Files
Alexandre 4501a7e330 birdnet-go-dev: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH option (#3096)
* birdnet-go: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH (dev)

The ingress nginx server in both birdnet-go add-ons listened on the add-on's
hassio-network address with no source restriction, so any other add-on
container could reach it directly (verified: HTTP 200 from another add-on).
Allow only the Supervisor's ingress proxy (172.30.32.2), as Home Assistant
requires and as calibre_web already does.

birdnet-go-dev gains an INGRESS_SKIP_AUTH option (default false). It is
exported as an env var by 00-global_var.sh and read by the fork
(alexbelgium/birdnet-go#80) to skip BirdNET-Go's own login for ingress
requests only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* birdnet-go: drop stable add-on changes; keep this PR to birdnet-go-dev

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: BirdNET-Go Addon Builder <addon-builder@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:27:54 +02:00
..