Mosquitto on Umbrel step by step

Goal: get Mosquitto from the Umbrel App Store running as a password-protected MQTT broker and connect Home Assistant and Zigbee2MQTT to it. After installation the app lets anonymous clients in, so the most important step is turning on passwords.1
Prerequisites: Umbrel (e.g. Umbrel Home or a Raspberry Pi with 8 GB or more), access to Settings โ†’ Advanced settings โ†’ Terminal, for Zigbee a network coordinator (e.g. SLZB-MR3) with a static IP.

Required apps

App (Umbrel App Store) Version Needed Purpose
Mosquitto 2.1.2 always broker, port 1883 (MQTT) and 9021 (web and MQTT over WebSockets)1
Home Assistant 2026.10.0 usually MQTT integration, runs in the host network (network_mode: host)1
Zigbee2MQTT 2.14.2 for Zigbee over MQTT has Mosquitto as a dependency and connects to mqtt://mosquitto_broker_1:18831
MQTTX Web 1.13.1 optional in-browser MQTT client for debugging, connects over WebSockets1

Synthesis: HA on Umbrel is a container without apps (formerly add-ons), so the "Mosquitto broker" from HA OS is not available here and HA cannot set up broker passwords by itself. You create users manually in step 2.

Procedure

  1. Install Mosquitto from the App Store (automation category). If you want Zigbee2MQTT, Umbrel won't install it without Mosquitto.1
  2. Create users. In the umbrelOS terminal run mosquitto_passwd, which ships in the broker image.2 The container is named mosquitto_broker_11:
    sudo docker exec -it mosquitto_broker_1 mosquitto_passwd -c /mosquitto/data/mosquitto.password_file ha
    sudo docker exec -it mosquitto_broker_1 mosquitto_passwd /mosquitto/data/mosquitto.password_file z2m
    
    -c creates (and overwrites) the file, so only for the first user. The password is entered interactively. Synthesis: one user per service, so one can be cut off without affecting the others. On the host the file is in ~/umbrel/app-data/mosquitto/data/mosquitto/.1
  3. Edit the config: sudo nano ~/umbrel/app-data/mosquitto/data/config/mosquitto.conf.1 Replace allow_anonymous true and the commented-out #password_file with:
    allow_anonymous false
    plugin /usr/lib/mosquitto_password_file.so
    plugin_opt_password_file /mosquitto/data/mosquitto.password_file
    
    Since 2.1 password_file is deprecated in favour of the password-file plugin and will be removed in 3.0.3 The plugin path and plugin_opt_password_file follow the official Docker image.2 Without per_listener_settings authentication applies to both listeners, including WebSockets on 9021.2
  4. Restart the broker: sudo docker restart mosquitto_broker_1, or restart the app in the Umbrel UI. Then sudo docker logs --tail 30 mosquitto_broker_1: the broker must run without errors. In 2.1 a broken password file makes the broker exit.3
  5. Home Assistant: Settings โ†’ Devices & services โ†’ Add integration โ†’ MQTT, enter the broker, port 1883, user ha and password.4 Use 127.0.0.1 as the broker: HA runs in the host network and Mosquitto publishes port 1883 on the host.1 Keep the default discovery prefix homeassistant.4
  6. Zigbee2MQTT (optional): install it and go through the onboarding wizard. It runs while no configuration.yaml exists and can find the adapter via mDNS, otherwise you enter port and type manually.5
    • network coordinator: port: tcp://<ip>:6638, the default SLZB socket is 66386
    • type: ember for Silicon Labs (EFR32), zstack for TI (CC26xx). The SLZB-OS config generator prints the values.5,6
  7. Zigbee2MQTT โ†’ password-protected broker. The app only sets the server address.1 Add to ~/umbrel/app-data/zigbee2mqtt/data/configuration.yaml (the data folder is /app/data in the container)1:
    mqtt:
      user: z2m
      password: '!secret.yaml password'
    homeassistant:
      enabled: true
    
    and the password into secret.yaml next to it (password: โ€ฆ).5 homeassistant.enabled turns on MQTT discovery into HA.5 Then restart the Zigbee2MQTT app.
  8. Turn off ZHA. Only one service can drive the coordinator. Delete and ignore the discovered ZHA integration in HA.7

Verification

Optional: ACL

The acl-file plugin limits who may read and write which topics: plugin /usr/lib/mosquitto_acl_file.so and plugin_opt_acl_file /mosquitto/data/mosquitto.aclfile.2 Lines user <name> with topic [read|write|readwrite|deny] <topic> below.2

user z2m
topic readwrite zigbee2mqtt/#
topic readwrite homeassistant/#

user ha
topic readwrite #

Synthesis: with ACLs on, everything else is denied, so Z2M also needs homeassistant/# for discovery. Add ACLs only after verifying everything works without them.

Rollback

Troubleshooting

Related

Sources

  1. Umbrel App Store: the Mosquitto app โ†— โ€” Mosquitto, Zigbee2MQTT, Home Assistant and MQTTX Web apps in the Umbrel App Store.
  2. Eclipse Mosquitto: Docker image 2.1 and mosquitto.conf(5) โ†— โ€” official Mosquitto 2.1 Docker image (plugins, paths) and mosquitto.conf(5).
  3. Mosquitto blog: release notes 2.0.19โ€“2.1.2 โ†— โ€” changes in 2.1.
  4. Home Assistant documentation (installation, concepts, backups, MQTT, ZHA, SMLIGHT, UniFi) โ†— โ€” MQTT integration setup.
  5. Zigbee2MQTT documentation (Zigbee network, stability, binding, pairing) โ†— โ€” MQTT, adapter, HA integration, onboarding.
  6. SLZB-OS (SMLIGHT Manuals) โ†— โ€” network coordinator socket.
  7. Home Assistant Connect ZBT-2 (Nabu Casa Support) โ†— โ€” ZHA next to Z2M.