Bit of background:
I am new to Home Assistant in 2025 (loving it so far), and relatively new to “proper” network management after finally taking the dive into Unifi in October 2024. I am, admittedly, quite proud of what I have learned and implemented so far, and the learning never ends. However, while proud of my progress, I have much to learn still; as a result, please pardon an oversight or ignorance in my question.
Current Setup:
HA installed on miniPC via HAOS on my IoT VLAN (along with all my IoT devices)
Pixel 8 running Android 15
I am currently looking at a more efficient way of home/away detection that doesn’t require location sensor on Companion App to be on all the time (I tried Wi-Fi connection sensor within the app, but it seems the entity does not update in a timely manner in the background unless I also have Background Location enabled as well).
I’m interested in the Unifi Integration that allows me to use connected clients as device tracker, and I am aware of the guides and setting it up. Instead my question lies in the security of adding such an integration; and I wonder if I am overthinking or simply wrong. For said integration, you require an admin account of read//write privilege (I opt for read-only); while unable to change anything, this account can read everything within your Unifi console (unmask VPN keys, SSH keys if you use, public IP address, etc). Therefore, if an IoT device on that VLAN becomes compromised, while contained within the IoT VLAN with firewall rules, it can now still access your unifi console with the read-only admin account via HomeAssistant.
Is this not a large security issue? We spend time locking down the IOT VLAN, including blocking access to the gateway itself (except for DNS requests on 53 and 443), but now via HA we open the front door into the unifi console?
Thank you for taking the time to read my post and help me further my understanding and knowledge ![:slight_smile: :slight_smile:]()
9 posts - 4 participants
Read full topic