Home Assistant

Home Assistant is the central smart home hub. It runs as Home Assistant OS on a Raspberry Pi 4 with the official PoE HAT, not in Kubernetes. The cluster only publishes it through Envoy Gateway at ha.wibrow.dev.

Deployment Details

SettingValue
HostHome Assistant OS on a Raspberry Pi 4
NetworkIoT VLAN 101, 10.101.13.61 (DHCP reservation homeassistant in terraform/unifi/reservations.tf)
DNS namehomeassistant.iot
Public URLha.wibrow.dev on envoy-external
In-cluster manifestskubernetes/apps/pitower/home-automation/home-assistant/

Routing

The app directory contains no workload, only an Envoy Gateway Backend that points at the HAOS host and an HTTPRoute that uses it:

service.yaml
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: Backend
metadata:
  name: home-assistant
  namespace: home-automation
spec:
  endpoints:
    - fqdn:
        hostname: homeassistant.iot
        port: 8123
httproute.yaml
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: home-assistant
  namespace: home-automation
spec:
  hostnames:
    - ha.wibrow.dev
  parentRefs:
    - name: envoy-external
      namespace: networking
      sectionName: https
  rules:
    - backendRefs:
        - group: gateway.envoyproxy.io
          kind: Backend
          name: home-assistant
          port: 8123

Integration Points

IntegrationDirectionEndpoint
FrigateFrigate publishes events over MQTThomeassistant.iot:1883
ToolHive MCPAn MCP server in the ai namespace talks to Home Assistantkubernetes/apps/pitower/ai/toolhive/toolhive-config/mcpserver-home-assistant.yaml
MonitoringBlackbox ICMP probekubernetes/apps/pitower/monitoring/blackbox-exporter/probe-icmp.yaml

Configuration as Code

Automations and device configs that are kept in Git live under iot/:

PathContents
iot/homeassistant/blueprints/Automation blueprints (e.g. Aqara H2 rocker switches)
iot/homeassistant/dashboards/, packages/Dashboards and HA packages
iot/esphome/devices/ESPHome device configs
iot/button-plus/Button+ device config

The HAOS host itself (PoE fan thresholds, the move onto VLAN 101) is managed with Ansible; see the homeassistant runbook in ansible/README.md.