docs(mqtt-auth): note VPS broker has allow_anonymous false but no TLS listener yet
The full mosquitto.conf (2026-09-30) has a single plain listener on 1883, used by the boards. The phone app sends a Firebase ID token as its MQTT password, so a TLS listener must be added before app users go live. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -137,6 +137,9 @@ When those lines stop appearing, set `MQTT_ALLOW_LEGACY_PASSWORD=false`.
|
||||
- Already set correctly: `backends files,http`, `http_host 172.20.0.1` (Docker bridge),
|
||||
`http_port 8000`, both URIs, `http_method post`, `params_mode form`,
|
||||
`response_mode status`, `cache true`, `cache_reset true`.
|
||||
- `allow_anonymous false` ✓. Only listener: `listener 1883 0.0.0.0` (plain TCP, used by
|
||||
the boards). **No TLS listener yet.** One must be added for the app (a second
|
||||
listener, e.g. 8883 with `certfile`/`keyfile`) while keeping 1883 for the boards.
|
||||
- Still to change: `auth_cache_seconds` and `acl_cache_seconds` are **300**. Lower
|
||||
both to 60 before app users go live, or a block/unassign can take up to 5 minutes
|
||||
to apply.
|
||||
|
||||
Reference in New Issue
Block a user