Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Unsolved
Collapse
Discussion Forum to share and further the development of home control and automation, independent of platforms.
  1. Home
  2. Software
  3. Multi-System Reactor
  4. MSR with reverse proxy
Reactor (Multi-System/Multi-Hub) Announcements
toggledbitsT
Build 21228 has been released. Docker images available from DockerHub as usual, and bare-metal packages here. Home Assistant up to version 2021.8.6 supported; the online version of the manual will now state the current supported versions; Fix an error in OWMWeatherController that could cause it to stop updating; Unify the approach to entity filtering on all hub interface classes (controllers); this works for device entities only; it may be extended to other entities later; Improve error detail in messages for EzloController during auth phase; Add isRuleSet() and isRuleEnabled() functions to expressions extensions; Implement set action for lock and passage capabilities (makes them more easily scriptable in some cases); Fix a place in the UI where 24-hour time was not being displayed.
Multi-System Reactor
MSR with reverse proxy
tunnusT
I'm trying to use MSR via reserve proxy in Synology DSM, but MSR page does not load https://<public ip>:30000/reactor/en-US/ At the same time logging page loads normally https://<public ip>:30000/api/v1/log I thought maybe authentication was messing it up, but there was no deny entries in the log, and also disabling authentication did not make any difference. For this use case VPN is not an option (that works, but as said not an option for this particular use case). Any ideas what could cause this? MSR build latest-26242-28d69aa8, Chrome browser
Multi-System Reactor
[MSR] Native fan capabilty
therealdbT
Nothing more to add. I see we have hvac_blower, but, anyway, maybe a native fan on the same assumptions of the fan from HASS could be reasonable. I have a couple of them. ie, this is from ESPHome via HASS. x_hass.domain="fan" x_hass.entity_id="fan.kitchen_seashell_hood_ventilation_fan" x_hass.floor_id=null x_hass.services=["fan","esphome"] x_hass.source="esphome" x_hass.state="off" x_hass_attr.friendly_name="Seashell Hood Ventilation Fan" x_hass_attr.percentage=50 x_hass_attr.percentage_step=25 x_hass_attr.preset_mode="" x_hass_attr.preset_modes=[] x_hass_attr.supported_features=49 Thanks.
Multi-System Reactor
[MSR] Rule do not fire
therealdbT
Topic thumbnail image
Multi-System Reactor
Rule condition shows TRUE in UI but Rule never transitions to SET — survives full restart
N
Build: latest-26221-b25bb3e3, Docker on Synology. Hi, I have a Rule whose Trigger/Constraints reference other Rules via Rule State ... is TRUE. At some point it stops firing. Expanding the rule's condition tree in the UI shows every Trigger and Constraint condition green/TRUE — confirmed live by walking into the room and watching Motion go true in real time. Rule History shows no new SET, just old reset entries. Tried, on the same rule, same evening: recreating the trigger conditions with fresh IDs, recreating the constraint conditions with fresh IDs (flat and wrapped in a new Group — wrapping in a Group produced one SET, but it didn't reproduce on repeat attempts with the same structure), and finally a full container restart with a verified-correct saved rule. Still no SET, even with a fresh live motion event right after the restart. Separately, I found that this rule (and its 10 per-room clones) share identical internal condition/group IDs with each other — leftover from a batch clone done months ago, never regenerated. Not sure if that's related, since fixing the IDs didn't reliably fix the symptom either. Has anyone seen a Rule State condition show TRUE in the UI without the Rule ever producing a SET, surviving a clean restart? Thanks in advance
Multi-System Reactor
DynamicGroupController and attributes
therealdbT
Hey @toggledbits I'm back to trying to optimize a couple of things based on dynamic group. First of all, I think I found a typo in the doc: primary_attribute: "binary_sensor.state" primary_attribute_value: | d = false; each id in members: d = getEntity(id)?.attributes?.power_switch?.state or d, d I think the correct code snippet is d = false, All that said, my use case for dynamic groups is to group 3 different climate devices, so I could easily command them at the same time. Commands are good, but sometimes I want to check if any of the devices are on, and that's easily done with a similar snippet as the one you have in the docs. But this is limited to the primary attribute, while I want to have any of the attributes in the group to be driven by a similar logic (while all are null in the group). ie, access hvac_control.mode and see if any of the unit is set to cool, or heat. Is that possible, without re-defining an expression in each of my rules? Thanks!
