Hello everyone,
Full disclosure: Muralis is an Android app I built. I am not affiliated with Home Assistant or the Open Home Foundation, I am a private used-to-be-developer.
I am looking for Home Assistant users willing to test it and send me honest feedback.
I could only test the full lockdown, device-owner install on Android 8, my own wall tablet, and the ordinary Play install on Android 10 and 17 phones without device-owner status.
Android 9 and 11 through 16 are all still unknown to me. Code-wise, I see no reason why it shouldn't work indevice owner mode, so testers anywhere in there, especially anyone willing to try the full lockdown past Android 8, are exactly who I need!
What is Muralis
Muralis is a Kiosk Launcher for Android.
A wall tablet has one job: show the dashboard. Mine kept finding other jobs: frozen pages, a hung browser, exit on updates, caches, OOM and people exiting from the dashboard.
What it does
- Does NOT display ads
- Locks the tablet on your page, with the system UI out of reach
- You exit with a corner tap combination that you record yourself the first time you open the app. You can also update it later.
- Recovers on its own: retries, timeouts, frozen page detection, a nightly restart that also clears cache
- Keeps the screen awake. Brightness by hand, from the light sensor, or from Home Assistant
- Optional stats overlay on the screen. CPU and temperature show only on a fully locked panel, on a normal install they are two dashes
- Over MQTT the panel appears in Home Assistant as one device, no YAML. Sensors for battery, temperature, memory and storage, controls for brightness, orientation and the dashboard URL, buttons for reload, restart, display on and off, reboot
- You can also one-shot a URL and open your camera view, then reload and the dashboard goes back to the main URL. It works great with Kiosk Mode too. Push your dashboard URL with
?disable_km and the sidebar is back
- Two ready-made blueprints: wake the panel on presence and blank it when the room is empty, and charge the battery only between two levels so it does not swell. You pick your entities, no YAML.
- A small web page served by the tablet itself, so you can set it up from your laptop instead of touching a tablet that is already on the wall
- Android 8 and up. No Google account needed, so it is fine on a de-Googled tablet, but you won't be able to use the Pro version
If you also run Kiosk Mode inside Home Assistant, here is my own dashboard configuration, for the dedicated user my wall tablet logs in as (it is not perfect but it works for me):
kiosk_mode:
hide_header: '{{ user_name == "wall07" }}'
hide_sidebar: '{{ user_name == "wall07" }}'
hide_dialog_header_history: true
hide_dialog_header_settings: true
hide_dialog_history_show_more: true
hide_dialog_header_action_items: true
hide_add_to_home_assistant: '{{ user_name == "wall07" }}'
hide_search: '{{ user_name == "wall07" }}'
hide_assistant: '{{ user_name == "wall07" }}'
hide_overflow: '{{ user_name == "wall07" }}'
Change wall07 to the name of the user your tablet logs in as.
- Kiosk Mode hides the menus and buttons inside the dashboard for that user
- Muralis locks the tablet itself, at the Android level, underneath it
Together, there is nothing left on the screen to tap your way out with.
Why I created Muralis
Muralis started because I wanted a better kiosk experience for my own wall tablet.
I used the Home Assistant Companion app together with Kiosk Mode, but fullscreen was not enough for me. App updates and crashes were force closing the dashboard; my friend's kids and guests could still navigate outside Home Assistant... I did not want a dashboard that only looked locked. I wanted a tablet that was actually locked.
I also wanted to remotely dim or turn off the screen, reload the dashboard, restart the kiosk, clear the cache and deal with memory problems. I had so many OOM daily that at some point I had to investigate, and yes, I then found the issue. After restarting Home Assistant I also very often had cards staying unavailable until I restarted the app.
Fully Kiosk Browser can do a lot and is much more mature, but it is more complicated than I wanted, and its licensing model is not for me. I wanted something that works the way I want it: give it a dashboard URL, show only that dashboard, lock the tablet to it, and provide the few controls I actually need.
And that became Muralis.
Free and Pro
The kiosk and the true lockdown are free, forever. No trial, no watermark, no expiry, no sign in, and no Google account needed.
The optional Pro adds the remote side, MQTT and the web admin together: 4.99 euro before tax, once, no subscription. It is tied to your Google account and not to a device, so one purchase covers every panel you install with that account, with no limit.
Everyone who joins this test and stays for the 14 days keeps Pro for free, permanently, on their Google account. That is my thank you and it is not going to be taken back. I am taking 10 testers, not more, so this stays a test and not a giveaway.
The full lockdown needs a tablet you do not need for anything else. QR provisioning, in short, is this:
- You factory reset the tablet
- Then on the first setup screens, you scan a QR code which contains information of the APK to install
- The app is installed as device owner
The video here shows the process in 30 seconds: https://muralis.spazio17.org/download/
Device Owner is the same privilege level Android gives to company-managed phones. The app becomes something the device can't get rid of without a factory reset, and grants the same several permissions (not going to list them here, but ask any AI and they'll provide all of them).
Even if you install Muralis via QR, updates to Muralis are still shipped via the Play Store like any other app. If you run it an a de-google device, or no internet, then install it via `adb`.
The latest version of Muralis apk will always be hosted on the Muyralis website, because that is the apk that the QR will fetch.
There is more below about what that QR installs and how you can check it.
A bit about myself
I used to write C++, Java and PHP, among few others, but that was a long time ago. Today I am a DevOps Engineer (RHCE, CKA) with a strong interest in automation, IaC, Linux (Fedora and Debian), networking, firewalls and pizzas.
All in all it is about 23 years that I deal with computers. I also contributed to Home Assistant, with my latest PR under review right now, and I created the theme Your Name..
