From de260eec6289fca5b38fccd40679830ea50d06ea Mon Sep 17 00:00:00 2001 From: David Gwilliam Date: Tue, 30 Jun 2026 23:19:37 -0700 Subject: [PATCH] =?UTF-8?q?Add=20infra/=20=E2=80=94=20full=20stack=20confi?= =?UTF-8?q?g=20as=20deployed=20on=20RPi=203B+?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Captures everything needed to rebuild the stack from scratch: infra/compose.yaml - mosquitto (eclipse-mosquitto:latest) - zigbee2mqtt (ghcr.io/pine64/zigbee2mqtt:latest-dev, BLZ fork) - nodered (nodered/node-red:latest) infra/mosquitto/config/mosquitto.conf - anonymous listener on 1883, file logging, persistence on infra/zigbee2mqtt/ - configuration.yaml: 5 paired devices with friendly names, 1 group - coordinator_backup.json: zigbee network key + pan id (recovery) - state.json: per-device persisted state (ON/OFF, linkquality) infra/nodered/ - settings.js: nodered defaults (flowFile: flows.json, no auth) - start.sh: patches Dashboard 2.0 SPA with at startup Also: - Updated z2m groups section to rename Laser & Fog -> DJ Booth (matches the friendly_name already in devices section) - Pushed the same change to live /root/zigbee2mqtt/configuration.yaml and restarted the zigbee2mqtt container - .gitignore: output/ (regenerated on every build, churns uuid ids) - README.md: link to infra/README.md for rebuild procedure --- README.md | 11 +- infra/README.md | 36 ++ infra/compose.yaml | 55 ++ infra/mosquitto/config/mosquitto.conf | 6 + infra/nodered/settings.js | 648 ++++++++++++++++++++++ infra/nodered/start.sh | 14 + infra/zigbee2mqtt/configuration.yaml | 34 ++ infra/zigbee2mqtt/coordinator_backup.json | 26 + infra/zigbee2mqtt/state.json | 60 ++ 9 files changed, 886 insertions(+), 4 deletions(-) create mode 100644 infra/README.md create mode 100644 infra/compose.yaml create mode 100644 infra/mosquitto/config/mosquitto.conf create mode 100644 infra/nodered/settings.js create mode 100644 infra/nodered/start.sh create mode 100644 infra/zigbee2mqtt/configuration.yaml create mode 100644 infra/zigbee2mqtt/coordinator_backup.json create mode 100644 infra/zigbee2mqtt/state.json diff --git a/README.md b/README.md index c9ede5c..9fa990c 100644 --- a/README.md +++ b/README.md @@ -5,10 +5,11 @@ Declarative Node-RED flows with conftest/Rego validation. Generates `flows.json` ## Layout ``` -flows/.yaml # declarative spec -scripts/flow2json.py # YAML → JSON generator -policy/flow.rego # Rego policy pack (conftest) -output/.json # generated flows.json +infra/ # host stack config (compose, z2m, mosquitto, nodered settings) +flows/.yaml # declarative spec +scripts/flow2json.py # YAML → JSON generator +policy/flow.rego # Rego policy pack (conftest) +output/.json # generated flows.json ``` ## Quick start @@ -20,6 +21,8 @@ just validate # generate + validate just deploy # push to Node-RED at 192.168.81.147:1880 ``` +See `infra/README.md` for the full Docker stack and rebuild procedure. + ## Generation invariants These are enforced by `policy/flow.rego` and burned in from real bugs found in deployment. The generator follows them by construction; the policy is the second line of defense. diff --git a/infra/README.md b/infra/README.md new file mode 100644 index 0000000..fa89221 --- /dev/null +++ b/infra/README.md @@ -0,0 +1,36 @@ +# infra/ + +Full stack configuration as deployed on the RPi 3B+ at `192.168.81.147`. + +## Layout on host + +``` +/root/ +├── compose.yaml → infra/compose.yaml +├── mosquitto/config/mosquitto.conf → infra/mosquitto/config/mosquitto.conf +├── zigbee2mqtt/ → infra/zigbee2mqtt/ +│ ├── configuration.yaml # device pairings + friendly names + groups +│ ├── coordinator_backup.json # zigbee network key + pan id (recovery) +│ └── state.json # per-device persisted state (ON/OFF, etc.) +└── nodered/ → bind-mount for nodered container's /data + ├── flows.json → generated from ../flows/zigbee-monitor.yaml + ├── settings.js → infra/nodered/settings.js + └── start.sh → infra/nodered/start.sh (patches Dashboard SPA) +``` + +## Rebuild procedure from a fresh host + +1. Install Docker, `docker compose`. +2. Clone this repo, `cd infra`. +3. `mkdir -p mosquitto/data mosquitto/log` (empty dirs for the volume mounts). +4. `docker compose up -d`. +5. Pair zigbee devices (IEEE addresses in `zigbee2mqtt/configuration.yaml` will be wrong; re-pair or use the existing `coordinator_backup.json` to rejoin the same network). +6. `just deploy` from the repo root to push the Node-RED flow. + +## Files that