Files
app-catalog-felhom.eu/templates/home-assistant/steps/52034472eaf393c5.yml
T
admin 15f4d5969a
gates / gates (push) Successful in 2s
home-assistant: 2026.9.3 -> 2026.9.4, within-major step, both venues proven (R-462)
Bench 9401 (harness v4, swap 0): the onboarding owner seeded and logged in before and after,
10-min memory watch 0 kills (anon peak 32.0 %); the abort starts and serves. Box 9202: the guarded
Update done in 113.8 s through the setup gate, the owner logs in. The old head was a backfilled
harness-v1 entry; this step carries the memory watch. Written by upgrade-test.py --write-ladder.

Evidence: felhom.eu/documentation/audits/more-night-apps-2026-09-30/

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 18:05:31 +02:00

62 lines
1.9 KiB
YAML

# Home Assistant - Nyílt forráskódú okos otthon központ
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~256M (mem_limit: 1024M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
services:
home-assistant:
image: ghcr.io/home-assistant/home-assistant:2026.9.3
container_name: home-assistant
restart: unless-stopped
entrypoint: ["/bin/sh", "-c"]
command:
- |
# Ensure reverse-proxy (Traefik) trusted_proxies config exists.
# 172.16.0.0/12 covers all Docker bridge networks.
CFG=/config/configuration.yaml
if [ -f "$$CFG" ] && ! grep -q 'trusted_proxies' "$$CFG"; then
printf '\nhttp:\n use_x_forwarded_for: true\n trusted_proxies:\n - 172.16.0.0/12\n' >> "$$CFG"
elif [ ! -f "$$CFG" ]; then
cat > "$$CFG" << 'HACFG'
default_config:
http:
use_x_forwarded_for: true
trusted_proxies:
- 172.16.0.0/12
HACFG
fi
exec /init
environment:
- TZ=Europe/Budapest
volumes:
- homeassistant_config:/config
networks:
- traefik-public
deploy:
resources:
limits:
memory: 1024M
healthcheck:
test: ["CMD", "curl", "-sf", "http://127.0.0.1:8123/manifest.json"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.home-assistant.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.home-assistant.entrypoints=websecure"
- "traefik.http.routers.home-assistant.tls=true"
- "traefik.http.routers.home-assistant.tls.certresolver=letsencrypt"
- "traefik.http.services.home-assistant.loadbalancer.server.port=8123"
volumes:
homeassistant_config:
networks:
traefik-public:
external: true