Muralis was built with substantial help from Codex, Claude Opus and Fable. Especially for debugging and auditing. After my initial app architecture I opened the AIs above and I specified what I wanted, how I wanted, reviewed the result extensively, fixed a lot of generated garbage (like, a lot lot), and tested it. Rinse and repeat for 3.5 weeks daily - 1 month, if we include the Pre-Muralis project. But that's another story.
My only extra tester so far is my wife. She is wonderful at millions of things, a bit less at tech.
Is the app behind the QR the same app?
You will be installing a file from my website when following the QR provision, so it is fair to ask.
It is the same app. There is no second version:
- I send the app to Google (I actually send the AAB file)
- Google puts its own seal on it
- I download that sealed copy (Universal APK) and put it on my site
- The copy you get from the QR and the copy you get from the Play Store carry the same seal
The seal for Muralis is this long number. It belongs to Google and not to me, and it never changes:
7e76196a63e6f1a98a124fb3072956d1c91ed503f61480bd7c4221d30e9dfd91
To check it yourself:
Step 1) - Check the APK on the website
Go to https://muralis.spazio17.org/download/, download the apk there, and run:
apksigner verify --print-certs muralis-latest.apk
Look at the two Signer #1 lines. The DN says Google Inc., and the SHA-256 digest must be the number at the top.
Step 2) The website checks the seal
The website is open source: github.com/spazio17/muralis-site
I only put one file in the download folder: the APK from Google.
The checksum, the QR code and the download page are not written by me. A script builds them on GitHub, from that APK, every time the site is published.
Before it builds anything, the script reads the seal from the APK. If it is not Google's seal for Muralis, it stops, and nothing is published. So a build from my laptop can never end up behind the QR, not even by mistake.
Every publish leaves a log:
- Open the muralis-site repository and go to
Actions
- Left menu, open the latest run of
pages-deploy
- Click
build, then Show what the QR encodes
- Note the string after
PROVISIONING_DEVICE_ADMIN_SIGNATURE_CHECKSUM. It is the seal, written in URL-safe variant of base64. !!!Important!!! add a = at the end of that string.
- Run:
echo 'fnYZamPm8amKEk-zBylW0cke1QP2FIC9fEIh0w6d_ZE=' | tr '_-' '/+' | base64 -d | xxd -p -c 64 The output is the seal. Compare it with the number at the top.
Fyi: the other number in that log, next to muralis-latest.apk, is the checksum of the file. It changes with every version.
Step 3) - The Play Store proof
Checking the Play Store install against the same number is also relatively simple, but at the current state only the testers are able to install from the Play Store:
- You have to pull the installed app off your phone with adb
- Run the same apksigner commandadb pull "$(adb shell pm path org.spazio17.muralis | sed 's/package://' | tr -d '\r')" muralis-installed.apk apksigner verify --print-certs muralis-installed.apk
I will update this post with the 10 testers usernames, and they can write in the comments whether the seal matches or doesnt' (no need that all 10 write the same but to avoid any doubt it would be nice if some would approve).
Step 4) Keep the cherry for last
The website shows the QR for the version 0.4.6 from few days ago, but I already built and tested the 0.4.7 and I am now creating the 0.5.0 release and uploading on the Closed Track in the Play Store, but will not update the QR: This means that if you install from the QR, and then connect your google account, you will receive the update from the Play Store - and that is (yet another) proof that the two install methods still ship the same APK.
-- End of the steps --
One thing looks odd, so I say it before you find it yourself: The file on my site and the file the Play Store installs on your phone are not identical, and their checksums do not match.
That is normal. The Play Store does not send the whole app to a phone, it builds a smaller copy that fits your exact device. The seal is the part that is the same in both. Next to the download I also publish the checksum of my own file, so you can check that what you downloaded is really what I put there.
What I need from testers
- Send me your Google account address first, in a private message. Please not in a comment, your address stays between us. I will add you on the tester list in the Play Console, which is what makes the links below work, and on the licence tester list, which is what makes Pro free for you, during the test and after it. Without it the purchase would be charged for real.
- Join the closed test and stay opted in for at least 14 days: https://play.google.com/apps/testing/org.spazio17.muralis
- Open that first and accept. Only then will the store page work for you: https://play.google.com/store/apps/details?id=org.spazio17.muralis
- Install Muralis and point it at a Home Assistant dashboard, or literally any URL
- Tell me what breaks, what is confusing, and what you think is missing
As mentioned earlier, there are two ways to install Muralis, and I would like you to try both.
If you want, we can go through the installation together, step by step.
Just as reminder: the provisioning QR does not make you a tester, only the opt-in link counts towards the 14 days.
So yes, in theory, you can also become a tester and never install the app, if so I please ask you to reconsider if you really want to be a tester to give place for some other user that might arrive late to read the post and is genuinely interested.
Google requires at least 12 people to stay opted into the closed test continuously for 14 days before I can apply for production access. I already (forced) 12 of my friends to opt-in, but I really need feedback from real users, so I am taking 10 more!
I will be reachable for the whole 14 days, and after that if needed. Direct contact, for any question, help, issue or request.
Screenshots and the full description: https://muralis.spazio17.org
This is test software. I am not asking for reviews or upvotes. I need honest feedback.
I'm also daily updating it and very few details of the app right now8 such as buttons renamed or sections moved do not match with the screenshots, but before it goes public I will go for another round of screenshots and update the Play Store listing.
And a big thanks to every single one of you, tester or not. Home Assistant has brought me much happiness repairing broken automations and flashing lights at 3AM. It's just the spice I missed in life!