What was wrong before

Home Assistant uses the visitor's IP address in three places that matter for security: failed login notifications, the login history, and IP banning. With every request arriving from the same internal address, all three were close to useless:

What changes in 0.7.0

How it works — and what it does not change

The Pluggie relay accepts the visitor's connection, so it knows the visitor's IP address. It now passes that address to the Pluggie app on your device in a small header placed in front of the encrypted stream. The format is the PROXY protocol, an open standard used by load balancers and reverse proxies.

One request, end to end
Visitor
public IP
→
Pluggie relay
adds the visitor's IP
→
Pluggie app
TLS ends here
→
Home Assistant
sees the real IP

Nothing about encryption changes. TLS is still terminated on your own device, with a certificate that is generated and stored there. The relay still forwards encrypted bytes it cannot read — the address header travels next to the encrypted stream, not inside it. If you want the full technical picture of what the relay can and cannot see, read Can Pluggie See Your Traffic?

On your device, the Pluggie app reads the address and hands it to Home Assistant in the standard X-Forwarded-For header. Home Assistant already trusts that header from Pluggie, because that is exactly what the one-time trusted proxy setting is for.

What you need to do

1
Update Pluggie

Home Assistant: open Settings → Apps → Pluggie and click Update. Docker: pull the new image and recreate the container with the same settings.

2
That's it

No change to your Home Assistant configuration is needed. The trusted proxy setting you made during installation stays exactly the same. If you have never made it, follow How to Set Up Trusted Proxies in Home Assistant first.

Not ready to update?

Older versions keep working exactly as before. Nothing breaks if you stay on your current version — Home Assistant simply keeps seeing the endpoint address instead of the real one.

Turning on IP banning (optional)

With real addresses available, Home Assistant's built-in IP banning becomes useful. In Home Assistant 2026.8 or newer:

  1. Open Settings → System → Network and find the HTTP server section.
  2. Turn on Enable IP banning.
  3. Set Login attempts before ban, for example 5. Leaving Unlimited login attempts on disables banning.
  4. Save. Home Assistant restarts, and you have to confirm the new settings afterwards — otherwise they are reverted after 5 minutes.

On versions older than 2026.8, the same options are ip_ban_enabled: true and login_attempts_threshold: 5 in the http: section of configuration.yaml.

Banned yourself?

Bans are stored in ip_bans.yaml in your Home Assistant configuration folder. A ban applies to your public IP address, so you can still sign in from your home network using the local address (for example http://homeassistant.local:8123). Remove the entry from ip_bans.yaml and restart Home Assistant.

How to check that it works

Open your Pluggie address on your phone with Wi-Fi turned off, and enter a wrong password once. Home Assistant shows a "Login attempt failed" notification. It should list your phone's public IP address — not an internal 10.x.x.x address.

Using the Pluggie Docker container with other services?

The same improvement applies to anything you run behind the Pluggie Docker container. Your service receives the visitor's real address in the X-Forwarded-For header. It will only use it if it trusts the Pluggie container as a proxy — the same idea as in Home Assistant, configured with set_real_ip_from in nginx or RemoteIPTrustedProxy in Apache.

📬 Questions?

If something does not look right after updating, write to support@pluggie.net with your Pluggie hostname and the version shown on the app page.