drift at runtime + +- `nodered/flows.json` — managed by the generator, do not hand-edit. +- `nodered/node_modules/@flowfuse/node-red-dashboard/dist/index.html` — patched by `start.sh` at every container start; survives reboots, lost on `docker compose down -v`. +- `mosquitto/data/` — broker persistence, transient. +- `zigbee2mqtt/database.db` — sqlite, transient (regenerated from `configuration.yaml` + `coordinator_backup.json`). +- `zigbee2mqtt/state.json` — committed so device ON/OFF state survives full rebuilds. diff --git a/infra/compose.yaml b/infra/compose.yaml new file mode 100644 index 0000000..bb83351 --- /dev/null +++ b/infra/compose.yaml @@ -0,0 +1,55 @@ +services: + mosquitto: + image: eclipse-mosquitto:latest + container_name: mosquitto + restart: unless-stopped + user: "1883:1883" + ports: + - "1883:1883" + volumes: + - ./mosquitto/config:/mosquitto/config + - ./mosquitto/data:/mosquitto/data + - ./mosquitto/log:/mosquitto/log + + zigbee2mqtt: + image: ghcr.io/pine64/zigbee2mqtt:latest-dev # BLZ fork, NOT koenkk + container_name: zigbee2mqtt + restart: unless-stopped + depends_on: + - mosquitto + ports: + - "8080:8080" + volumes: + - ./zigbee2mqtt:/app/data + devices: + - /dev/ttyUSB0:/dev/ttyUSB0 + environment: + TZ: America/Los_Angeles + + # govee2mqtt: + # image: ghcr.io/wez/govee2mqtt:latest + # container_name: govee2mqtt + # restart: unless-stopped + # network_mode: host + # environment: + # GOVEE_EMAIL: your@email.com + # GOVEE_PASSWORD: yourpassword + # GOVEE_API_KEY: your-api-key + # MQTT_HOST: 127.0.0.1 + # TZ: America/Los_Angeles + # + nodered: + image: nodered/node-red:latest + container_name: nodered + restart: unless-stopped + depends_on: + - mosquitto + user: "1000:1000" + ports: + - "1880:1880" + volumes: + - ./nodered:/data + environment: + TZ: America/Los_Angeles + DASHBOARD_BASE_HREF: /dashboard/ + command: ["sh", "/data/start.sh"] diff --git a/infra/mosquitto/config/mosquitto.conf b/infra/mosquitto/config/mosquitto.conf new file mode 100644 index 0000000..8c1df4a --- /dev/null +++ b/infra/mosquitto/config/mosquitto.conf @@ -0,0 +1,6 @@ +listener 1883 +allow_anonymous true + +persistence true +persistence_location /mosquitto/data +log_dest file /mosquitto/log/mosquitto.log diff --git a/infra/nodered/settings.js b/infra/nodered/settings.js new file mode 100644 index 0000000..339d23f --- /dev/null +++ b/infra/nodered/settings.js @@ -0,0 +1,648 @@ +/** + * This is the default settings file provided by Node-RED. + * + * It can contain any valid JavaScript code that will get run when Node-RED + * is started. + * + * Lines that start with // are commented out. + * Each entry should be separated from the entries above and below by a comma ',' + * + * For more information about individual settings, refer to the documentation: + * https://nodered.org/docs/user-guide/runtime/configuration + * + * The settings are split into the following sections: + * - Flow File and User Directory Settings + * - Security + * - Server Settings + * - Runtime Settings + * - Editor Settings + * - Node Settings + * + **/ + +module.exports = { + +/******************************************************************************* + * Flow File and User Directory Settings + * - flowFile + * - credentialSecret + * - flowFilePretty + * - userDir + * - nodesDir + ******************************************************************************/ + + /** The file containing the flows. If not set, defaults to flows_.json **/ + flowFile: 'flows.json', + + /** By default, credentials are encrypted in storage using a generated key. To + * specify your own secret, set the following property. + * If you want to disable encryption of credentials, set this property to false. + * Note: once you set this property, do not change it - doing so will prevent + * node-red from being able to decrypt your existing credentials and they will be + * lost. + */ + //credentialSecret: "a-secret-key", + + /** By default, the flow JSON will be formatted over multiple lines making + * it easier to compare changes when using version control. + * To disable pretty-printing of the JSON set the following property to false. + */ + flowFilePretty: true, + + /** By default, all user data is stored in a directory called `.node-red` under + * the user's home directory. To use a different location, the following + * property can be used + */ + //userDir: '/home/nol/.node-red/', + + /** Node-RED scans the `nodes` directory