# HomeOS MQTT ACLs — least privilege per client role.

# Backend (Laravel listener + drivers): full access to the bus.
user laravel
topic readwrite #

# Shelly devices (shared role): publish their own status/telemetry, read their commands.
# `+` matches the per-device topic prefix.
user shelly
topic write +/status/#
topic write +/events/#
topic write +/online
topic read +/command/#
topic readwrite +/rpc
topic write +/rpc_ntf

# Discovery sidecar (Phase 4): only publishes discovery findings.
user sidecar
topic write homeos/discovery/#
