surfaces that as the script exit code and
the container never starts. Suppress it with || true on both occurrences in
the MinIO credential generation block.

https://claude.ai/code/session_01MaLKhb2CJiF9Fb3Dyr585r
2026-06-04 13:42:41 +00:00
Alexandre
fe00c57724 Merge pull request #2760 from alexbelgium/claude/ente-addon-review-lM4Zu
ente: fix apparmor name, expose accounts/auth/cast ports, harden DB config
2026-06-04 15:35:59 +02:00
Claude
e1679a0e04 ente: fix apparmor name, expose accounts/auth/cast ports, harden DB config
- Rename AppArmor profile from the leftover qbittorrent name to ente_addon
  to avoid colliding with the qbittorrent add-on's profile
- Map the Accounts (3001), Auth (3003) and Cast (3004) ports so the login,
  2FA and cast web apps served by nginx are actually reachable
- Default the external Postgres port to 5432 when DB_PORT is left blank
- Write the resolved DB host/port to museum.yaml so external databases are
  configured correctly on disk, not just via env overrides
- Exclude minio-data and postgres from Home Assistant backups to avoid
  pulling the whole photo library and database into every backup

https://claude.ai/code/session_01MaLKhb2CJiF9Fb3Dyr585r
2026-06-04 13:34:17 +00:00
Alexandre
d47d0e197d Update 99-run.sh 2026-06-04 15:32:32 +02:00
github-actions
da16296665 GitHub bot: changelog [nobuild] 2026-06-04 13:22:19 +00:00
Alexandre
3f3591516f Update config.yaml 2026-06-04 15:19:26 +02:00
Alexandre
aed596959d Merge pull request #2759 from alexbelgium/copilot/fix-comments-in-review-thread
Fix Ente addon: idempotent web start, random MinIO creds, bind console, fix albums origin
2026-06-04 15:18:26 +02:00
copilot-swe-agent[bot]
41e3ba6119 Address PR review: random MinIO creds, idempotent web start, bind console, fix albums origin
1. Generate random MinIO credentials on first run, persist to /config/minio-creds,
   reuse on restart. Export MINIO_ROOT_USER/PASSWORD env vars for MinIO server.
2. Make nginx web startup idempotent by checking if web.bak exists before moving.
3. Bind MinIO console to 127.0.0.1:9001 with --console-address.
4. Expose port 3002 (albums) in config.yaml and derive ENTE_ALBUMS_ORIGIN from
   the API endpoint host with the mapped external port 8302.
2026-06-04 13:17:15 +00:00
copilot-swe-agent[bot]
7ddeadba1c Initial plan 2026-06-04 13:13:57 +00:00
Alexandre
97ba73eb2f Merge pull request #2758 from alexbelgium/copilot/fix-ente-webui-accessibility
Troubleshooting ente webui accessibility problem
2026-06-04 15:10:37 +02:00
copilot-swe-agent[bot]
89df640115 fix(ente): fix API origin for web UI, remove dead options, hardcode MinIO creds 2026-06-04 12:57:34 +00:00
copilot-swe-agent[bot]
1cf986a885 feat(ente): remove DISABLE_WEB_UI option, make MinIO internal-only, bump to 4.4.22-3 2026-06-04 12:38:32 +00:00
copilot-swe-agent[bot]
07320ae0ab fix(ente): change DISABLE_WEB_UI default to false so web UI is accessible 2026-06-04 12:32:11 +00:00
5 changed files with 81 additions and 48 deletions

