GREE Controller 0.14.15

This commit is contained in:
Mateusz Gruszczyński
2026-09-16 17:07:28 +02:00
parent 7c0e0235f7
commit d22c91655b
6 changed files with 25 additions and 5 deletions
@@ -1,7 +1,7 @@
{ {
"domain": "gree_controller", "domain": "gree_controller",
"name": "GREE Controller", "name": "GREE Controller",
"version": "0.14.14", "version": "0.14.15",
"config_flow": true, "config_flow": true,
"integration_type": "hub", "integration_type": "hub",
"iot_class": "local_polling", "iot_class": "local_polling",
+9
View File
@@ -1,5 +1,14 @@
# Changelog # Changelog
## 0.14.15
- Treats TCP `8787` as the fixed internal Home Assistant add-on application/ingress port and validates the Supervisor-reported ingress port at startup.
- Makes the add-on build fail when `run.sh`, `ingress_port` and watchdog port metadata diverge.
- Uses the Home Assistant Supervisor network API to resolve the primary host IPv4 for generated chart-only share links instead of depending on the browser/ingress hostname.
- Adds optional `public_chart_base_url` for reverse proxies, alternate hostnames or non-standard external routing while keeping the public surface limited to generated Custom Chart shares.
- Uses Home Assistant's `[PORT:8787]` watchdog placeholder so Supervisor resolves the effective watchdog port from the add-on port contract.
- Keeps standalone installations fully port-configurable through `GREE_CONTROLLER_BIND`.
## 0.14.14 ## 0.14.14
- Changes History → Custom Charts links to open a standalone chart-only page instead of the full dashboard. - Changes History → Custom Charts links to open a standalone chart-only page instead of the full dashboard.
+4 -2
View File
@@ -56,6 +56,7 @@ Broadcast zwykle nie przechodzi przez router. Sterowanie unicast może działać
| `zone_interval_seconds` | interwał sterowania strefami/termostatem | | `zone_interval_seconds` | interwał sterowania strefami/termostatem |
| `discovery_timeout_ms` | timeout discovery UDP | | `discovery_timeout_ms` | timeout discovery UDP |
| `app_token` | token bezpośredniego Web UI/API; w trybie Supervisor pusty = direct access zablokowany | | `app_token` | token bezpośredniego Web UI/API; w trybie Supervisor pusty = direct access zablokowany |
| `public_chart_base_url` | opcjonalny bazowy URL publicznych linków Custom Chart; puste = automatyczne główne IPv4 hosta HA + `:8787` |
| `log_level` | `error`, `warn`, `info`, `debug`, `trace` | | `log_level` | `error`, `warn`, `info`, `debug`, `trace` |
### Home Assistant API ### Home Assistant API
@@ -64,7 +65,7 @@ Dodatek korzysta automatycznie z wewnętrznego proxy Home Assistant Core (`http:
### Dostęp, dane i bezpieczeństwo ### Dostęp, dane i bezpieczeństwo
Usługa słucha na TCP `8787`; ingress Home Assistant przekazuje Web UI na ten port. Gdy wykryty jest `SUPERVISOR_TOKEN`, bezpośredni dashboard/API na `:8787` wymaga `app_token`; przy pustym `app_token` bezpośredni dashboard jest zablokowany. Z sieci bez poświadczeń dostępny jest tylko publiczny widok i endpoint danych pojedynczego Custom Chart (`/charts/custom/<share-token>`, `/api/public/charts/custom/<share-token>`). Token udostępnienia jest losowy, jego skrót jest zapisywany w SQLite, a sam URL nie zawiera nazw urządzeń ani listy metryk. Link kopiowany z History → Custom chart omija HA ingress i wskazuje bezpośrednio host/IP dodatku na jego porcie HTTP (domyślnie `8787`). `/api/health` bez tokenu jest akceptowane tylko od peera Supervisora na potrzeby watchdoga; bezpośrednie żądanie sieciowe wymaga `app_token`. Baza jest zapisywana w `/data/gree-controller.db`; konfiguracja używa `backup: cold`, więc dane są objęte backupem dodatku. Usługa używa stałego wewnętrznego portu TCP `8787`; ingress Home Assistant przekazuje Web UI na ten port. Port nie jest opcją użytkownika w zakładce Network. Przy starcie add-on porównuje port raportowany przez Supervisor z kontraktem `8787` i odmawia startu, jeśli ręcznie zmodyfikowana paczka jest niespójna. Gdy wykryty jest `SUPERVISOR_TOKEN`, bezpośredni dashboard/API na `:8787` wymaga `app_token`; przy pustym `app_token` bezpośredni dashboard jest zablokowany. Z sieci bez poświadczeń dostępny jest tylko publiczny widok i endpoint danych pojedynczego Custom Chart (`/charts/custom/<share-token>`, `/api/public/charts/custom/<share-token>`). Token udostępnienia jest losowy, jego skrót jest zapisywany w SQLite, a sam URL nie zawiera nazw urządzeń ani listy metryk. Link kopiowany z History → Custom chart omija HA ingress; domyślnie add-on pobiera główne IPv4 hosta z Supervisor API i tworzy `http://<IP-HA>:8787/charts/custom/...`. `public_chart_base_url` pozwala jawnie wskazać reverse proxy, inną nazwę hosta lub alternatywną trasę. `/api/health` bez tokenu jest akceptowane tylko od peera Supervisora na potrzeby watchdoga; bezpośrednie żądanie sieciowe wymaga `app_token`. Baza jest zapisywana w `/data/gree-controller.db`; konfiguracja używa `backup: cold`, więc dane są objęte backupem dodatku.