in the userDir to find local node files. + * The following property can be used to specify an additional directory to scan. + */ + //nodesDir: '/home/nol/.node-red/nodes', + +/******************************************************************************* + * Security + * - adminAuth + * - https + * - httpsRefreshInterval + * - requireHttps + * - httpNodeAuth + * - httpStaticAuth + ******************************************************************************/ + + /** To password protect the Node-RED editor and admin API, the following + * property can be used. See https://nodered.org/docs/security.html for details. + */ + //adminAuth: { + // type: "credentials", + // users: [{ + // username: "admin", + // password: "$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN.", + // permissions: "*" + // }] + //}, + + /** The following property can be used to enable HTTPS + * This property can be either an object, containing both a (private) key + * and a (public) certificate, or a function that returns such an object. + * See http://nodejs.org/api/https.html#https_https_createserver_options_requestlistener + * for details of its contents. + */ + + /** Option 1: static object */ + //https: { + // key: require("fs").readFileSync('privkey.pem'), + // cert: require("fs").readFileSync('cert.pem') + //}, + + /** Option 2: function that returns the HTTP configuration object */ + // https: function() { + // // This function should return the options object, or a Promise + // // that resolves to the options object + // return { + // key: require("fs").readFileSync('privkey.pem'), + // cert: require("fs").readFileSync('cert.pem') + // } + // }, + + /** If the `https` setting is a function, the following setting can be used + * to set how often, in hours, the function will be called. That can be used + * to refresh any certificates. + */ + //httpsRefreshInterval : 12, + + /** The following property can be used to cause insecure HTTP connections to + * be redirected to HTTPS. + */ + //requireHttps: true, + + /** To password protect the node-defined HTTP endpoints (httpNodeRoot), + * including node-red-dashboard, or the static content (httpStatic), the + * following properties can be used. + * The `pass` field is a bcrypt hash of the password. + * See https://nodered.org/docs/security.html#generating-the-password-hash + */ + //httpNodeAuth: {user:"user",pass:"$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN."}, + //httpStaticAuth: {user:"user",pass:"$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN."}, + +/******************************************************************************* + * Server Settings + * - uiPort + * - uiHost + * - apiMaxLength + * - httpServerOptions + * - httpAdminRoot + * - httpAdminMiddleware + * - httpAdminCookieOptions + * - httpNodeRoot + * - httpNodeCors + * - httpNodeMiddleware + * - httpStatic + * - httpStaticRoot + * - httpStaticCors + ******************************************************************************/ + + /** the tcp port that the Node-RED web server is listening on */ + uiPort: process.env.PORT || 1880, + + /** By default, the Node-RED UI accepts connections on all IPv4 interfaces. + * To listen on all IPv6 addresses, set uiHost to "::", + * The following property can be used to listen on a specific interface. For + * example, the following would only allow connections from the local machine. + */ + //uiHost: "127.0.0.1", + + /** The maximum size of HTTP request that will be accepted by the runtime api. + * Default: 5mb + */ + //apiMaxLength: '5mb', + + /** The following property can be used to pass custom options to the Express.js + * server used by Node-RED. For a full list of available options, refer + * to http://expressjs.com/en/api.html#app.settings.table + */ + //httpServerOptions: { }, + + /** By default, the Node-RED UI is available at http://localhost:1880/ + * The following property can be used to specify a different root path. + * If set to false, this is disabled. + */ + //httpAdminRoot: '/admin', + + /** The following property can be used to add a custom middleware function + * in front of all admin http routes. For example, to set custom http + * headers. It can be a single function or an array of middleware functions. + */ + // httpAdminMiddleware: function(req,res,next) { + // // Set the X-Frame-Options header to limit where the editor + // // can be embedded + // //res.set('X-Frame-Options', 