Multi-System Reactor
Unofficial thread for compatibility
tunnusT
As there are statements about compatibility for home assistant versions in MSR new version announcements (e.g. "HassController: Bless Hass to 2025.7.3"), I thought it would be good idea to track other controllers as well. As an example, I can confirm that build "latest-25208-c53e8513" works with Hubitat Elevation C-8 platform version 2.4.2.134 using Maker API. Updates: (the latest versions first in the list) OK: build "latest-25264-2fbe9217" with Hubitat C-8 platform v. 2.4.3.123
Multi-System Reactor
Ooops - Deleted Reactor Ex Machina II
R
I accidentally deleted Reactor Ex Machina II (REM II) from my Reactor rules. I tried to recover it by deleting the .json and .dval in the Rules subdirectory and then recreating it from Togglebits original posting, but that did not work. Does anyone know how to recover REM ll ?
Multi-System Reactor
Bail out of failed reaction?
T
Topic thumbnail image
Multi-System Reactor
Arming Envisalink panel from MSR
T
Topic thumbnail image
Multi-System Reactor
[Solved] DynamicGroupController updating members issue
CrilleC
Edit: Solved in latest-26221. Bare-metal latest-26193 I have this group: "OKforLarm": name: OK för Larm select: - include_controller: vera - include_capability: door_sensor filter_expression: entity.attributes.door_sensor.state It contains the entities I expect but behaves a bit odd. When I open vera>device_10097 the entity attribute door_sensor.state changes to true but it won't show up as member in the group, when I also open vera>device_10095 they both shows as members and when I close vera>device_10095 it disappear from the group but when I close vera>device_10097 it lingers in the group until I restart Reactor.
Multi-System Reactor
Upgrade Issues
T
Topic thumbnail image
Multi-System Reactor
[SOLVED] Conflicting Set Reaction Groups Appear to Fire Simultaneously in Single Rule Evaluation
G
Topic thumbnail image
Multi-System Reactor
[SOLVED] Question regarding "in" vs "contains" vs contents of the string
G
Topic thumbnail image
Multi-System Reactor
Logon screen timeout
G
Noticing since 170 that the lock screen doesn't switch to the logon prompt but, rather, stays on the active UI until such time as you go to click something within it. Then it jumps to the login screen. Brave browser Brave 1.92.139 (Official Build) (arm64) Chromium: 150.0.7871.114
Multi-System Reactor
[MSR] Copy&past of actions and/or drag&drop between set/reset
therealdbT
Hey @toggledbits One thing that bothers me while doing work on new systems/new features, is that I cannot copy&paste actions, and I cannot drag&drop between set and resets. #1 is for when I want to copy an action between different rules opened in two separate browser windows, while #2 is when I just need to flip a bunch of actions in the reset, or move some logic back and forth. Both will be appreciated, but I understand the technical challenges. Thanks!
Multi-System Reactor
Upgrade advice - upgrade from aarch64 to ARM64 image
T
I'm currently on version 26011. I understand that the aarch64 image is no longer supported. So, I therefore need to update to the ARM64 image. Can anyone possibly suggest how I update my docker compose.yaml file (see below). Ideally I'd like to keep my existing reactions etc. rather than start from scratch. # Multi-System Reactor template docker-compose.yml (version 22160) # # Change the lines indicated by "DO"... # services: reactor: container_name: reactor environment: # DO change the TZ: line to set your local time zone. # See valid TZ list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones TZ: GB # # DO NOT change this path. Your directory location is in "source" below. REACTOR_DATA_PREFIX: /var/reactor # DO change the image below to the one you are using (e.g. armv7l or aarch64 for RPi 4) image: toggledbits/reactor:latest-aarch64 restart: "always" expose: - 8111 ports: - 8111:8111 volumes: # DO change the /home/username/reactor below to the directory you created for # your local data; DO NOT change the /var/reactor part - /home/pi/docker/reactor:/var/reactor - /etc/localtime:/etc/localtime:ro tmpfs: /tmp
Multi-System Reactor
Alexa for MSR, any interest?
MikeReadingtonM
Topic thumbnail image
Multi-System Reactor
[RESOLVED] Telegram notification broke with latest update
3
Topic thumbnail image
Multi-System Reactor
[RESOLVED] Phantom device, “INFO” appears
wmarcolinW
Topic thumbnail image
Multi-System Reactor

