Skip to content

Install HotLoop Gateway 4.17.0 with Helm

HotLoop Gateway 4.17.0 ships as a container image for amd64 and arm64, about 34 MB, and a Helm chart. Both pull with no login. Already running an older release? Don’t install over it. Upgrading has the path from 4.16.0, which is a plain helm upgrade with one flag that bites, and the path from 4.3.1, which isn’t plain at all because the chart was renamed.

It runs on any Kubernetes, k3s included. There’s no Quadlet unit for the Gateway yet, so off a cluster, the answer is k3s. The Edge Relay has one today. There’s no Docker or Compose path, on purpose.

Terminal window
helm repo add hotloop https://hotloop.io/hotloop
helm repo update
helm install hotloop hotloop/hotloop --version 4.17.0 \
--namespace hotloop --create-namespace

That deploys the Gateway, plus TimescaleDB 2.30.1 beside it on a 20 Gi volume. The chart generates the database password, the MCP token and an admin password into the release Secret, and reuses them on every upgrade, so a helm upgrade never rotates a password out from under you or logs you out of your own plant.

The chart also generates a second Secret, <release>-secret-key (hotloop-secret-key with the command above). It holds the key that encrypts every password HotLoop keeps for a device: an OPC UA, MQTT, HTTP, MTConnect or UniFi password, and HTTP and MTConnect header values such as API keys. The key is never in the database and never in a backup, so a dump that walks out the door on a laptop holds ciphertext, not the keys to the plant.

The chart keeps that Secret across upgrades, and keeps it through a helm uninstall too, because a database left on its volume is useless for its credentials without it. That also means the key is part of your data. Start the Gateway without it and every device with a sealed password stays down, retrying, with an error that names the key it needs. A backup restores only where that key is mounted, and --restore-from refuses it by name anywhere else.

So back the Secret up the way you back up the rest of the cluster’s secrets, and keep it somewhere other than next to your backups. A key sitting beside the backups it protects protects nothing.

Rendering the chart instead of installing it? Bring your own key. The key is generated by a lookup that only a real helm install or helm upgrade can do. Anything that runs helm template and applies the result gets a new key on every render, and the next sync locks every sealed password out. Make a key with hotloop gen-secret-key, put it in a Secret you manage under the key secret.key, and name that Secret in secretKey.existingSecret. Helm, Fleet and the EmberNET App Store all install for real and don’t need this.

A credential written into a URL (mqtt://user:pass@host) or into free text stays in the clear. Put it in password. Device credentials has the full list of what gets encrypted.

The user is admin. The install notes print the command that reads the password back:

Terminal window
kubectl -n hotloop get secret hotloop \
-o jsonpath='{.data.admin-password}' | base64 -d
kubectl -n hotloop port-forward svc/hotloop 8080:8080

Open http://localhost:8080. That admin account is a bootstrap, not a reset switch. Once it exists, changing auth.admin.password and upgrading does nothing, so a password somebody set in the UI never gets clobbered by the next deploy.

Now add a device, discover its tags, and try to write to one. You can’t. That’s on purpose. Every tag starts read-only and gets armed one at a time, and safety.allowWrites stays off until you decide this pod gets to move machinery. Nobody’s first day with HotLoop should end with a press doing something they didn’t ask for.

Put these in a values file and install with -f. Don’t lean on --set for anything you’ll need again at the next upgrade, because you won’t remember it and the upgrade won’t either.

Value Default Why you’d touch it
plant.name, plant.siteId HotLoop, empty What the plant is called on screens, in pages, and to other sites.
global.timezone America/New_York Schedules, reports and shift changes run on it. It has to be a real zone name (America/Chicago, not CST), because a timezone that won’t load stops startup instead of quietly running on UTC.
publicUrl empty The address a phone on the plant Wi-Fi reaches HotLoop at. Without it, notifications have no link back and ntfy gets no Acknowledge button.
safety.allowWrites false The master switch. Off, nothing writes to a machine, from anywhere. Turn it on once the deployment has been reviewed.
safety.allowMcpWrites false Lets agents write through the same gate. It narrows the master switch and never goes around it. Set it without safety.allowWrites and the Gateway refuses to start.
database.postgresql.persistence.size 20Gi Your history lives here. Size it for your tag count and historian.retentionDays (90).
logbook.retentionDays 90 Days of entity state changes the logbook keeps. 0 keeps everything until the volume fills, and the Gateway warns you about it at start.
secretKey.existingSecret empty A Secret you manage holding the device password key. Leave it empty and the chart makes one. Set it if you render the chart with helm template.
database.postgresql.enabled true Set false and fill in database.external to use your own PostgreSQL. With the TimescaleDB extension you get a hypertable, without it native partitioning.
opcuaClient.persistence.enabled false Turn it on before you add a secured OPC UA device. Without it the client’s certificates have nowhere to survive a restart, and the device refuses to connect rather than make you re-approve trust on both ends after every redeploy.
ingress off Only if you want it reachable from outside the cluster by a name.

Writes ship off, and that’s the point. Even with safety.allowWrites on, a tag is read-only until you arm it on its own, and every value is checked against the tag’s range, refused and never clamped. The write gate has every check, in order.

Add a device, discover its tags, and watch them come in. Protocols says how far each driver has been proven, including the two that have never touched a physical PLC. If you run it under the EmberNET dashboard, the dashboard finds it by itself and proxies it at the in-cluster address, no ingress needed.

HotLoop Gateway is free for individual use. Using it in a business? That goes through EmberNET, where signing up is free and so is business use. See Using HotLoop in a business.