#!/usr/bin/env bash # Home Assistant Bootstrap - Auto-configure OIDC with hass-openid integration set -euo pipefail echo "=== Home Assistant Bootstrap - Fully Automated ===" cd "$(dirname "$0")/.." || exit 1 NS=home-assistant # 1) Ensure namespace kubectl get ns "${NS}" >/dev/null 2>&1 || kubectl create ns "${NS}" # 2) Apply ExternalSecret for OIDC credentials echo "Applying Home Assistant OIDC ExternalSecret..." kubectl apply -f apps/home-assistant/external-secret.yaml # 3) Wait for ESO to sync OIDC credentials echo "Waiting for OIDC credentials to sync from Vault..." for i in {1..30}; do if kubectl -n "${NS}" get secret homeassistant-oidc-secret >/dev/null 2>&1; then echo "OIDC credentials synced successfully" break fi echo " waiting... (attempt $i/30)" sleep 2 done # 4) Wait for the PVC to be bound echo "Waiting for PVC to be bound..." for i in {1..60}; do if kubectl -n "${NS}" get pvc home-assistant-config >/dev/null 2>&1; then PVC_STATUS=$(kubectl -n "${NS}" get pvc home-assistant-config -o jsonpath='{.status.phase}') if [ "${PVC_STATUS}" = "Bound" ]; then echo "PVC is bound" break fi fi echo " waiting for PVC... (attempt $i/60)" sleep 2 done # 5) Get the running Home Assistant pod (if any) POD_NAME=$(kubectl get pods -n "${NS}" -l app.kubernetes.io/name=home-assistant -o jsonpath='{.items[0].metadata.name}' 2>/dev/null || echo "") if [ -n "${POD_NAME}" ] && kubectl -n "${NS}" get pod "${POD_NAME}" >/dev/null 2>&1; then echo "Configuring existing Home Assistant pod: ${POD_NAME}" # Get OIDC credentials CLIENT_ID=$(kubectl get secret -n "${NS}" homeassistant-oidc-secret -o jsonpath='{.data.client_id}' | base64 -d) CLIENT_SECRET=$(kubectl get secret -n "${NS}" homeassistant-oidc-secret -o jsonpath='{.data.client_secret}' | base64 -d) # Create secrets.yaml echo "Creating secrets.yaml..." kubectl exec -n "${NS}" "${POD_NAME}" -- sh -c "cat > /config/secrets.yaml </dev/null; then echo '' >> /config/configuration.yaml echo 'homeassistant:' >> /config/configuration.yaml echo ' packages: !include_dir_merge_named oidc' >> /config/configuration.yaml fi if ! grep -q 'use_x_forwarded_for:' /config/configuration.yaml 2>/dev/null; then cat >> /config/configuration.yaml <<'EOF' http: use_x_forwarded_for: true trusted_proxies: - 10.0.0.0/8 - 172.16.0.0/12 - 192.168.0.0/16 - 127.0.0.1 - ::1 EOF fi " echo "Configuration complete. Restarting Home Assistant..." kubectl rollout restart deployment -n "${NS}" home-assistant kubectl rollout status deployment -n "${NS}" home-assistant --timeout=300s else echo "No running Home Assistant pod found. Configuration will be applied when pod starts." echo "The initContainer will install hass-openid, and the configuration will be set up on first boot." fi echo "Home Assistant bootstrap complete!"