Home Automation

The home-automation namespace holds two apps: Frigate, the camera NVR, and home-assistant, which is only an ingress route. Home Assistant itself runs as Home Assistant OS on a dedicated Raspberry Pi outside the cluster, and that host also answers MQTT on port 1883.

Architecture

flowchart TD
    subgraph IoT["IoT VLAN 101"]
        HAOS[Home Assistant OS<br/>Raspberry Pi 4<br/>homeassistant.iot]
        CAM[IP cameras<br/>RTSP]
    end

    subgraph Cluster["home-automation namespace"]
        FR[Frigate<br/>worker-04, Intel GPU]
        BE[Envoy Backend<br/>home-assistant]
    end

    GW[envoy-external<br/>ha.wibrow.dev] --> BE
    GW2[envoy-internal<br/>frigate.wibrow.dev] --> FR
    BE -->|:8123| HAOS
    CAM -->|RTSP via go2rtc| FR
    FR -->|MQTT :1883<br/>events| HAOS
    FR -->|recordings| NAS[(Synology NAS<br/>/volume1/cctv)]

    classDef hub fill:#7c3aed,stroke:#5b21b6,color:#fff
    class HAOS hub

Application Summary

AppPurposeGatewayURL
Home AssistantSmart home hub on HAOS, proxied into the gatewayenvoy-externalha.wibrow.dev
FrigateNVR with object detectionenvoy-internalfrigate.wibrow.dev

Frigate

Frigate records the IP cameras and detects objects with OpenVINO on the node's Intel GPU.

SettingValue
Imageghcr.io/blakeblackshear/frigate
Nodeworker-04 (nodeSelector on hostname and intel.feature.node.kubernetes.io/gpu; tolerates dedicated=media-home)
GPUgpu.intel.com/i915: 1, VA-API hardware decoding (LIBVA_DRIVER_NAME: iHD)
DetectorOpenVINO on GPU
ConfigConfigMap frigate-config mounted at /config/config.yml; camera credentials from the frigate-secret ExternalSecret
StoragePVC frigate (5Gi) at /config via the pvc component, backed up by kopiur (mover runs as root to read Frigate's files); recordings on NFS data:/volume1/cctv
WebRTCLoadBalancer Service on 10.20.10.235 for UDP 8555; RTSP 8554 and WebRTC TCP 8555 on the app Service

Recording keeps everything for 7 days, then only footage around alerts and detections. Frigate publishes events to the MQTT broker on the HAOS host (homeassistant.iot:1883), which is how Home Assistant receives them.

Configuration Outside the Cluster

Home Assistant blueprints, dashboards and packages, ESPHome device configs, and Button+ configs live in the repository's iot/ directory. The HAOS host is managed with Ansible (ansible/, just ansible deploy-homeassistant); see ansible/README.md.