Compare commits

...

10 Commits

Author SHA1 Message Date
Alexandre
87313d3c95 Update entry validation for local mounts script
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-10-01 20:35:15 +02:00
alexbelgium
b9a8daeca5 claude_desktop: stop reusing the template layer of the first build
The builder takes the previous image as layer cache, and the Dockerfile's
module download RUN never changes, so every rebuild since 2026-08-20 reused
the old .templates/ scripts. The published 07308545.11 and .12 images are the
2026-08-20 image under new tags. #3076's `localdisks: NAS/folder` therefore
never reached claude_desktop, and the old script reported "folder does not
match any known physical device".

Add a BUILD_DATE marker to that RUN, as birdnet-go-dev does, so the template
download re-runs on every CI build.

Also name the whole entry in the "does not match" message, with a hint for
folder entries: it used to print only the part after the last slash.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-01 15:53:35 +02:00
github-actions
696528997f GitHub bot: changelog [nobuild] 2026-10-01 13:38:25 +00:00
Alexandre
a2a3f1fe46 Update config.yaml 2026-10-01 15:36:09 +02:00
github-actions
321b982c1b GitHub bot: changelog [nobuild] 2026-10-01 13:34:12 +00:00
Alexandre
08f7e3d703 Update config.yaml 2026-10-01 15:32:05 +02:00
Alexandre
7bec7f75c4 Update config.yaml 2026-10-01 15:28:35 +02:00
Alexandre
4501a7e330 birdnet-go-dev: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH option (#3096)
* birdnet-go: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH (dev)

The ingress nginx server in both birdnet-go add-ons listened on the add-on's
hassio-network address with no source restriction, so any other add-on
container could reach it directly (verified: HTTP 200 from another add-on).
Allow only the Supervisor's ingress proxy (172.30.32.2), as Home Assistant
requires and as calibre_web already does.

birdnet-go-dev gains an INGRESS_SKIP_AUTH option (default false). It is
exported as an env var by 00-global_var.sh and read by the fork
(alexbelgium/birdnet-go#80) to skip BirdNET-Go's own login for ingress
requests only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* birdnet-go: drop stable add-on changes; keep this PR to birdnet-go-dev

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: BirdNET-Go Addon Builder <addon-builder@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:27:54 +02:00
alexbelgium
449f147bc9 birdnet-go-dev: bump to 20260929
Fork synced with upstream and PR conflicts resolved (#62, #63, #79).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-29 09:10:23 +02:00
dependabot[bot]
71d3416aaf build(deps): bump anthropics/claude-code-action from 1.0.230 to 1.0.235 (#3095)
Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.230 to 1.0.235.
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](4036a180cf...756cc22e19)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.235
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-29 09:00:26 +02:00
13 changed files with 44 additions and 10 deletions

View File

@@ -125,7 +125,7 @@ jobs:
- name: Analyse and fix
if: steps.batch.outputs.count != '0'
uses: anthropics/claude-code-action@4036a180cf690f49529f5d8c79c998855287f590 # v1
uses: anthropics/claude-code-action@756cc22e19660d20e8cc9496b4f242475a7f7790 # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Skip the OIDC -> Claude App token exchange. The scheduled path

View File

@@ -64,7 +64,7 @@ jobs:
fetch-depth: 1
- name: Run Claude Code
uses: anthropics/claude-code-action@4036a180cf690f49529f5d8c79c998855287f590 # v1
uses: anthropics/claude-code-action@756cc22e19660d20e8cc9496b4f242475a7f7790 # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# AI_PR_TOKEN, not GITHUB_TOKEN, so a PR Claude opens triggers CI.

