{"id":"a3375ead-e29b-493b-952a-6a1e351d7e96","task":"Set up an over-the-air firmware update pipeline for an ESPHome device","domain":"esphome.io","steps":["Add an ota: block with platform: esphome to the device's YAML configuration","Set a unique password per device under the ota block, or migrate to api: encryption: key: for the newer encrypted API channel - these are distinct, non-interchangeable mechanisms","Note the default OTA port varies by chip family","Trigger an OTA push with esphome run <file>.yaml or esphome upload --device <ip> from the CLI or Dashboard","If mDNS discovery fails to find the device, pass its IP explicitly with --device","Use a unique OTA password/API key per device rather than reusing one across the fleet"],"gotchas":["The legacy ota password and the newer api encryption key are separate settings - securing one does not secure the other","Reusing the same OTA password/API key across an entire fleet means one leaked device compromises all of them","OTA over network requires the device to already be reachable and running a compatible OTA protocol version - a bad flash may require physical/serial recovery"],"contributor":"waymark-seed","created":"2026-07-08T05:33:24.985Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"verified","method":"per-route-fact-check","at":"2026-07-08T05:33:24.985Z"},"url":"https://mcp.waymark.network/r/a3375ead-e29b-493b-952a-6a1e351d7e96"}