Solution
Reference solution
A working solution consists of five files shipped under downloads/, applied against a live Home Assistant instance that can invoke the pico runtime Python CLI:
configuration.yaml— the four Home Assistant top-level keys (command_line,shell_command,input_button,automation) that add one observation surface and one safe control action.hello-pico-ha-phase.sh— thecommand_linesensor helper. Delegates topico runtime inspectand prints only the Pico engine Pod phase.event.json— the one event payload theshell_commandsends viapico runtime emit. Byte-identical to the underlying Manifold lab’sevent.json.README.md— operator note that lists the three requirements the Home Assistant container must satisfy:picoonPATH, a workingkubeconfig, and the helper installed at the expected path.verify.sh— the automatable shape check the walkthrough runs in Step 5.
Commands (recap)
From your local clone, before touching Home Assistant:
cd labs/hello-pico-home-assistant/downloads
bash verify.shThen, after merging configuration.yaml into Home Assistant and installing the helper (walkthrough Steps 1–2), from a shell that sees the same declared runtime truth Home Assistant will see:
pico runtime inspect --lab hello-pico-on-manifold --namespace manifold
pico runtime emit --lab hello-pico-on-manifold --channel hello --value 'Hello, Pico!'
pico runtime observe \
--lab hello-pico-on-manifold --pico pico-engine \
--expect 'pico[hello-world-pico] observation: Hello, Pico!'Expected output
verify.sh ends with:
verify: OK — Home Assistant integration path is layered over the approved runtime
The Home Assistant sensor sensor.hello_pico_engine_phase transitions from Running to Succeeded within one scan_interval after the button press. The pico runtime observe command prints:
pico runtime observe: OK — observed 'pico[hello-world-pico] observation: Hello, Pico!'
Why this satisfies the objectives
- Home Assistant is a ControlSurface, not the runtime: the
command_linesensor’scommand:points athello-pico-ha-phase.sh, which delegates topico runtime inspect. Theshell_command’s value ispico runtime emit …. Home Assistant never talks to Kubernetes, Manifold, or Wrangler directly. - One honest observation surface: the sensor state is exactly what the approved CLI reports (
Pending/Running/Succeeded/unknown) — no derived state, no cached shadow model, no HA-local translation of Kubernetes semantics. - One safe control action: the
input_buttonfires exactly one event on the same Wrangler-declared Channel the underlying lab proves is single-event / single-response. No multi-event flows, no cluster-wide operations, no destructive kubectl commands. - Layered over the approved Python CLI:
verify.shasserts that the shell_command argv is byte-equal to apico runtime emitinvocation and that no shipped file referenceskubectlorhelmdirectly. This is the machine-checkable guarantee that HA does not bypass the CLI. - Runtime substrate stays Kubernetes: nothing on the on-cluster side changes. The
manifoldNamespace,pico-enginePod,helloChannel Service, and topologyConfigMapare all still applied by the underlying Hello Pico on Manifold lab; this lab only observes and asserts against them.
Verification
You can verify the solution matches this reference by:
- Running
bash verify.shfromdownloads/and confirming the finalverify: OKline. - Confirming that the Home Assistant sensor state and the
pico runtime inspectoutput agree at all times (they must — HA reads through the CLI). - Confirming that pressing the HA button produces the exact same Observation the underlying Manifold lab’s
verify.shproduces (pico[hello-world-pico] observation: Hello, Pico!), because the argv the shell_command runs is byte-equal.
Variations
- Change the greeting: edit the
--valueinshell_command.hello_pico_send_greeting. The Pico engine will echo whatever value the button sends. The sensor state is unaffected — it reflects Pod phase, not payload. - Add a second observation: add a second
command_linesensor that delegates topico runtime inspectwith--lab hello-two-picos(once you have deployed that lab). Keep the sensor read-only and keep the delegation through the CLI intact. - Switch to another lab: change
--labin the sensor helper and the shell_command to another approved lab (currently onlyhello-pico-on-manifoldandhello-two-picosare known by the CLI). Do not add labs that the CLI does not already know.
Multi-Pico visualization, fleet dashboards, home-scoped smart-home integrations, HA integrations that call kubectl or the Kubernetes API directly, and non-Kubernetes runtime paths are all explicitly out of scope for this first graphical ControlSurface lab and its reference solution.