पाठ 23 / 25

IoT with the ESP32

Wi-Fi, HTTP, MQTT and keeping secrets out of git.

Connecting a device to the network

The ESP32 family adds Wi-Fi (and on many models Bluetooth) to an Arduino-compatible MCU running at 3.3 V. The Arduino core provides WiFi.h to join a network and HTTPClient for simple HTTP requests. For telemetry, MQTT is popular: devices publish small messages to topics on a broker, and other devices or dashboards subscribe; libraries such as PubSubClient implement it. Production devices should use TLS (for example WiFiClientSecure with a verified certificate), reconnect gracefully when Wi-Fi drops and never block the main loop forever waiting for the network. Never hard-code Wi-Fi passwords or API keys in code you publish: keep them in a separate header that is excluded from version control, and ship a template file instead. Library APIs change between core versions; check the docs.

Join Wi-Fi and make an HTTP GET

ESP32 Arduino core. secrets.h is listed in .gitignore; the URL is a placeholder.

#include <WiFi.h>
#include <HTTPClient.h>
#include "secrets.h"   // defines WIFI_SSID, WIFI_PASS (NOT committed)

void setup() {
  Serial.begin(115200);
  WiFi.mode(WIFI_STA);
  WiFi.begin(WIFI_SSID, WIFI_PASS);
  unsigned long start = millis();
  while (WiFi.status() != WL_CONNECTED && millis() - start < 15000) {
    delay(250);                       // bounded wait, not forever
  }
  if (WiFi.status() != WL_CONNECTED) {
    Serial.println("Wi-Fi failed; will retry later");
    return;
  }
  Serial.println(WiFi.localIP());

  HTTPClient http;
  http.begin("http://example.com/api/status");
  int code = http.GET();
  if (code > 0) Serial.println(http.getString());
  else Serial.printf("HTTP error %d\n", code);
  http.end();
}

void loop() {}

Keeping secrets out of the repository

Project layout and ignore rule.

MySensor/
  MySensor.ino
  secrets.h            <- real credentials, never committed
  secrets.example.h    <- committed template with dummy values

.gitignore:
  secrets.h

secrets.example.h:
  #define WIFI_SSID "your-network"
  #define WIFI_PASS "your-password"

If a secret was ever pushed: rotate it (change the password/key),
because removing it from the latest commit does not remove it from history.

Plain HTTP and MQTT are readable

Without TLS, anyone on the network path can read and alter traffic. Use encrypted connections and per-device credentials for anything beyond a local experiment.

त्वरित जाँच: Where should Wi-Fi credentials for a public project live?

  • In a separate file excluded from version control, with a committed template
  • Directly in the main sketch so others can test it
  • In a comment at the top of the README
  • In the device name broadcast over Wi-Fi
Answer

In a separate file excluded from version control, with a committed template — Credentials pushed to a public repository must be considered leaked.