Skip to main content
Version: 1.0.0

Home Assistant on Aruba Cloud

Deploy Home Assistant — the leading open-source home automation platform — on Aruba Cloud using Terraform and cloud-init. Home Assistant runs as a Docker container (Home Assistant Container edition) with persistent configuration storage.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

Home Assistant is a privacy-focused home automation hub that integrates with thousands of smart home devices. This example deploys the Home Assistant Container edition, which provides the full Home Assistant core experience in a Docker container. It provisions:

  • Docker installed from the official Docker apt repository
  • Home Assistant Container (ghcr.io/home-assistant/home-assistant:stable) managed by Docker Compose
  • Persistent configuration stored in /opt/homeassistant/config
  • A systemd service that starts Home Assistant automatically on boot
  • Port 8123 for the web UI, restricted to admin_cidr
  • Configurable timezone

First-time setup: The first visit to the Home Assistant UI triggers the onboarding wizard where you create your admin account and configure your home location. No credentials are pre-set by Terraform.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectha-prodProject container
arubacloud_vpcha-prod-vpcVirtual Private Cloud
arubacloud_subnetha-prod-subnetBasic subnet
arubacloud_securitygroupha-prod-vm-sgSecurity group
arubacloud_securityruleha-prod-vm-sshSSH ingress
arubacloud_securityruleha-prod-vm-admin-uiWeb UI ingress TCP 8123
arubacloud_elasticipha-prod-vm-eipVM public IP
arubacloud_blockstorageha-prod-boot32 GB boot disk (Performance)
arubacloud_keypairha-prod-keypairSSH public key
arubacloud_cloudserverha-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO2A4 — 2 vCPU / 4 GB~€18
Boot disk32 GB Performance~€5
Elastic IP—~€3
Total~€26/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content

Optional​

VariableDefaultDescription
app_name"ha"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO2A4"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb32Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH
admin_cidr"0.0.0.0/0"CIDR for web UI port 8123 — restrict in production
timezone"UTC"Timezone for Home Assistant

Outputs​

OutputDescription
home_assistant_urlHome Assistant web UI URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/home-assistant

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Set your credentials, timezone, and restrict the UI to your IP:

timezone = "Europe/Rome"
admin_cidr = "203.0.113.42/32"
ssh_cidr = "203.0.113.42/32"

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 3–5 minutes (Docker install + image pull).

4. Complete onboarding​

terraform output home_assistant_url

Open the URL — the first visit shows the onboarding wizard. Create your admin account, set your home location, and start adding integrations.


Security Recommendations​

  1. Restrict admin_cidr to your IP or VPN tunnel CIDR. Home Assistant on 0.0.0.0/0 is acceptable for initial setup, but should be locked down before connecting any real devices.

  2. Enable HTTPS. Home Assistant supports TLS natively. After onboarding, go to Settings → System → Network and configure a trusted network or enable the built-in HTTPS proxy. Alternatively, place it behind Caddy or NGINX (from this repo) for automatic TLS.

  3. Use a VPN. The recommended long-term setup: restrict admin_cidr to your WireGuard tunnel CIDR and access Home Assistant exclusively over VPN.


Troubleshooting​

Home Assistant not loading after deploy​

ssh ubuntu@$(terraform output -raw vm_public_ip)
docker logs homeassistant --tail 50
sudo systemctl status homeassistant

The first start pulls ~200 MB from GitHub Container Registry — give it 3–5 minutes.

Updating Home Assistant​

ssh ubuntu@$(terraform output -raw vm_public_ip)
cd /opt/homeassistant
docker compose pull
docker compose up -d

Home Assistant releases new versions monthly. Consider enabling Settings → System → Updates in the HA UI for in-place updates.


References​