Working Docker Compose for OpenThread Border Router on Raspberry Pi 5 (Bookworm) with ZBT-2 using openthread/border-router:latest #13290
sldunn
started this conversation in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
This is a known-working configuration for running OpenThread Border Router as a Docker container on Raspberry Pi OS (Bookworm) alongside Home Assistant Container. It successfully resolves common issues with port binding, nftables compatibility, and environment variable handling.
Hardware / Environment
Raspberry Pi 5 (8GB)
Raspberry Pi OS Bookworm (64-bit)
Home Assistant Connect ZBT-2 (Thread RCP mode)
Second ZBT-2 (Zigbee mode)
Home Assistant running as Docker container
Using network_mode: host
Challenges Addressed
openthread/otbr:latest image frequently ignored port and listen address environment variables.
Services binding only to 127.0.0.1 instead of 0.0.0.0.
Conflict with Nginx Proxy Manager on ports 8080/8081.
nftables vs iptables changes in newer Raspberry Pi OS.
Working docker-compose.yml
YAMLversion: "3.8"
services:
otbr:
image: openthread/border-router:latest
container_name: otbr
restart: unless-stopped
network_mode: host
privileged: true
cap_add:
- NET_ADMIN
- SYS_ADMIN
environment:
- INFRA_IF_NAME=eth0
- NAT64=0
- DNS64=0
- FIREWALL=0
- OT_WEB_LISTEN_ADDR=0.0.0.0
- OT_WEB_LISTEN_PORT=8082
- OT_REST_LISTEN_ADDR=0.0.0.0
- OT_REST_LISTEN_PORT=8083
- OT_INFRA_IF=eth0
- OT_THREAD_IF=wpan0
- OT_LOG_LEVEL=7
- OT_RCP_DEVICE=spinel+hdlc+uart:///dev/ttyACM1?uart-baudrate=460800
devices:
- /dev/ttyACM1:/dev/ttyACM1
- /dev/net/tun:/dev/net/tun
volumes:
- /sys/fs/cgroup:/sys/fs/cgroup:ro
- otbr_data:/data
matter-server:
image: ghcr.io/home-assistant-libs/python-matter-server:stable
container_name: matter-server
restart: unless-stopped
network_mode: host
security_opt:
- apparmor=unconfined
volumes:
- matter_data:/data
command:
- --storage-path
- /data
- --paa-root-cert-dir
- /data/credentials
- --bluetooth-adapter
- "0"
- --log-level
- info
volumes:
otbr_data:
matter_data:
Key Configuration Notes
Uses openthread/border-router:latest (more reliable than openthread/otbr:latest regarding environment variables).
Explicitly sets both listen address and port variables.
Disabled built-in firewall/NAT64 (NAT64=0, FIREWALL=0) due to nftables on Bookworm.
Volume mount changed to /data (matches current image expectations).
Ports shifted to 8082 / 8083 to avoid conflict with Nginx Proxy Manager.
All reactions