View File

@@ -1,3 +1,23 @@
## 4.4.22-7 (04-06-2026)
- Minor bugs fixed
## 4.4.22-6 (04-06-2026)
- Fix SIGPIPE (exit 141) on startup: tr piped to head -c against /dev/urandom
now suppresses the expected SIGPIPE under set -o pipefail
## 4.4.22-5 (04-06-2026)
- Fix AppArmor profile name (was copied from qbittorrent, could collide with that add-on)
- Expose Accounts (3001), Auth (3003) and Cast (3004) ports so the login/2FA web apps are reachable
- Default external Postgres port to 5432 when DB_PORT is left blank
- Write the correct DB host/port to museum.yaml when using an external database
- Exclude minio-data and postgres folders from Home Assistant backups
## 4.4.22-4 (04-06-2026)
- Minor bugs fixed
## 4.4.22-3 (04-06-2026)
- Remove DISABLE_WEB_UI option, web UI is now always enabled
- Make MinIO internal-only (127.0.0.1) since museum proxies S3 operations
- Fix web UI API origin: use ENTE_ENDPOINT_URL so browsers can reach the API
- Hardcode MinIO credentials internally (no longer user-configurable)
- Remove dead options: MINIO_DATA_LOCATION, MINIO_ROOT_USER, MINIO_ROOT_PASSWORD
## 4.4.22-2 (04-06-2026)
- Minor bugs fixed

View File

@@ -53,12 +53,8 @@ Webui can be found at <http://homeassistant:PORT>.
| Option | Type | Default | Description |
|--------|------|---------|-------------|
| `ENTE_ENDPOINT_URL` | str | `http://homeassistant.local:8280` | The URL where Ente API will be accessible |
| `MINIO_ROOT_USER` | str | `minioadmin` | MinIO root username |
| `MINIO_ROOT_PASSWORD` | str | `minioadmin` | MinIO root password |
| `MINIO_DATA_LOCATION` | str | `/config/minio-data` | Path where MinIO stores data |
| `ENTE_ENDPOINT_URL` | str | `http://homeassistant.local:8280` | The URL where Ente API will be accessible (used by web UI) |
| `DB_PASSWORD` | str | `ente` | Database password for internal PostgreSQL |
| `DISABLE_WEB_UI` | bool | `true` | Disable the web UI (use mobile/desktop apps) |
| `USE_EXTERNAL_DB` | bool | `false` | Use external PostgreSQL database |
| `TZ` | str | `Europe/Paris` | Timezone setting |
@@ -77,11 +73,7 @@ If you want to use an external PostgreSQL database, set `USE_EXTERNAL_DB: true`
```yaml
ENTE_ENDPOINT_URL: "http://homeassistant.local:8280"
MINIO_ROOT_USER: "myuser"
MINIO_ROOT_PASSWORD: "mypassword"
MINIO_DATA_LOCATION: "/config/ente-storage"
DB_PASSWORD: "securepassword"
DISABLE_WEB_UI: false
TZ: "America/New_York"
```
@@ -137,11 +129,17 @@ After starting the addon for the first time:
## Ports
The addon exposes three ports:
The addon exposes the following ports:
- **8300** (3000/tcp): Ente web UI (if enabled)
- **8300** (3000/tcp): Ente web UI
- **8305** (3005/tcp): Ente Share
- **8306** (3006/tcp): Ente Embed
- **8307** (3007/tcp): Ente Paste
- **8308** (3008/tcp): Ente Locker
- **8309** (3009/tcp): Ente Memories
- **8280** (8080/tcp): Ente API server (museum) - Main endpoint for apps
- **8320** (3200/tcp): MinIO S3 endpoint (for storage backend)
MinIO S3 is internal-only (127.0.0.1:3200) and not exposed externally since museum proxies all S3 operations.
## Data Storage

View File

@@ -1,6 +1,6 @@
#include <tunables/global>
profile db21ed7f_qbittorrent flags=(attach_disconnected,mediate_deleted) {
profile ente_addon flags=(attach_disconnected,mediate_deleted) {
#include <abstractions/base>
capability chown,
@@ -43,7 +43,6 @@ profile db21ed7f_qbittorrent flags=(attach_disconnected,mediate_deleted) {
/init rix,
/var/run/** mrwkl,
/var/run/ mrwkl,
/dev/i2c-1 mrwkl,
# Files required
/dev/fuse mrwkl,
/dev/sda1 mrwkl,

