bonaminandClaude Opus 5.5 e663b0a609 docs(mqtt-auth): record TLS for app users via NPM + WebSockets
TLS for the phone app went live on the VPS on 2026-09-30:
- Mosquitto got a second, non-published listener on 8083 with
  `protocol websockets`; port 1883 stays plain TCP for the boards
  (ESP32s can't spare RAM for TLS).
- The mosquitto service joined the external Docker network npm_npmnet so
  NPM (NPMplus) can reach mosquitto:8083 by name; it stays on `default`
  to reach the Console backend at 172.20.0.1:8000.
- NPM proxy host mqtt.bellsystems.net -> http://mosquitto:8083 terminates
  TLS and renews the Let's Encrypt cert. proxy_read/send_timeout 3600s
  added so NPM doesn't drop idle MQTT connections after 60s. NPMplus has no
  "Websockets Support" toggle (always on).
- Verified end to end: a paho client over wss://mqtt.bellsystems.net:443
  (path /mqtt) authenticated via the Console backend and received a
  heartbeat.

Chosen over native 8883 because NPM already owns 80/443 and certificate
renewal, so there is no extra cert handling on the host, and 443 also gets
through networks that block 8883.

The doc now gives the app's final transport (wss, 443, /mqtt, never 1883,
keepalive < 3600s), the listener/network/NPM layout, the end-to-end test,
rollback steps, and a new known gap: the backend's port 8000 is published
on 0.0.0.0, so the /mqtt/auth/* endpoints are reachable from the internet.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 01:15:34 +03:00
2026-02-25 21:29:56 +02:00
2026-02-16 19:57:22 +02:00

BellSystems Admin Panel

Self-hosted web admin panel for managing BellSystems devices, melodies, users, and MQTT communications.

Tech Stack

  • Backend: Python / FastAPI
  • Frontend: React + Tailwind CSS (Vite)
  • Database: Google Firestore (Firebase Admin SDK)
  • MQTT: Mosquitto (paho-mqtt)
  • Auth: JWT with role-based access control
  • Deployment: Docker Compose + Nginx

Getting Started

# Clone the repo
git clone <your-gitea-url>/bellsystems-admin.git
cd bellsystems-admin

# Copy env template and fill in your values
cp .env.example .env

# Place your Firebase service account key in the project root
# (file is gitignored — never commit it)

# Start everything
docker compose up --build

Project Structure

bellsystems-admin/
├── backend/          # FastAPI API server
├── frontend/         # React SPA
├── nginx/            # Reverse proxy config
├── docker-compose.yml
└── .env

Documentation

See BellSystems_AdminPanel_Strategy.md for the full architecture and build plan.

S
Description
BellSystems Contol Panel. Handles everything from Devices to Clients. Firebase / Mosquitto / Device Control / logging...
Readme
33 MiB
Languages
JavaScript 72.3%
Python 12.8%
HTML 12.4%
CSS 2.5%