Settings
A few things about HOFI are set in one file on the stick, hofi-settings.yaml, in the hofi_drive partition. HOFI creates it on its first start, with every option commented out, and never overwrites your copy afterwards.
Change a setting
- Open
hofi-settings.yaml. Plug the stick into your computer, or open thehofi_drivenetwork share while HOFI runs (see Copy over the network). - Edit it in any text editor. Every option is optional: remove a line, or the whole file, to get the default back.
- Apply it. Either restart HOFI, or press Q on the HOFI screen. The screen comes back after a few seconds with the new settings.
If the file has a mistake, HOFI ignores the whole file, runs with the defaults and shows a red line about it in its log. An option it doesn't know is skipped, and the rest of the file still applies.
Example
version: 1
language: pl
flasher:
hide:
- eeprom
- download
access:
port22: key
Options
| Option | Values | Default | What it does |
|---|---|---|---|
version | 1 | 1 | Format of the file. Leave it at 1. |
language | en, pl | en | Language of the HOFI screen: buttons, lists, the Wi-Fi screen and the image catalogue. Log messages and the hotkey letters stay in English. |
flasher.hide | list of eeprom, extract, download | nothing hidden | Hides actions that a station doesn't need (see below). |
access.port22 | open, key | open | key locks HOFI to your SSH keys (see below). |
access.web | open, off | off with port22: key, otherwise open | Whether the HOFI screen opens in a browser. |
access.samba | open, protected | protected with port22: key, otherwise open | Whether the network share shows hofi-settings.yaml and the ssh folder. |
Hide flasher actions
| Value | Hides |
|---|---|
eeprom | The Config EEPROM button (Raspberry Pi only) |
extract | The Extract button for .img.xz and .img.zst images |
download | Download from Internet in the image list, and the Wi-Fi screen (W) with it |
Flash, Abort and Power Off are always there.
Lock HOFI to your SSH keys 🔒
By default, anyone who can reach HOFI over the network can use its screen and its network share. With access.port22: key, only people with an SSH key you listed on the stick can open the HOFI screen over the network.
-
Add your public key. In
hofi_drive, create a folder namedsshwith a file namedauthorized_keysinside it. Put one OpenSSH public key per line, for example the contents of~/.ssh/id_ed25519.pub. -
Turn the lock on in
hofi-settings.yaml:access:port22: key -
Apply it by pressing Q or restarting HOFI. You can add the key and turn the lock on in the same edit.
Then open HOFI with your key:
ssh -i ~/.ssh/id_ed25519 root@hofi-rpi.local # or hofi-x64.local / hofi-jetson.local
While HOFI is locked:
- The browser screen is off, so the laptop and phone browser tabs no longer work. Set
access.web: opento keep it, but then anyone who can reach it can use it again. - The network share hides
hofi-settings.yamland thesshfolder, so nobody on the network can undo the lock. Copying OS images over the share still works. Setaccess.samba: opento show them again, but then anyone on the network can remove the lock. - A monitor and keyboard on the robot always work, whatever the settings.
With no usable key in ssh/authorized_keys, nobody can open HOFI over the network, and HOFI says so in its log. To fix it, plug the stick into your computer and either add a key or change port22 back to open.
A file with a mistake never locks HOFI: while HOFI ignores the file, access stays open.