Mosquitto on Umbrel step by step
Goal: get Mosquitto from the Umbrel App Store running as a password-protected MQTT broker and connect Home Assistant and Zigbee2MQTT to it. After installation the app lets anonymous clients in, so the most important step is turning on passwords.1
Prerequisites: Umbrel (e.g. Umbrel Home or a Raspberry Pi with 8 GB or more), access to Settings โ Advanced settings โ Terminal, for Zigbee a network coordinator (e.g. SLZB-MR3) with a static IP.
Required apps
| App (Umbrel App Store) | Version | Needed | Purpose |
|---|---|---|---|
| Mosquitto | 2.1.2 | always | broker, port 1883 (MQTT) and 9021 (web and MQTT over WebSockets)1 |
| Home Assistant | 2026.10.0 | usually | MQTT integration, runs in the host network (network_mode: host)1 |
| Zigbee2MQTT | 2.14.2 | for Zigbee over MQTT | has Mosquitto as a dependency and connects to mqtt://mosquitto_broker_1:18831 |
| MQTTX Web | 1.13.1 | optional | in-browser MQTT client for debugging, connects over WebSockets1 |
Synthesis: HA on Umbrel is a container without apps (formerly add-ons), so the "Mosquitto broker" from HA OS is not available here and HA cannot set up broker passwords by itself. You create users manually in step 2.
Procedure
- Install Mosquitto from the App Store (automation category). If you want Zigbee2MQTT, Umbrel won't install it without Mosquitto.1
- Create users. In the umbrelOS terminal run
mosquitto_passwd, which ships in the broker image.2 The container is namedmosquitto_broker_11:sudo docker exec -it mosquitto_broker_1 mosquitto_passwd -c /mosquitto/data/mosquitto.password_file ha sudo docker exec -it mosquitto_broker_1 mosquitto_passwd /mosquitto/data/mosquitto.password_file z2m-ccreates (and overwrites) the file, so only for the first user. The password is entered interactively. Synthesis: one user per service, so one can be cut off without affecting the others. On the host the file is in~/umbrel/app-data/mosquitto/data/mosquitto/.1 - Edit the config:
sudo nano ~/umbrel/app-data/mosquitto/data/config/mosquitto.conf.1 Replaceallow_anonymous trueand the commented-out#password_filewith:
Since 2.1allow_anonymous false plugin /usr/lib/mosquitto_password_file.so plugin_opt_password_file /mosquitto/data/mosquitto.password_filepassword_fileis deprecated in favour of the password-file plugin and will be removed in 3.0.3 The plugin path andplugin_opt_password_filefollow the official Docker image.2 Withoutper_listener_settingsauthentication applies to both listeners, including WebSockets on 9021.2 - Restart the broker:
sudo docker restart mosquitto_broker_1, or restart the app in the Umbrel UI. Thensudo docker logs --tail 30 mosquitto_broker_1: the broker must run without errors. In 2.1 a broken password file makes the broker exit.3 - Home Assistant: Settings โ Devices & services โ Add integration โ MQTT, enter the broker, port 1883, user
haand password.4 Use127.0.0.1as the broker: HA runs in the host network and Mosquitto publishes port 1883 on the host.1 Keep the default discovery prefixhomeassistant.4 - Zigbee2MQTT (optional): install it and go through the onboarding wizard. It runs while no
configuration.yamlexists and can find the adapter via mDNS, otherwise you enter port and type manually.5 - Zigbee2MQTT โ password-protected broker. The app only sets the server address.1 Add to
~/umbrel/app-data/zigbee2mqtt/data/configuration.yaml(thedatafolder is/app/datain the container)1:
and the password intomqtt: user: z2m password: '!secret.yaml password' homeassistant: enabled: truesecret.yamlnext to it (password: โฆ).5homeassistant.enabledturns on MQTT discovery into HA.5 Then restart the Zigbee2MQTT app. - Turn off ZHA. Only one service can drive the coordinator. Delete and ignore the discovered ZHA integration in HA.7
Verification
- Broker log without errors after restart; connecting clients show up with their user names (
sudo docker logs -f mosquitto_broker_1). Synthesis - MQTTX Web: new connection to
umbrel.local, port 9021 (WebSockets), user and password. Without a password it won't connect; with one, subscribe to#.1 - HA: MQTT integration without errors. "Listen to a topic" with
#in its settings shows the traffic.4 - Z2M: the frontend shows the coordinator, and paired devices appear in HA through discovery.
Optional: ACL
The acl-file plugin limits who may read and write which topics: plugin /usr/lib/mosquitto_acl_file.so and plugin_opt_acl_file /mosquitto/data/mosquitto.aclfile.2 Lines user <name> with topic [read|write|readwrite|deny] <topic> below.2
user z2m
topic readwrite zigbee2mqtt/#
topic readwrite homeassistant/#
user ha
topic readwrite #
Synthesis: with ACLs on, everything else is denied, so Z2M also needs homeassistant/# for discovery. Add ACLs only after verifying everything works without them.
Rollback
- Restore
allow_anonymous true, comment out bothpluginlines and restart the broker. - Keep the password and ACL files in place so the change can be repeated.
Troubleshooting
- Broker won't start: wrong path to the file or plugin. Always use the path inside the container (
/mosquitto/...), not on the host (~/umbrel/...).2 Since 2.1 the config can be checked with--test-config.3 - "not authorised" / refused connection: wrong user or password, or a client still running without a password (typically Z2M after step 3). Synthesis
- Large messages fail: since 2.1
max_packet_sizedefaults to 2 MB instead of 256 MB.3 - Access from outside: don't expose the broker to the internet, use a VPN for remote access, see Mosquitto. Umbrel itself recommends authentication when exposing it.1
Related
- Mosquitto, MQTT, Zigbee2MQTT, Home Assistant, Home Assistant Connect SLZB, Umbrel Home, Raspberry Pi, SLZB-MR3, ZHA, Docker
Sources
- Umbrel App Store: the Mosquitto app โ โ Mosquitto, Zigbee2MQTT, Home Assistant and MQTTX Web apps in the Umbrel App Store.
- Eclipse Mosquitto: Docker image 2.1 and mosquitto.conf(5) โ โ official Mosquitto 2.1 Docker image (plugins, paths) and mosquitto.conf(5).
- Mosquitto blog: release notes 2.0.19โ2.1.2 โ โ changes in 2.1.
- Home Assistant documentation (installation, concepts, backups, MQTT, ZHA, SMLIGHT, UniFi) โ โ MQTT integration setup.
- Zigbee2MQTT documentation (Zigbee network, stability, binding, pairing) โ โ MQTT, adapter, HA integration, onboarding.
- SLZB-OS (SMLIGHT Manuals) โ โ network coordinator socket.
- Home Assistant Connect ZBT-2 (Nabu Casa Support) โ โ ZHA next to Z2M.
Intellihome