Watchdog sprawdza `/api/health`. Do diagnostyki sieci najpierw sprawdź `ha network info`, poprawność `gree_interface`, broadcast konkretnej podsieci i reguły UDP/firewalla. Watchdog sprawdza `/api/health`. Do diagnostyki sieci najpierw sprawdź `ha network info`, poprawność `gree_interface`, broadcast konkretnej podsieci i reguły UDP/firewalla.
@@ -121,6 +122,7 @@ Broadcast normally does not cross routers. Unicast control may work through rout
| `zone_interval_seconds` | thermostat/zone control interval | | `zone_interval_seconds` | thermostat/zone control interval |
| `discovery_timeout_ms` | UDP discovery timeout | | `discovery_timeout_ms` | UDP discovery timeout |
| `app_token` | token for direct Web UI/API access; in Supervisor mode empty = direct access disabled | | `app_token` | token for direct Web UI/API access; in Supervisor mode empty = direct access disabled |
| `public_chart_base_url` | optional base URL for public Custom Chart links; empty = primary HA host IPv4 + `:8787` automatically |
| `log_level` | `error`, `warn`, `info`, `debug`, `trace` | | `log_level` | `error`, `warn`, `info`, `debug`, `trace` |
### Home Assistant API ### Home Assistant API
@@ -129,6 +131,6 @@ The add-on automatically uses the internal Home Assistant Core proxy (`http://su
### Access, data and security ### Access, data and security
The service listens on TCP `8787`; Home Assistant ingress proxies the Web UI to that port. When `SUPERVISOR_TOKEN` is detected, direct dashboard/API access on `:8787` requires `app_token`; with an empty `app_token`, direct dashboard access is disabled. From the network, the only unauthenticated application data is the single public Custom Chart view/data endpoint (`/charts/custom/<share-token>`, `/api/public/charts/custom/<share-token>`). The share token is random, only its hash is stored in SQLite, and the URL does not expose device names or metric selectors. Links copied from History → Custom chart bypass HA ingress and point directly to the add-on host/IP on its HTTP port (default `8787`). `/api/health` is accepted without a token only from the Supervisor peer for the add-on watchdog; direct network requests require `app_token`. The database is stored in `/data/gree-controller.db`; `backup: cold` keeps it in the add-on backup. The service uses fixed internal TCP port `8787`; Home Assistant ingress proxies the Web UI to that port. The port is not a user-facing Network option. On startup the add-on compares the Supervisor-reported ingress port with the `8787` contract and refuses to start if a manually modified package is inconsistent. When `SUPERVISOR_TOKEN` is detected, direct dashboard/API access on `:8787` requires `app_token`; with an empty `app_token`, direct dashboard access is disabled. From the network, the only unauthenticated application data is the single public Custom Chart view/data endpoint (`/charts/custom/<share-token>`, `/api/public/charts/custom/<share-token>`). The share token is random, only its hash is stored in SQLite, and the URL does not expose device names or metric selectors. Links copied from History → Custom chart bypass HA ingress; by default the add-on obtains the primary host IPv4 from the Supervisor API and builds `http://<HA-IP>:8787/charts/custom/...`. `public_chart_base_url` can explicitly select a reverse proxy, alternate hostname or routing path. `/api/health` is accepted without a token only from the Supervisor peer for the add-on watchdog; direct network requests require `app_token`. The database is stored in `/data/gree-controller.db`; `backup: cold` keeps it in the add-on backup.