MSR with reverse proxy

Scheduled Pinned Locked Moved Multi-System Reactor
11 Posts 3 Posters 443 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tunnusT Offline
    tunnusT Offline
    tunnus
    wrote last edited by
    #1

    I'm trying to use MSR via reserve proxy in Synology DSM, but MSR page does not load

    https://<public ip>:30000/reactor/en-US/
    

    At the same time logging page loads normally

    https://<public ip>:30000/api/v1/log
    

    I thought maybe authentication was messing it up, but there was no deny entries in the log, and also disabling authentication did not make any difference. For this use case VPN is not an option (that works, but as said not an option for this particular use case).

    Any ideas what could cause this? MSR build latest-26242-28d69aa8, Chrome browser

    Using MSR on Docker (Synology NAS), having InfluxDB, Grafana & Home Assistant, Zigbee2MQTT & ZWA-2

    1 Reply Last reply
    0
    • toggledbitsT Offline
      toggledbitsT Offline
      toggledbits
      wrote last edited by
      #2

      Do you have baseurl set in your config?

      Author of Multi-system Reactor and Reactor, DelayLight, Switchboard, and about a dozen other plugins that run on Vera and openLuup.

      tunnusT 1 Reply Last reply
      1
      • toggledbitsT toggledbits

        Do you have baseurl set in your config?

        tunnusT Offline
        tunnusT Offline
        tunnus
        wrote last edited by
        #3

        @toggledbits yes I have

        baseurl: "http://<private ip>:8111"
        

        Using MSR on Docker (Synology NAS), having InfluxDB, Grafana & Home Assistant, Zigbee2MQTT & ZWA-2

        1 Reply Last reply
        0
        • toggledbitsT Offline
          toggledbitsT Offline
          toggledbits
          wrote last edited by toggledbits
          #4

          Yeah, that will likely be a problem. It will try to redirect to that private IP and find itself unable. The API calls to the public IP don't need to do this, but the UI interfaces very much do. You might try putting the public IP there.

          Author of Multi-system Reactor and Reactor, DelayLight, Switchboard, and about a dozen other plugins that run on Vera and openLuup.

          tunnusT 1 Reply Last reply
          0
          • toggledbitsT toggledbits

            Yeah, that will likely be a problem. It will try to redirect to that private IP and find itself unable. The API calls to the public IP don't need to do this, but the UI interfaces very much do. You might try putting the public IP there.

            tunnusT Offline
            tunnusT Offline
            tunnus
            wrote last edited by
            #5

            @toggledbits if I’d put public IP there, would it still work as expected when UI is used without a proxy? Also, does it accept dns name or just IPs?

            Using MSR on Docker (Synology NAS), having InfluxDB, Grafana & Home Assistant, Zigbee2MQTT & ZWA-2

            toggledbitsT 1 Reply Last reply
            0
            • tunnusT tunnus

              @toggledbits if I’d put public IP there, would it still work as expected when UI is used without a proxy? Also, does it accept dns name or just IPs?

              toggledbitsT Offline
              toggledbitsT Offline
              toggledbits
              wrote last edited by
              #6

              @tunnus said in MSR with reverse proxy:

              if I’d put public IP there, would it still work as expected when UI is used without a proxy?

              That's a routing/firewall issue. Some will do it out of the box, some you have to enable it (it's often called NAT loopback, NAT hairpinning, or NAT reflection).

              @tunnus said in MSR with reverse proxy:

              Also, does it accept dns name or just IPs?

              It should. That may be another path for you -- internal DNS resolution gives the local address, while external give the public address.

              Caution all around, though. I don't build or test this for use in such proxies. I can foresee issues with access control in your scenario, because there's a high probability of extra steps needed to "see through" the proxy to the real original requesting address. If it works for you, fine, but at the moment, I'm not inclined to do more on this.

              Author of Multi-system Reactor and Reactor, DelayLight, Switchboard, and about a dozen other plugins that run on Vera and openLuup.

              1 Reply Last reply
              0
              • therealdbT Offline
                therealdbT Offline
                therealdb
                wrote last edited by
                #7

                I use it with synology in this exact way. This is only resolved by my own dns running on my unifi. I have local entries in my laptop to resolve to my static ip. Even https/was are ok.

                --
                On a mission to automate everything.

