1---2name: iot3description: Assist with IoT device setup, protocols, security hardening, and home automation integration.4---5
6## Protocol Selection
7- MQTT for lightweight messaging — pub/sub, low bandwidth, ideal for sensors
8- CoAP for constrained devices — UDP-based, REST-like, very low power
9- HTTP/REST for capable devices — familiar but heavier, use when bandwidth allows
10- WebSocket for real-time bidirectional — dashboards, live updates
11- Zigbee/Z-Wave for mesh networks — no WiFi needed, battery-friendly
12
13## MQTT Essentials
14- Broker is the central hub — Mosquitto most common self-hosted
15- Topics are hierarchical — home/livingroom/temperature
16- QoS levels: 0 (fire-forget), 1 (at least once), 2 (exactly once)
17- Retain flag keeps last message — new subscribers get current state
18- Will message announces disconnection — device offline detection
19
20## Security (Critical)
21- Never expose MQTT broker to internet without auth — bots scan constantly
22- TLS mandatory for any external access — encrypt all traffic
23- Unique credentials per device — revoke one without affecting others
24- Firmware updates must be signed — prevent malicious updates
25- Segment IoT on separate VLAN — isolate from main network
26
27## Common Vulnerabilities
28- Default credentials left unchanged — first thing attackers try
29- Unencrypted protocols on network — credentials sniffable
30- No firmware update mechanism — stuck with known vulnerabilities
31- Cloud dependency without fallback — device useless when server down
32- Debug ports left enabled — UART, JTAG exposed
33
34## Home Assistant Integration
35- MQTT discovery auto-configures devices — follow HA format
36- ESPHome for custom ESP devices — YAML config, OTA updates
37- Zigbee2MQTT bridges Zigbee to MQTT — hundreds of devices supported
38- Tasmota for off-the-shelf flashing — many WiFi devices supported
39
40## ESP32/ESP8266 Development
41- Arduino framework most accessible — huge library ecosystem
42- ESP-IDF for production — FreeRTOS, more control, steeper curve
43- PlatformIO over Arduino IDE — better dependency management
44- Deep sleep for battery life — microamps when sleeping
45- OTA updates essential — don't require physical access
46
47## Power Management
48- Battery devices need deep sleep — wake on timer or interrupt
49- Calculate power budget — mAh capacity vs average consumption
50- Solar charging viable — small panel can sustain low-power sensors
51- Supercapacitors for burst power — supplement weak batteries
52- Monitor battery voltage — alert before device dies
53
54## Connectivity Patterns
55- WiFi: high bandwidth, high power — plugged devices
56- Zigbee/Z-Wave: mesh, low power — battery sensors
57- LoRa: long range, low bandwidth — outdoor, agricultural
58- BLE: short range, low power — wearables, beacons
59- Thread/Matter: new standard — Apple/Google/Amazon unified
60
61## Reliability
62- Watchdog timer prevents freezes — reset if loop stalls
63- Persistent storage for state — survive power cycles
64- Heartbeat/ping monitoring — detect silent failures
65- Graceful degradation — work offline when cloud unavailable
66- Redundant sensors for critical systems — don't trust single point
67
68## Data Considerations
69- Sample rate vs storage — don't over-collect
70- Local processing when possible — reduce bandwidth, latency
71- Time synchronization critical — NTP for timestamps
72- Aggregate before sending — reduce message count
73- Retain important data locally — survive connectivity loss
74
75## Debugging
76- Serial output for development — remove in production
77- MQTT debug topics — publish diagnostics
78- LED status indicators — quick visual feedback
79- Remote logging carefully — don't flood network
80- Simulate sensors for testing — don't wait for real conditions
81
82## Vendor Lock-in
83- Prefer local API devices — Tuya local, Shelly, Tasmota-compatible
84- Cloud-only devices risky — company shutdowns brick devices
85- Open protocols over proprietary — MQTT, Zigbee over custom
86- Check if flashable — many devices accept custom firmware
87- Matter promises interoperability — but still maturing