The watchdog checks `/api/health`. For network troubleshooting, verify `ha network info`, `gree_interface`, the selected subnet broadcast, and UDP/firewall rules first. The watchdog checks `/api/health`. For network troubleshooting, verify `ha network info`, `gree_interface`, the selected subnet broadcast, and UDP/firewall rules first.
+5 -2
View File
@@ -1,5 +1,5 @@
name: "GREE Controller" name: "GREE Controller"
version: "0.14.14" version: "0.14.15"
slug: "gree_controller" slug: "gree_controller"
description: "Local GREE HVAC controller with Web UI and Home Assistant integration" description: "Local GREE HVAC controller with Web UI and Home Assistant integration"
url: "https://git.linuxiarz.pl/gru/gree-controller-ha-addon/" url: "https://git.linuxiarz.pl/gru/gree-controller-ha-addon/"
@@ -12,13 +12,14 @@ boot: auto
init: false init: false
host_network: true host_network: true
homeassistant_api: true homeassistant_api: true
hassio_api: true
ingress: true ingress: true
ingress_port: 8787 ingress_port: 8787
ingress_stream: true ingress_stream: true
panel_icon: mdi:air-conditioner panel_icon: mdi:air-conditioner
panel_title: GREE Controller panel_title: GREE Controller
panel_admin: true panel_admin: true
watchdog: "http://[HOST]:8787/api/health" watchdog: "http://[HOST]:[PORT:8787]/api/health"
backup: cold backup: cold
options: options:
gree_interface: "" gree_interface: ""
@@ -29,6 +30,7 @@ options:
zone_interval_seconds: 5 zone_interval_seconds: 5
discovery_timeout_ms: 3000 discovery_timeout_ms: 3000
app_token: "" app_token: ""
public_chart_base_url: ""
log_level: info log_level: info
schema: schema:
gree_interface: str gree_interface: str
@@ -39,4 +41,5 @@ schema:
zone_interval_seconds: "int(2,3600)" zone_interval_seconds: "int(2,3600)"
discovery_timeout_ms: "int(500,30000)" discovery_timeout_ms: "int(500,30000)"
app_token: password app_token: password
public_chart_base_url: str
log_level: "list(error|warn|info|debug|trace)" log_level: "list(error|warn|info|debug|trace)"
+3
View File
@@ -23,6 +23,9 @@ configuration:
app_token: app_token:
name: Application token name: Application token
description: Token required for direct dashboard/API access on port 8787. With SUPERVISOR_TOKEN active, an empty token disables direct access; only generated Custom Chart share links remain public. description: Token required for direct dashboard/API access on port 8787. With SUPERVISOR_TOKEN active, an empty token disables direct access; only generated Custom Chart share links remain public.
public_chart_base_url:
name: Public chart base URL
description: Optional override for generated Custom Chart links, for example http://192.168.1.20:8787 or a reverse-proxy URL. Leave empty to use the primary Home Assistant host IPv4 and the fixed add-on port 8787 automatically.
log_level: log_level:
name: Log level name: Log level
description: Controller log verbosity. description: Controller log verbosity.
+3
View File
@@ -23,6 +23,9 @@ configuration:
app_token: app_token:
name: Token aplikacji name: Token aplikacji
description: Token wymagany do bezpośredniego dostępu do dashboardu/API na porcie 8787. Przy aktywnym SUPERVISOR_TOKEN pusty token blokuje direct access; publiczne pozostają wyłącznie wygenerowane linki Custom Chart. description: Token wymagany do bezpośredniego dostępu do dashboardu/API na porcie 8787. Przy aktywnym SUPERVISOR_TOKEN pusty token blokuje direct access; publiczne pozostają wyłącznie wygenerowane linki Custom Chart.
public_chart_base_url:
name: Bazowy URL publicznych wykresów
description: Opcjonalne nadpisanie adresu generowanych linków Custom Chart, np. http://192.168.1.20:8787 albo adres reverse proxy. Pozostaw puste, aby automatycznie użyć głównego IPv4 hosta Home Assistant i stałego portu add-onu 8787.
log_level: log_level:
name: Poziom logowania name: Poziom logowania
description: Szczegółowość logów kontrolera. description: Szczegółowość logów kontrolera.