                My MS Reactor contrib
                My Luup Plug-ins

                tunnusT 1 Reply Last reply
                0
                • therealdbT therealdb

                  I use it with synology in this exact way. This is only resolved by my own dns running on my unifi. I have local entries in my laptop to resolve to my static ip. Even https/was are ok.

                  tunnusT Offline
                  tunnusT Offline
                  tunnus
                  wrote last edited by
                  #8

                  @therealdb although I used only IP addresses and not dns names, I wasn't able to get UI to load. In my setup I'm using MSR in a docker container network and not host networking, so that might cause some additional headaches.

                  So could you share your configuration (e.g Synology reverse proxy conf, baseurl ...)? Obviously no need to use real IPs. I'm also wondering if https configuration in MSR can be avoided (not using that at the moment), but using let's encrypt cert in DSM. Port forwardings & firewall settings shouldn't be an issue, as /api/v1/log page works fine.

                  Screenshot 2026-10-03 at 16.53.53.png

                  (MSR itself being in a container network having 172.18.0.11 address)

                  Using MSR on Docker (Synology NAS), having InfluxDB, Grafana & Home Assistant, Zigbee2MQTT & ZWA-2

                  1 Reply Last reply
                  0
                  • therealdbT Offline
                    therealdbT Offline
                    therealdb
                    wrote last edited by
                    #9

                    sorry, I'm on a tour right now. I have a similar config, but I configured a specific host name and I'm on the standard HTTPs port.

                    maybe this is useful

                    image.png

                    --
                    On a mission to automate everything.

                    My MS Reactor contrib
                    My Luup Plug-ins

                    tunnusT 1 Reply Last reply
                    0
                    • therealdbT therealdb

                      sorry, I'm on a tour right now. I have a similar config, but I configured a specific host name and I'm on the standard HTTPs port.

                      maybe this is useful

                      image.png

                      tunnusT Offline
                      tunnusT Offline
                      tunnus
                      wrote last edited by tunnus
                      #10

                      @therealdb what's your baseurl setting? Especially are you using different external port (and not 8111)?

                      Using MSR on Docker (Synology NAS), having InfluxDB, Grafana & Home Assistant, Zigbee2MQTT & ZWA-2

                      1 Reply Last reply
                      0
                      • toggledbitsT Offline
                        toggledbitsT Offline
                        toggledbits
                        wrote last edited by toggledbits
                        #11

                        OK, I had some time in the past couple of weeks to look into this. Build 26284 now contains some changes that should smooth out configuration and use of reverse proxies. Let's see how it goes, and if I need to do more, we can work through that. There are a couple of new configuration keys to be used when a reverse proxy will provide access to Reactor, and a couple of existing keys have small (?) changes in behavior. The keys and behavior are summarized in the documentation for Access Control in the appropriate places, but to streamline the discussion and your efforts, I'll summarize them here. These configuration keys live in the reactor section of reactor.yaml.

                        First is trusted_proxy — this tells Reactor the host address of the LAN side of the reverse proxy. This is the address Reactor first sees opening the UI or API connection. The value of this configuration key can be an IPv4 address (e.g. 192.168.0.10). It can also be an array of addresses. I recommend surrounding the address(es) with quotes just to avoid any problems. When Reactor sees a request come in from this address, it looks to see if the request follows the HTTP/1.1 protocol for reverse proxied requests. If so, Reactor knows to track both the request source address (the inside address of the proxy) and the client address (the IP address of the client using the proxy to access Reactor, which may be inside or outside of the LAN). If those two addresses are different, Reactor knows its a proxy request.

                        Second is proxy_baseurl. This sets the URL to be used as baseurl when the request is proxied. If Reactor needs to redirect for the UI, it will use baseurl as the base of the redirect if the request is not a proxy request, and proxy_baseurl if it is proxied. Typically, users of reverse proxies will keep baseurl set to the internal (LAN) URL used to access Reactor (e.g. http://192.168.0.66:8111), but set the proxy_baseurl to the externally-resolvable URL for accessing Reactor from outside their network (e.g. https://example.duckdns.org:8554).

                        Proxied requests are processed a little differently by allowed_ips and ACL IP matching. When a request is proxied, the IP address matched by allowed_ips is that of the actual client, not the proxy's inside (LAN) address. Therefore, if you use allowed_ips with trusted_proxy, you must list every external/public host address (or network address in CIDR form) that is allowed to access Reactor through the proxy. By default, the proxy is not trusted by allowed_ips. That can be very inconvenient when you are a road warrior (frequent traveler to many places unknown) and want/need to access Reactor from wherever you may be. To help with this, at the expense of some security, you can tell Reactor that the proxy is trusted and all requests from the proxy should bypass allowed_ips filtering. Do this by setting pass_all_proxy: true, but if you do this, you must make sure that the proxy itself provides any and all filtering/authentication/security you might need before allowing access to Reactor. The pass_all_proxy key works only to circumvent the allow_ips list; it does not apply to ACLs.