'sameorigin'); + // next(); + // }, + + /** The following property can be used to set addition options on the session + * cookie used as part of adminAuth authentication system + * Available options are documented here: https://www.npmjs.com/package/express-session#cookie + */ + // httpAdminCookieOptions: { }, + + /** Some nodes, such as HTTP In, can be used to listen for incoming http requests. + * By default, these are served relative to '/'. The following property + * can be used to specify a different root path. If set to false, this is + * disabled. + */ + //httpNodeRoot: '/red-nodes', + + /** The following property can be used to configure cross-origin resource sharing + * in the HTTP nodes. + * See https://github.com/troygoode/node-cors#configuration-options for + * details on its contents. The following is a basic permissive set of options: + */ + //httpNodeCors: { + // origin: "*", + // methods: "GET,PUT,POST,DELETE" + //}, + + /** If you need to set an http proxy please set an environment variable + * called http_proxy (or HTTP_PROXY) outside of Node-RED in the operating system. + * For example - http_proxy=http://myproxy.com:8080 + * (Setting it here will have no effect) + * You may also specify no_proxy (or NO_PROXY) to supply a comma separated + * list of domains to not proxy, eg - no_proxy=.acme.co,.acme.co.uk + */ + + /** The following property can be used to add a custom middleware function + * in front of all http in nodes. This allows custom authentication to be + * applied to all http in nodes, or any other sort of common request processing. + * It can be a single function or an array of middleware functions. + */ + //httpNodeMiddleware: function(req,res,next) { + // // Handle/reject the request, or pass it on to the http in node by calling next(); + // // Optionally skip our rawBodyParser by setting this to true; + // //req.skipRawBodyParser = true; + // next(); + //}, + + /** When httpAdminRoot is used to move the UI to a different root path, the + * following property can be used to identify a directory of static content + * that should be served at http://localhost:1880/. + * When httpStaticRoot is set differently to httpAdminRoot, there is no need + * to move httpAdminRoot + */ + //httpStatic: '/home/nol/node-red-static/', //single static source + /** + * OR multiple static sources can be created using an array of objects... + * Each object can also contain an options object for further configuration. + * See https://expressjs.com/en/api.html#express.static for available options. + * They can also contain an option `cors` object to set specific Cross-Origin + * Resource Sharing rules for the source. `httpStaticCors` can be used to + * set a default cors policy across all static routes. + */ + //httpStatic: [ + // {path: '/home/nol/pics/', root: "/img/"}, + // {path: '/home/nol/reports/', root: "/doc/"}, + // {path: '/home/nol/videos/', root: "/vid/", options: {maxAge: '1d'}} + //], + + /** + * All static routes will be appended to httpStaticRoot + * e.g. if httpStatic = "/home/nol/docs" and httpStaticRoot = "/static/" + * then "/home/nol/docs" will be served at "/static/" + * e.g. if httpStatic = [{path: '/home/nol/pics/', root: "/img/"}] + * and httpStaticRoot = "/static/" + * then "/home/nol/pics/" will be served at "/static/img/" + */ + //httpStaticRoot: '/static/', + + /** The following property can be used to configure cross-origin resource sharing + * in the http static routes. + * See https://github.com/troygoode/node-cors#configuration-options for + * details on its contents. The following is a basic permissive set of options: + */ + //httpStaticCors: { + // origin: "*", + // methods: "GET,PUT,POST,DELETE" + //}, + + /** The following property can be used to modify proxy options */ + // proxyOptions: { + // mode: "legacy", // legacy mode is for non-strict previous proxy determination logic (node-red < v4 compatible) + // }, + +/******************************************************************************* + * Runtime Settings + * - lang + * - runtimeState + * - telemetry + * - diagnostics + * - logging + * - contextStorage + * - exportGlobalContextKeys + * - externalModules + ******************************************************************************/ + + /** Uncomment the following to run node-red in your preferred language. + * Available languages include: en-US (default), ja, de, zh-CN, zh-TW, ru, ko + * Some languages are more complete