View File

@@ -135,7 +135,7 @@ jobs:
- name: Execute the plan
if: steps.bundle.outputs.has_plan == 'true'
uses: anthropics/claude-code-action@4036a180cf690f49529f5d8c79c998855287f590 # v1
uses: anthropics/claude-code-action@756cc22e19660d20e8cc9496b4f242475a7f7790 # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Skip the OIDC -> Claude App token exchange, which 401s whenever

View File

@@ -166,7 +166,7 @@ jobs:
id: classify
if: github.event_name != 'issue_comment' || steps.claim.outputs.go == 'true'
continue-on-error: true
uses: anthropics/claude-code-action@4036a180cf690f49529f5d8c79c998855287f590 # v1
uses: anthropics/claude-code-action@756cc22e19660d20e8cc9496b4f242475a7f7790 # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Without this the action falls back to the OIDC -> Claude App token

View File

@@ -79,7 +79,7 @@ jobs:
- name: Address CodeRabbit comments
if: steps.claim.outputs.go == 'true'
uses: anthropics/claude-code-action@4036a180cf690f49529f5d8c79c998855287f590 # v1
uses: anthropics/claude-code-action@756cc22e19660d20e8cc9496b4f242475a7f7790 # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Skip the OIDC -> Claude App token exchange, which 401s whenever

View File

@@ -69,7 +69,9 @@ if bashio::config.has_value 'localdisks'; then
echo "... $disk is a device by label"
devpath=/dev/disk/by-label
else
bashio::log.fatal "$disk does not match any known physical device, UUID, or label. "
hint=""
[[ "$entry" == [!/]*/?* && "$prefix" != dev && "$prefix" != disk ]] && hint="For a folder, the text before the first '/' must be the disk. "
bashio::log.fatal "$entry does not match any known physical device, UUID, or label. $hint"
continue
fi

View File

@@ -1,3 +1,8 @@
## 20260929.1 (30-09-2026)
- New `INGRESS_SKIP_AUTH` option (default `false`): when `true`, BirdNET-Go no longer asks for its own login when opened through the Home Assistant sidebar (ingress), since Home Assistant has already signed you in. Direct access on port 8080 still requires the login.
- Security: the ingress web server now only accepts connections from the Home Assistant Supervisor, as Home Assistant requires.
## 20260929 (29-09-2026)
- Synced with upstream; merged open PRs (conflicts in #62, #63, #79 resolved)
## 20260920.2 (19-09-2026)
- Minor bugs fixed
## 20260920 (19-09-2026)