View File

@@ -1,6 +1,9 @@
arch:
- aarch64
- amd64
backup_exclude:
- "**/minio-data/**"
- "**/postgres/**"
description:
Self-hosted, end-to-end-encrypted photo & video storage (Ente server
+ MinIO)
@@ -78,30 +81,32 @@ name: Ente
options:
env_vars: []
DB_PASSWORD: ente
DISABLE_WEB_UI: true
ENTE_ENDPOINT_URL: http://homeassistant.local:8280
MINIO_DATA_LOCATION: /config/minio-data
MINIO_ROOT_PASSWORD: minioadmin
MINIO_ROOT_USER: minioadmin
TZ: Europe/Paris
USE_EXTERNAL_DB: false
ports:
3000/tcp: 8300
3001/tcp: 8301
3002/tcp: 8302
3003/tcp: 8303
3004/tcp: 8304
3005/tcp: 8305
3006/tcp: 8306
3007/tcp: 8307
3008/tcp: 8308
3009/tcp: 8309
3200/tcp: 8320
8080/tcp: 8280
ports_description:
3000/tcp: Ente web UI
3001/tcp: Ente Accounts
3002/tcp: Ente Albums
3003/tcp: Ente Auth
3004/tcp: Ente Cast
3005/tcp: Ente Share
3006/tcp: Ente Embed
3007/tcp: Ente Paste
3008/tcp: Ente Locker
3009/tcp: Ente Memories
3200/tcp: MinIO S3 endpoint
8080/tcp: Ente API (museum)
privileged:
- SYS_ADMIN
@@ -115,11 +120,7 @@ schema:
DB_PASSWORD: str
DB_PORT: int?
DB_USERNAME: str?
DISABLE_WEB_UI: bool?
ENTE_ENDPOINT_URL: str
MINIO_DATA_LOCATION: str
MINIO_ROOT_PASSWORD: str
MINIO_ROOT_USER: str
TZ: str?
USE_EXTERNAL_DB: bool?
cifsdomain: str?
@@ -130,6 +131,6 @@ schema:
slug: ente
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "4.4.22-2"
version: "4.4.22-7"
video: true
webui: http://[HOST]:[PORT:3000]

