Files
ruvnet--RuView/v2/crates/cog-ha-matter/blueprints/bfld/identity-risk-anomaly.yaml
T
ruv 820258e932 feat(adr-118/p5.10): three HA operator blueprints (210/210 GREEN)
Iter 30. Ships the three ADR-122 §2.6 operator-ready Home Assistant
automation blueprints. Each blueprint binds to one BFLD MQTT entity
(presence / motion / identity_risk) and lets an HA operator import
+ configure without writing YAML by hand.

Added (under v2/crates/cog-ha-matter/blueprints/bfld/):
- presence-lighting.yaml
    binary_sensor.<node>_bfld_presence ⇒ light.turn_on / turn_off
    with a configurable hold_seconds delay before the off action
    (ADR-122 §2.6 requirement: "configurable hold time")
- motion-hvac.yaml
    sensor.<node>_bfld_motion ⇒ climate.set_temperature
    Operator picks motion_threshold (default 0.3, per ADR §2.6),
    delta_temperature_c (°C adjustment), and quiet_seconds debounce
- identity-risk-anomaly.yaml
    sensor.<node>_bfld_identity_risk ⇒ notify.<target>
    Two trigger paths:
      - Absolute spike (raw score >= spike_threshold, default 0.8)
      - Rolling 7-day z-score deviation (default 3 sigma)
    Requires a Statistics helper entity for the baseline; documented
    in the inline description and the blueprints README.
- README.md
    Lists the three blueprints + privacy caveat for identity_risk
    (only present at PrivacyClass::Anonymous; class 3 deployments
    will fail validation by design)

Added (in v2/crates/wifi-densepose-bfld/tests/ha_blueprints.rs):
- 7 named tests using include_str! to embed each YAML at build time
  and validate structure without adding a serde_yaml dep:
    presence_lighting_blueprint_is_structurally_valid
    motion_hvac_blueprint_is_structurally_valid
    identity_risk_blueprint_is_structurally_valid
    blueprints_carry_source_url_pointing_at_canonical_path
      (catches path drift when files move)
    presence_blueprint_uses_mqtt_integration_filter
    motion_blueprint_uses_mqtt_integration_filter
    identity_risk_blueprint_carries_privacy_class_caveat_in_description
      (operators running class 3 should know not to install)
- Helper assert_required_blueprint_fields(yaml, name_substring, label)
  enforces blueprint.{name,domain,input,trigger,action,mode} per HA spec

ACs progressed:
- ADR-122 §2.6 — all three blueprints shipped with the documented
  configurable inputs (hold_seconds for #1, motion_threshold +
  delta_temperature_c for #2, z_score_threshold + statistics_entity
  for #3). Operator installs via HA UI; no YAML editing required.
- ADR-118 §1.5 privacy_mode visibility — identity-risk blueprint
  documents the class-2-only availability so operators understand
  why the blueprint fails on class-3 deployments.

Test config:
- cargo test --no-default-features → 72 passed
- cargo test                       → 210 passed (203 + 7)

Out of scope (next iter target):
- GitHub Actions workflow with mosquitto Docker so iters 24 + 29
  e2e tests actually run in CI with BFLD_MQTT_BROKER set.
- cog-ha-matter cargo crate-internal test that loads each blueprint
  via serde_yaml + validates against an HA blueprint schema (instead
  of the string-only checks here). Optional; current coverage is
  sufficient to catch drift in the YAML files themselves.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-05-24 18:17:41 -04:00

77 lines
2.7 KiB
YAML

blueprint:
name: BFLD Identity-Risk Anomaly Notification
description: >
Notify the operator when BFLD's identity-risk score deviates significantly
from its rolling 7-day baseline — a signal that the RF environment has
shifted toward a higher-leakage regime (new AP firmware, attacker-grade
sniffer in range, unusual propagation). Sourced from ADR-122 §2.6 and
ADR-121 §2.4.
domain: automation
source_url: https://github.com/ruvnet/RuView/blob/main/v2/crates/cog-ha-matter/blueprints/bfld/identity-risk-anomaly.yaml
input:
bfld_identity_risk:
name: BFLD Identity Risk sensor
description: The `sensor.<node>_bfld_identity_risk` entity (only present at privacy_class = Anonymous).
selector:
entity:
domain: sensor
integration: mqtt
notify_target:
name: Notify target service
description: HA notify service to call (e.g., notify.mobile_app_<phone>).
selector:
text: {}
spike_threshold:
name: Absolute spike threshold
description: Trigger immediately when raw score >= this value.
default: 0.8
selector:
number:
min: 0.5
max: 0.99
step: 0.01
z_score_threshold:
name: Rolling z-score threshold
description: Trigger when deviation from 7-day mean exceeds this many sigmas.
default: 3.0
selector:
number:
min: 1.5
max: 6.0
step: 0.5
statistics_entity:
name: Statistics helper entity for the 7-day baseline
description: >
An HA `statistics` integration entity computing mean + standard
deviation of the BFLD identity-risk sensor over a 7-day window.
Configure via Settings → Devices & Services → Helpers → Statistics.
selector:
entity:
domain: sensor
trigger:
- platform: numeric_state
entity_id: !input bfld_identity_risk
above: !input spike_threshold
id: absolute_spike
- platform: template
value_template: >
{% set raw = states(trigger.entity_id) | float(0) %}
{% set mean = state_attr(!input statistics_entity, 'mean') | float(0) %}
{% set sigma = state_attr(!input statistics_entity, 'standard_deviation') | float(0.01) %}
{{ (raw - mean) / sigma >= z_score_threshold }}
id: z_score_spike
variables:
z_score_threshold: !input z_score_threshold
action:
- service: !input notify_target
data:
title: BFLD Identity-Risk Anomaly
message: >
Node {{ trigger.entity_id }} identity-risk score is {{ states(trigger.entity_id) }}.
Investigate possible RF-environment shift (new AP firmware, nearby sniffer,
unusual multipath). See ADR-118 / ADR-121 for context.
mode: single