View File

@@ -57,6 +57,7 @@ env_vars: [] # extra environment variables to pass to the container
TZ: Etc/UTC # timezone, see https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
mqtt_auto_config: false # set true to auto-wire the Home Assistant MQTT addon into config.yaml
mariadb_auto_config: false # set true to auto-wire the Home Assistant MariaDB addon into config.yaml (also disables SQLite)
INGRESS_SKIP_AUTH: false # set true to skip the BirdNET-Go login when opened through the Home Assistant sidebar (ingress)
```
- Config.yaml
@@ -97,6 +98,14 @@ In practice it only bites when a single audio source has two or more bird models
Requires [alexbelgium/birdnet-go#63](https://github.com/alexbelgium/birdnet-go/pull/63).
#### Skip login through ingress
With `INGRESS_SKIP_AUTH: true`, BirdNET-Go does not show its own login page when you open it from the Home Assistant sidebar (ingress), because Home Assistant has already signed you in. Access on port 8080, and API access, still require the BirdNET-Go login as before.
**Off by default.** Every Home Assistant user who can open the add-on panel, including non-administrators, then gets full access to BirdNET-Go, settings included. Changing the option requires an add-on restart.
Requires [alexbelgium/birdnet-go#80](https://github.com/alexbelgium/birdnet-go/pull/80).
### MQTT and MariaDB auto-configuration (opt-in)
If the Home Assistant **MQTT** addon is installed and running and you set `mqtt_auto_config: true` in the addon options, the addon writes the HA Mosquitto credentials directly into BirdNET-Go's `config.yaml` on every startup: `realtime.mqtt.enabled`, `broker`, `username`, and `password` are populated, and the topic defaults to `birdnet`. In addition, it enables BirdNET-Go's **native Home Assistant MQTT auto-discovery** (`realtime.mqtt.homeassistant.enabled`), so the detection sensors show up in Home Assistant automatically — **no manual MQTT sensor YAML required** (the hand-written sensors in [HAINTEGRATION.md](./HAINTEGRATION.md) remain available if you prefer to build your own). Messages are also retained (`realtime.mqtt.retain: true`) so sensor states survive Home Assistant restarts. When the option is `false` (the default), the addon still logs the broker details and reminds you about the option whenever Mosquitto is detected — nothing is written.

View File

@@ -92,6 +92,7 @@ options:
homeassistant_microphone: false
mqtt_auto_config: false
mariadb_auto_config: false
INGRESS_SKIP_AUTH: false
panel_admin: false
panel_icon: mdi:bird
ports:
@@ -110,6 +111,7 @@ schema:
value: str?
BIRDSONGS_FOLDER: str?
LOG_MAX_SIZE_MB: int(1,1000)?
INGRESS_SKIP_AUTH: bool?
LOG_MAX_AGE_DAYS: int(1,365)?
TZ: str?
cifsdomain: str?
@@ -127,5 +129,5 @@ slug: birdnet-go-dev
udev: true
url: https://github.com/alexbelgium/hassio-addons
usb: true
version: "20260920.2"
version: "20260929.1"
video: true

View File

@@ -4,6 +4,10 @@ server {
include /etc/nginx/includes/proxy_params.conf;
location / {
# Only the Supervisor's ingress proxy may use this server.
allow 172.30.32.2;
deny all;
proxy_pass http://localhost:8080/;
rewrite ^%%ingress_entry%%/?(.*)$ /$1 break;

View File

@@ -1,3 +1,10 @@
## 07308545.13 (01-10-2026)
- Fix: the image kept the `.templates/` scripts of its first build, because a rebuild reused the cached download layer. Template fixes never reached this add-on, so `localdisks: NAS/folder` still failed with `folder does not match any known physical device`. The layer is now refreshed on every build, which brings in the `disk/folder` support of `localdisks`.
## 07308545.12 (01-10-2026)
- Minor bugs fixed
## 2026.10.01 (01-10-2026)
- Minor bugs fixed
## 07308545.11 (2026-09-24)
- Update to latest version from aaddrick/claude-desktop-debian (changelog : https://github.com/aaddrick/claude-desktop-debian/releases)

View File

@@ -218,8 +218,14 @@ RUN if [ -f /etc/s6-overlay/s6-rc.d/svc-selkies/run ]; then \
# Modules
ARG MODULES="00-banner.sh 00-global_var.sh 01-custom_script.sh 00-local_mounts.sh 00-smb_mounts.sh 90-dns_set.sh"
# BUILD_DATE changes on every CI run, busting this layer's cache. The builder reuses
# the layers of the previous image, so without it a rebuild keeps the .templates/
# scripts downloaded by the first build and never picks up later template changes
ARG BUILD_DATE=unknown
# Automatic modules download
RUN curl -fsSL --retry 3 --retry-delay 2 \
RUN echo "Build date marker: ${BUILD_DATE}" && \
curl -fsSL --retry 3 --retry-delay 2 \
-o /ha_automodules.sh "${TEMPLATE_BASE_URL}/ha_automodules.sh" && \
chmod 744 /ha_automodules.sh && \
/ha_automodules.sh "$MODULES" && \

View File

@@ -3,7 +3,6 @@ arch:
- amd64
audio: true
description: "Claude Desktop with Headroom, RTK, and TokenSave optimization"
devices:
devices:
- /dev/sda
- /dev/sdb
@@ -176,5 +175,5 @@ schema:
slug: claude_desktop
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "07308545.11"
version: "07308545.13"
video: true