than others. + */ + // lang: "de", + + /** Configure diagnostics options + * - enabled: When `enabled` is `true` (or unset), diagnostics data will + * be available at http://localhost:1880/diagnostics + * - ui: When `ui` is `true` (or unset), the action `show-system-info` will + * be available to logged in users of node-red editor + */ + diagnostics: { + /** enable or disable diagnostics endpoint. Must be set to `false` to disable */ + enabled: true, + /** enable or disable diagnostics display in the node-red editor. Must be set to `false` to disable */ + ui: true, + }, + /** Configure runtimeState options + * - enabled: When `enabled` is `true` flows runtime can be Started/Stopped + * by POSTing to available at http://localhost:1880/flows/state + * - ui: When `ui` is `true`, the action `core:start-flows` and + * `core:stop-flows` will be available to logged in users of node-red editor + * Also, the deploy menu (when set to default) will show a stop or start button + */ + runtimeState: { + /** enable or disable flows/state endpoint. Must be set to `false` to disable */ + enabled: false, + /** show or hide runtime stop/start options in the node-red editor. Must be set to `false` to hide */ + ui: false, + }, + telemetry: { + /** + * By default, telemetry is disabled until the user provides consent the first + * time they open the editor. + * + * The following property can be uncommented and set to true/false to enable/disable + * telemetry without seeking further consent in the editor. + * The user can override this setting via the user settings dialog within the editor + */ + // enabled: true, + /** + * If telemetry is enabled, the editor will notify the user if a new version of Node-RED + * is available. Set the following property to false to disable this notification. + */ + // updateNotification: true + }, + /** Configure the logging output */ + logging: { + /** Only console logging is currently supported */ + console: { + /** Level of logging to be recorded. Options are: + * fatal - only those errors which make the application unusable should be recorded + * error - record errors which are deemed fatal for a particular request + fatal errors + * warn - record problems which are non fatal + errors + fatal errors + * info - record information about the general running of the application + warn + error + fatal errors + * debug - record information which is more verbose than info + info + warn + error + fatal errors + * trace - record very detailed logging + debug + info + warn + error + fatal errors + * off - turn off all logging (doesn't affect metrics or audit) + */ + level: "info", + /** Whether or not to include metric events in the log output */ + metrics: false, + /** Whether or not to include audit events in the log output */ + audit: false + } + }, + + /** Context Storage + * The following property can be used to enable context storage. The configuration + * provided here will enable file-based context that flushes to disk every 30 seconds. + * Refer to the documentation for further options: https://nodered.org/docs/api/context/ + */ + //contextStorage: { + // default: { + // module:"localfilesystem" + // }, + //}, + + /** `global.keys()` returns a list of all properties set in global context. + * This allows them to be displayed in the Context Sidebar within the editor. + * In some circumstances it is not desirable to expose them to the editor. The + * following property can be used to hide any property set in `functionGlobalContext` + * from being list by `global.keys()`. + * By default, the property is set to false to avoid accidental exposure of + * their values. Setting this to true will cause the keys to be listed. + */ + exportGlobalContextKeys: false, + + /** Configure how the runtime will handle external npm modules. + * This covers: + * - whether the editor will allow new node modules to be installed + * - whether nodes, such as the Function node are allowed to have their + * own dynamically configured dependencies. + * The allow/denyList options can be used to limit what modules the runtime + * will install/load. It can use '*' as a wildcard that matches anything. + */ + externalModules: { + // autoInstall: false, /** Whether the runtime will attempt to automatically install missing modules */ + // autoInstallRetry: 30, /** Interval, in seconds, between reinstall attempts */ + // palette: { /** Configuration for the Palette Manager */ + // allowInstall: true, /** Enable the Palette Manager in the editor */ + // allowUpdate: true, /** Allow modules to be updated in the Palette Manager */ + // allowUpload: true, /** Allow module tgz files to be uploaded and installed */ + // allowList: ['*'], + // denyList: [], + // allowUpdateList: ['*'], + // denyUpdateList: [] + // }, + // modules: { /** Configuration for node-specified modules */ + // allowInstall: true, + // allowList: [], + // denyList: [] + // } + }, + + +/******************************************************************************* + * Editor Settings + * - disableEditor + * - editorTheme + ******************************************************************************/ + + /** The following property can be used to disable the editor. The admin API + * is not affected by this option. To disable both the editor and the admin + * API, use either the httpRoot or httpAdminRoot properties + */ + //disableEditor: false, + + /** Customising the editor + * See https://nodered.org/docs/user-guide/runtime/configuration#editor-themes + * for all available options. + */ + editorTheme: { + /** The following property can be used to set a custom theme for the editor. + * See https://github.com/node-red-contrib-themes/theme-collection for + * a collection of themes to chose from. + */ + //theme: "", + + /** To disable the 'Welcome to Node-RED' tour that is displayed the first + * time you access the editor for each release of Node-RED, set this to false + */ + //tours: false, + + palette: { + /** The following property can be used to order the categories in the editor + * palette. If a node's category is not in the list, the category will get + * added to the end of the palette. + * If not set, the following default order is used: + */ + //categories: { + // order: ['subflows', 'common', 'function', 'network', 'sequence', 'parser', 'storage'], + // }, + }, + + projects: { + /** To enable the Projects feature, set this value to true */ + enabled: false, + workflow: { + /** Set the default projects workflow mode. + * - manual - you must manually commit changes + * - auto - changes are automatically committed + * This can be overridden per-user from the 'Git config' + * section of 'User Settings' within the editor + */ + mode: "manual" + } + }, + + codeEditor: { + /** + * Code Editor Selection can be one of the following: + * - monaco - the Monaco Editor (the default) + * - ace - the Ace Editor + * - basic - a simple textarea based editor + * @type {'monaco'|'ace'|'basic'} + */ + lib: "monaco", + options: { + /** The follow options only apply if the editor is set to "monaco" + * + * theme - must match the file name of a theme in + * packages/node_modules/@node-red/editor-client/src/vendor/monaco/dist/theme + * e.g. "tomorrow-night", "upstream-sunburst", "github", "my-theme" + */ + // theme: "vs", + /** other overrides can be set e.g. fontSize, fontFamily, fontLigatures etc. + * for the full list, see https://microsoft.github.io/monaco-editor/docs.html#interfaces/editor_editor_api.editor.IStandaloneEditorConstructionOptions.html + */ + //fontSize: 14, + //fontFamily: "Cascadia Code, Fira Code, Consolas, 'Courier New', monospace", + //fontLigatures: true, + } + }, + + markdownEditor: { + mermaid: { + /** enable or disable mermaid diagram in markdown document + */ + enabled: true + } + }, + + multiplayer: { + /** To enable the Multiplayer feature, set this value to true */ + enabled: false + }, + }, + +/******************************************************************************* + * Node Settings + * - fileWorkingDirectory + * - functionGlobalContext + * - functionExternalModules + * - globalFunctionTimeout + * - functionTimeout + * - nodeMessageBufferMaxLength + * - ui (for use with Node-RED Dashboard) + * - debugUseColors + * - debugMaxLength + * - debugStatusLength + * - execMaxBufferSize + * - httpRequestTimeout + * - mqttReconnectTime + * - serialReconnectTime + * - socketReconnectTime + * - socketTimeout + * - tcpMsgQueueSize + * - inboundWebSocketTimeout + * - tlsConfigDisableLocalFiles + * - webSocketNodeVerifyClient + ******************************************************************************/ + + /** The working directory to handle relative file paths from within the File nodes + * defaults to the working directory of the Node-RED process. + */ + //fileWorkingDirectory: "", + + /** Allow the Function node to load additional npm modules directly */ + functionExternalModules: true, + + + /** + * The default timeout (in seconds) for all Function nodes. + * Individual nodes can set their own timeout value within their configuration. + */ + globalFunctionTimeout: 0, + + /** + * Default timeout, in seconds, for the Function node. 0 means no timeout is applied + * This value is applied when the node is first added to the workspace - any changes + * must then be made with the individual node configurations. + * To set a global timeout value, use `globalFunctionTimeout` + */ + functionTimeout: 0, + + /** The following property can be used to set predefined values in Global Context. + * This allows extra node modules to be made available with in Function node. + * For example, the following: + * functionGlobalContext: { os:require('os') } + * will allow the `os` module to be accessed in a Function node using: + * global.get("os") + */ + functionGlobalContext: { + // os:require('os'), + }, + + /** The maximum number of messages nodes will buffer internally as part of their + * operation. This applies across a range of nodes that operate on message sequences. + * defaults to no limit. A value of 0 also means no limit is applied. + */ + //nodeMessageBufferMaxLength: 0, + + /** If you installed the optional node-red-dashboard you can set it's path + * relative to httpNodeRoot + * Other optional properties include + * readOnly:{boolean}, + * middleware:{function or array}, (req,res,next) - http middleware + * ioMiddleware:{function or array}, (socket,next) - socket.io middleware + */ + //ui: { path: "ui" }, + + /** Colourise the console output of the debug node */ + //debugUseColors: true, + + /** The maximum length, in characters, of any message sent to the debug sidebar tab */ + debugMaxLength: 1000, + + /** The maximum length, in characters, of status messages under the debug node */ + //debugStatusLength: 32, + + /** Maximum buffer size for the exec node. Defaults to 10Mb */ + //execMaxBufferSize: 10000000, + + /** Timeout in milliseconds for HTTP request connections. Defaults to 120s */ + //httpRequestTimeout: 120000, + + /** Retry time in milliseconds for MQTT connections */ + mqttReconnectTime: 15000, + + /** Retry time in milliseconds for Serial port connections */ + serialReconnectTime: 15000, + + /** Retry time in milliseconds for TCP socket connections */ + //socketReconnectTime: 10000, + + /** Timeout in milliseconds for TCP server socket connections. Defaults to no timeout */ + //socketTimeout: 120000, + + /** Maximum number of messages to wait in queue while attempting to connect to TCP socket + * defaults to 1000 + */ + //tcpMsgQueueSize: 2000, + + /** Timeout in milliseconds for inbound WebSocket connections that do not + * match any configured node. Defaults to 5000 + */ + //inboundWebSocketTimeout: 5000, + + /** To disable the option for using local files for storing keys and + * certificates in the TLS configuration node, set this to true. + */ + //tlsConfigDisableLocalFiles: true, + + /** The following property can be used to verify WebSocket connection attempts. + * This allows, for example, the HTTP request headers to be checked to ensure + * they include valid authentication information. + */ + //webSocketNodeVerifyClient: function(info) { + // /** 'info' has three properties: + // * - origin : the value in the Origin header + // * - req : the HTTP request + // * - secure : true if req.connection.authorized or req.connection.encrypted is set + // * + // * The function should return true if the connection should be accepted, false otherwise. + // * + // * Alternatively, if this function is defined to accept a second argument, callback, + // * it can be used to verify the client asynchronously. + // * The callback takes three arguments: + // * - result : boolean, whether to accept the connection or not + // * - code : if result is false, the HTTP error status to return + // * - reason: if result is false, the HTTP reason string to return + // */ + //}, + +/******************************************************************************* + * Node Default Overrides + * + * This allows the user to override default values of a node. These are the values + * that are applied when a node is added to the workspace. They do not affect + * nodes that have already been deployed. + * + * The available properties of a node type can be found in the Information sidebar when + * selecting a node of that type. + * + * + *******************************************************************************/ + + // nodeDefaults: { + // "debug": { + // "complete": true // set the debug node to show complete msg by default + // } + // } +} diff --git a/infra/nodered/start.sh b/infra/nodered/start.sh new file mode 100644 index 0000000..efd788b --- /dev/null +++ b/infra/nodered/start.sh @@ -0,0 +1,14 @@ +#!