Lesson 23 / 25
IoT with the ESP32
Wi-Fi, HTTP, MQTT and keeping secrets out of git.
Connecting a device to the network
The ESP32 family adds Wi-Fi (and on many models Bluetooth) to an Arduino-compatible MCU running at 3.3 V. The Arduino core provides WiFi.h to join a network and HTTPClient for simple HTTP requests. For telemetry, MQTT is popular: devices publish small messages to topics on a broker, and other devices or dashboards subscribe; libraries such as PubSubClient implement it. Production devices should use TLS (for example WiFiClientSecure with a verified certificate), reconnect gracefully when Wi-Fi drops and never block the main loop forever waiting for the network. Never hard-code Wi-Fi passwords or API keys in code you publish: keep them in a separate header that is excluded from version control, and ship a template file instead. Library APIs change between core versions; check the docs.
Join Wi-Fi and make an HTTP GET
ESP32 Arduino core. secrets.h is listed in .gitignore; the URL is a placeholder.
#include <WiFi.h>
#include <HTTPClient.h>
#include "secrets.h" // defines WIFI_SSID, WIFI_PASS (NOT committed)
void setup() {
Serial.begin(115200);
WiFi.mode(WIFI_STA);
WiFi.begin(WIFI_SSID, WIFI_PASS);
unsigned long start = millis();
while (WiFi.status() != WL_CONNECTED && millis() - start < 15000) {
delay(250); // bounded wait, not forever
}
if (WiFi.status() != WL_CONNECTED) {
Serial.println("Wi-Fi failed; will retry later");
return;
}
Serial.println(WiFi.localIP());
HTTPClient http;
http.begin("http://example.com/api/status");
int code = http.GET();
if (code > 0) Serial.println(http.getString());
else Serial.printf("HTTP error %d\n", code);
http.end();
}
void loop() {}Keeping secrets out of the repository
Project layout and ignore rule.
MySensor/
MySensor.ino
secrets.h <- real credentials, never committed
secrets.example.h <- committed template with dummy values
.gitignore:
secrets.h
secrets.example.h:
#define WIFI_SSID "your-network"
#define WIFI_PASS "your-password"
If a secret was ever pushed: rotate it (change the password/key),
because removing it from the latest commit does not remove it from history.Plain HTTP and MQTT are readable
Without TLS, anyone on the network path can read and alter traffic. Use encrypted connections and per-device credentials for anything beyond a local experiment.
Quick check: Where should Wi-Fi credentials for a public project live?
- In a separate file excluded from version control, with a committed template
- Directly in the main sketch so others can test it
- In a comment at the top of the README
- In the device name broadcast over Wi-Fi
Answer
In a separate file excluded from version control, with a committed template — Credentials pushed to a public repository must be considered leaked.