                        Access control ACLs now have from_proxy to provide matching to requests coming from a specific proxy host (or network). The source_ip filter always looks at the client address. An analog for pass_all_proxy in ACLs could therefore be an ACL with from_proxy and allow: true (actual implementation depends on the full set of ACLs and their sequence).

                        Proxy configuration does not change any behavior of user access control in Reactor (i.e. Reactor user login). It is highly recommended that user login be configured and used when a reverse proxy is in use, even if the proxy provides access control in front of Reactor. If you choose not to use user login, you may be leaving your Reactor system vulnerable to external access by accidental discovery (e.g. port scans). Using user login with strong passwords provides an additional, necessary layer of deterrance to illicit access. Reactor will warn you if you are configured for proxy access without enabling and using user login.

                        The Reactor documentation recommends that you enable/use HTTPS when using user login/auth. You can get away without HTTPS if your access is exclusively on your home network (no external requests or reverse proxies), but it's a different matter when your login requests are going to be through public networks. Therefore, it is also highly recommended that you use HTTPS to access Reactor through your proxy. At the very least, your proxy should receive SSL/TLS-encrypted HTTP requests at its public/external interface. You can keep internal access to Reactor in plain, unencrypted HTTP (including requests from the proxy to Reactor) if you trust your internal network.

                        And for clarity, in all above where I say "highly recommended" I mean required unless you want to invite trouble.

                        To wrap up, a checklist:

                        1. Set trusted_proxy to the inside host/interface address of your reverse proxy;
                        2. Set proxy_baseurl to the externally-accessible URL used to reach Reactor through your reverse proxy;
                        3. Enable and configure user authentication/login in Reactor if you haven't already;
                        4. Make sure your proxy's public interface uses HTTPS (encrypted); HTTPS on the inside (between proxy and Reactor) is up to you.

                        Ref: Access Control in Reactor documentation

                        And a disclaimer: Opening up any system to the public Internet increases risk. Because the totality of your systems, tools, and needs are unique to you, only you can assess the risks of such access, and the correct and most secure way to provide it. Proceed at your own risk, and know that it is entirely at your own risk and that you accept that risk and its consequences in so doing. I am providing tools, not solutions. How you use these tools is up to you, and the consequences for not using any tool properly can be dire. If you don't know what you are doing in this area, don't do it. You've been warned.

                        Author of Multi-system Reactor and Reactor, DelayLight, Switchboard, and about a dozen other plugins that run on Vera and openLuup.

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        Recent Topics

                        • Reactor (Multi-System/Multi-Hub) Announcements
                          toggledbitsT
                          toggledbits
                          5
                          150
                          145.4k

                        • MSR with reverse proxy
                          toggledbitsT
                          toggledbits
                          0
                          11
                          443

                        • Use of Google Gemini as an MSR and Hubitat configuration aid
                          therealdbT
                          therealdb
                          0
                          2
                          121

                        • [MSR] Native fan capabilty
                          therealdbT
                          therealdb
                          1
                          3
                          189

                        • [MSR] Rule do not fire
                          therealdbT
                          therealdb
                          0
                          4
                          231

                        • Rule condition shows TRUE in UI but Rule never transitions to SET — survives full restart
                          N
                          noelab
                          0
                          8
                          350

                        • DynamicGroupController and attributes
                          toggledbitsT
                          toggledbits
                          1
                          9
                          438

                        • Unofficial thread for compatibility
                          tunnusT
                          tunnus
                          2
                          2
                          817

                        • Ooops - Deleted Reactor Ex Machina II
                          toggledbitsT
                          toggledbits
                          0
                          2
                          151

                        • Bail out of failed reaction?
                          T
                          tamorgen
                          0
                          3
                          279

                        • Arming Envisalink panel from MSR
                          T
                          tamorgen
                          0
                          7
                          526

                        • [Solved] DynamicGroupController updating members issue
                          CrilleC
                          Crille
                          0
                          5
                          375
                        Powered by NodeBB | Contributors
                        Hosted freely by 10RUPTiV - Solutions Technologiques | Contact us
                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • Unsolved