/bin/sh +echo "[start.sh] BEGIN" +INDEX=/data/node_modules/@flowfuse/node-red-dashboard/dist/index.html +BASE_HREF="${DASHBOARD_BASE_HREF:-/dashboard/}" +echo "[start.sh] INDEX=$INDEX BASE_HREF=$BASE_HREF" +echo "[start.sh] has_base_before=$(grep -c '&1 || echo none)" +if [ -f "$INDEX" ] && ! grep -q ' + &1 || echo none)" +cd /usr/src/node-red +exec node $NODE_OPTIONS node_modules/node-red/red.js $FLOWS diff --git a/infra/zigbee2mqtt/configuration.yaml b/infra/zigbee2mqtt/configuration.yaml new file mode 100644 index 0000000..c56424e --- /dev/null +++ b/infra/zigbee2mqtt/configuration.yaml @@ -0,0 +1,34 @@ +version: 5 +mqtt: + base_topic: zigbee2mqtt + server: mqtt://mosquitto:1883 +serial: + port: /dev/ttyUSB0 + adapter: blz + baudrate: 2000000 + rtscts: false +advanced: + log_level: debug +frontend: + enabled: true + port: 8080 +permit_join: false +groups: + '1': + friendly_name: all_plugs + devices: + - Squiggle + - Sideboard Lamp + - Bamboo Lights + - DJ Booth +devices: + '0xffffb40e0604fbd0': + friendly_name: Squiggle + '0xffffb40e06065536': + friendly_name: Door Button + '0xffffb40e0603c9e4': + friendly_name: Sideboard Lamp + '0xffffb40e06050af6': + friendly_name: Bamboo Lights + '0xffffb40e0603ef11': + friendly_name: DJ Booth diff --git a/infra/zigbee2mqtt/coordinator_backup.json b/infra/zigbee2mqtt/coordinator_backup.json new file mode 100644 index 0000000..975b279 --- /dev/null +++ b/infra/zigbee2mqtt/coordinator_backup.json @@ -0,0 +1,26 @@ +{ + "metadata": { + "format": "zigpy/open-coordinator-backup", + "version": 1, + "source": "zigbee-herdsman@10.5.0", + "internal": { + "date": "2026-07-01T05:51:05.408Z" + } + }, + "stack_specific": {}, + "coordinator_ieee": "0000000000000000", + "pan_id": "1a62", + "extended_pan_id": "dddddddddddddddd", + "nwk_update_id": 0, + "security_level": 5, + "channel": 11, + "channel_mask": [ + 11 + ], + "network_key": { + "key": "01030507090b0d0f00020406080a0c0d", + "sequence_number": 0, + "frame_counter": 57407 + }, + "devices": [] +} \ No newline at end of file diff --git a/infra/zigbee2mqtt/state.json b/infra/zigbee2mqtt/state.json new file mode 100644 index 0000000..58dc203 --- /dev/null +++ b/infra/zigbee2mqtt/state.json @@ -0,0 +1,60 @@ +{ + "0xffffb40e0604fbd0": { + "state": "ON", + "power_on_behavior": "off", + "update": { + "state": "available", + "installed_version": 268513372, + "latest_version": 268513381, + "latest_source": "https://raw.githubusercontent.com/Koenkk/zigbee-OTA/master/images/ThirdReality/SmartPlug_Zigbee_PROD_OTA_V101_1.01.01.ota", + "latest_release_notes": null + }, + "linkquality": 255 + }, + "0xffffb40e06065536": { + "battery": 83, + "update": { + "state": "available", + "installed_version": 35, + "latest_version": 47, + "latest_source": "https://raw.githubusercontent.com/Koenkk/zigbee-OTA/master/images/ThirdReality/Button_PROD_OTA_V47_v1.00.47.ota", + "latest_release_notes": null + } + }, + "0xffffb40e0603c9e4": { + "state": "ON", + "power_on_behavior": "off", + "update": { + "state": "available", + "installed_version": 268513372, + "latest_version": 268513381, + "latest_source": "https://raw.githubusercontent.com/Koenkk/zigbee-OTA/master/images/ThirdReality/SmartPlug_Zigbee_PROD_OTA_V101_1.01.01.ota", + "latest_release_notes": null + }, + "linkquality": 255 + }, + "0xffffb40e06050af6": { + "state": "ON", + "power_on_behavior": "off", + "update": { + "state": "available", + "installed_version": 268513372, + "latest_version": 268513381, + "latest_source": "https://raw.githubusercontent.com/Koenkk/zigbee-OTA/master/images/ThirdReality/SmartPlug_Zigbee_PROD_OTA_V101_1.01.01.ota", + "latest_release_notes": null + }, + "linkquality": 140 + }, + "0xffffb40e0603ef11": { + "state": "OFF", + "power_on_behavior": "off", + "update": { + "state": "available", + "installed_version": 268513372, + "latest_version": 268513381, + "latest_source": "https://raw.githubusercontent.com/Koenkk/zigbee-OTA/master/images/ThirdReality/SmartPlug_Zigbee_PROD_OTA_V101_1.01.01.ota", + "latest_release_notes": null + }, + "linkquality": 255 + } +} \ No newline at end of file