View File

@@ -1,15 +1,32 @@
#!/usr/bin/env bashio
# shellcheck shell=bash
set -euo pipefail
MINIO_USER="$(bashio::config 'MINIO_ROOT_USER')"
MINIO_PASS="$(bashio::config 'MINIO_ROOT_PASSWORD')"
# Internal MinIO credentials (not user-configurable; MinIO is 127.0.0.1 only)
MINIO_CRED_FILE="/config/minio-creds"
if [ -f "$MINIO_CRED_FILE" ]; then
# Reuse persisted credentials across restarts
MINIO_USER="$(sed -n '1p' "$MINIO_CRED_FILE")"
MINIO_PASS="$(sed -n '2p' "$MINIO_CRED_FILE")"
# Regenerate if file is corrupted
if [ -z "$MINIO_USER" ] || [ -z "$MINIO_PASS" ]; then
MINIO_USER="minio_$(head -c 4 /dev/urandom | od -An -tx1 | tr -d ' \n')"
MINIO_PASS="$(head -c 24 /dev/urandom | base64 | tr -d '\n')"
printf '%s\n%s\n' "$MINIO_USER" "$MINIO_PASS" > "$MINIO_CRED_FILE"
chmod 600 "$MINIO_CRED_FILE"
fi
else
# Generate random credentials on first run
MINIO_USER="minio_$(head -c 4 /dev/urandom | od -An -tx1 | tr -d ' \n')"
MINIO_PASS="$(head -c 24 /dev/urandom | base64 | tr -d '\n')"
printf '%s\n%s\n' "$MINIO_USER" "$MINIO_PASS" > "$MINIO_CRED_FILE"
chmod 600 "$MINIO_CRED_FILE"
fi
S3_BUCKET="b2-eu-cen"
export ENTE_S3_ARE_LOCAL_BUCKETS=true
export ENTE_S3_B2_EU_CEN_KEY="$MINIO_USER"
export ENTE_S3_B2_EU_CEN_SECRET="$MINIO_PASS"
export ENTE_S3_B2_EU_CEN_ENDPOINT="http://192.168.178.23:$(bashio::addon.port "3200")"
export ENTE_S3_B2_EU_CEN_ENDPOINT="http://127.0.0.1:3200"
export ENTE_S3_B2_EU_CEN_REGION=eu-central-2
export ENTE_S3_B2_EU_CEN_BUCKET="$S3_BUCKET"
@@ -33,6 +50,8 @@ DB_PASS="$(bashio::config 'DB_PASSWORD' || echo ente)"
# External DB opts (may be blank)
DB_HOST_EXT="$(bashio::config 'DB_HOSTNAME' || echo '')"
DB_PORT_EXT="$(bashio::config 'DB_PORT' || echo '')"
# Default external Postgres port when unset
[ -z "$DB_PORT_EXT" ] && DB_PORT_EXT=5432
USE_EXTERNAL_DB=false
if bashio::config.true 'USE_EXTERNAL_DB'; then
@@ -42,11 +61,6 @@ else
bashio::log.info "Using internal Postgres."
fi
DISABLE_WEB_UI=false
if bashio::config.true 'DISABLE_WEB_UI'; then
DISABLE_WEB_UI=true
fi
# Active DB connection target (may be overridden below)
if $USE_EXTERNAL_DB; then
DB_HOST="$DB_HOST_EXT"
@@ -95,8 +109,8 @@ jwt:
secret: $(_rand_b64url 32)
db:
host: ${DB_HOST_INTERNAL}
port: ${DB_PORT_INTERNAL}
host: ${DB_HOST}
port: ${DB_PORT}
name: ${DB_NAME}
user: ${DB_USER}
password: ${DB_PASS}
@@ -186,9 +200,11 @@ bootstrap_internal_db() {
# MinIO
############################################
start_minio() {
bashio::log.info "Starting MinIO (:3200)..."
bashio::log.info "Starting MinIO (127.0.0.1:3200)..."
mkdir -p /config/minio-data
"$MINIO_BIN" server /config/minio-data --address ":3200" &
export MINIO_ROOT_USER="$MINIO_USER"
export MINIO_ROOT_PASSWORD="$MINIO_PASS"
"$MINIO_BIN" server /config/minio-data --address "127.0.0.1:3200" --console-address "127.0.0.1:9001" &
MINIO_PID=$!
}
@@ -206,13 +222,10 @@ wait_minio_ready_and_bucket() {
# Web (static nginx bundle)
############################################
start_web() {
if $DISABLE_WEB_UI; then
bashio::log.info "Web UI disabled."
return 0
fi
ENTE_API_ORIGIN=http://localhost:8080
ENTE_ALBUMS_ORIGIN=http://localhost:3002
ENTE_API_ORIGIN="$(bashio::config 'ENTE_ENDPOINT_URL')"
# Derive albums origin from the same host as the API endpoint, mapped to port 8302
ENTE_ALBUMS_HOST="$(echo "$ENTE_API_ORIGIN" | sed -E 's#(https?://[^:/]+).*#\1#')"
ENTE_ALBUMS_ORIGIN="${ENTE_ALBUMS_HOST}:8302"
export ENTE_API_ORIGIN ENTE_ALBUMS_ORIGIN
# Running ente-web-prepare
@@ -222,11 +235,13 @@ start_web() {
mkdir -p /run/nginx /var/log/nginx
# Set nginx
mv /etc/nginx/http.d/web.bak /etc/nginx/http.d/web.conf
# Set nginx (idempotent: only move if .bak still exists)
if [ -f /etc/nginx/http.d/web.bak ]; then
mv /etc/nginx/http.d/web.bak /etc/nginx/http.d/web.conf
fi
bashio::log.info "Starting Ente web (nginx, ports 3000‑3009)..."
exec nginx -g 'daemon off;' &
nginx -g 'daemon off;' &
WEB_PID=$!
}