41 lines
1.6 KiB
Plaintext
41 lines
1.6 KiB
Plaintext
per_listener_settings true
|
|
|
|
# Plain MQTT — internal services and clients authenticate with username/password on port 1883
|
|
listener 1883 0.0.0.0
|
|
password_file /run/secrets/mosquitto_passwd
|
|
acl_file /run/secrets/mosquitto_acl
|
|
allow_anonymous false
|
|
|
|
# Authenticated MQTT over WebSocket for app clients. Docker binds this listener only to
|
|
# host loopback; nginx supplies the public WSS/TLS endpoint at /mqtt on port 443.
|
|
listener 9001 0.0.0.0
|
|
protocol websockets
|
|
password_file /run/secrets/mosquitto_passwd
|
|
acl_file /run/secrets/mosquitto_acl
|
|
allow_anonymous false
|
|
|
|
# TLS MQTT — devices authenticate with client certificates (port 8883)
|
|
# require_certificate true forces client cert; cert CN becomes the MQTT username.
|
|
# ACL restricts each device to devices/<serial_number>/#
|
|
# Certs are issued by the backend's certificates module (see backend/src/certificates/)
|
|
# into ./mosquitto/certs — requires a broker restart after CA init/provisioning
|
|
# since there's no config/cert hot-reload.
|
|
listener 8883 0.0.0.0
|
|
cafile /mosquitto/certs/ca.crt
|
|
certfile /mosquitto/certs/public-fullchain.pem
|
|
keyfile /mosquitto/certs/public-privkey.pem
|
|
require_certificate true
|
|
use_identity_as_username true
|
|
allow_anonymous false
|
|
acl_file /run/secrets/mosquitto_acl
|
|
|
|
# TLS MQTT — app/admin username+password access (port 8884). App usernames are orgIds;
|
|
# devices.acl confines them to ul/{orgId}/app/... . No anonymous listener is exposed.
|
|
listener 8884 0.0.0.0
|
|
certfile /mosquitto/certs/public-fullchain.pem
|
|
keyfile /mosquitto/certs/public-privkey.pem
|
|
require_certificate false
|
|
password_file /run/secrets/mosquitto_passwd
|
|
allow_anonymous false
|
|
acl_file /run/secrets/mosquitto_acl
|