Files
bellsystems-cp/docs
bonaminandClaude Opus 5.5 e663b0a609 docs(mqtt-auth): record TLS for app users via NPM + WebSockets
TLS for the phone app went live on the VPS on 2026-09-30:
- Mosquitto got a second, non-published listener on 8083 with
  `protocol websockets`; port 1883 stays plain TCP for the boards
  (ESP32s can't spare RAM for TLS).
- The mosquitto service joined the external Docker network npm_npmnet so
  NPM (NPMplus) can reach mosquitto:8083 by name; it stays on `default`
  to reach the Console backend at 172.20.0.1:8000.
- NPM proxy host mqtt.bellsystems.net -> http://mosquitto:8083 terminates
  TLS and renews the Let's Encrypt cert. proxy_read/send_timeout 3600s
  added so NPM doesn't drop idle MQTT connections after 60s. NPMplus has no
  "Websockets Support" toggle (always on).
- Verified end to end: a paho client over wss://mqtt.bellsystems.net:443
  (path /mqtt) authenticated via the Console backend and received a
  heartbeat.

Chosen over native 8883 because NPM already owns 80/443 and certificate
renewal, so there is no extra cert handling on the host, and 443 also gets
through networks that block 8883.

The doc now gives the app's final transport (wss, 443, /mqtt, never 1883,
keepalive < 3600s), the listener/network/NPM layout, the end-to-end test,
rollback steps, and a new known gap: the backend's port 8000 is published
on 0.0.0.0, so the /mqtt/auth/* endpoints are reachable from the internet.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 01:15:34 +03:00
..