Update every device over the air with Fleet

Change the interval, the sleep mode or the firmware of one board or forty without a USB cable. Jobs, templates, verify modes and rollback explained.

HydroNode 8 min read
The HydroNode Fleet page listing devices with firmware, config revision and live stateThe HydroNode Fleet page listing devices with firmware, config revision and live state

Three sensors in the greenhouse, two on the balcony, one in the cellar. And now every one of them should send every 5 minutes instead of 10. That used to mean fetching the cable six times. With Fleet it is one dialog, and each board checks after the update that it still measures correctly.

What updates over the air

HydroNode firmware 0.5.0 or laterFlashed once with the Device Builder. That is the last USB flash the board needs.
Firmware: the ESP32 familyESP32, S2, S3, C3 and C6 take new firmware and new config.
Config: everythingThe ESP8266 takes new settings but no new firmware. It has no room for a second copy.
Owner or adminFleet lists your sensors and every sensor shared with you at admin level.

Config is everything the builder asked you: which sensors sit on which pins, how often the board sends and how it sleeps. WiFi and the secret are never part of it; the board keeps the ones it has.

The overview

FleetDevices starts with six tiles: all sensors, healthy, delayed, offline, update available and jobs running. Click a tile to filter the list. Each row shows what the device is doing right now, its firmware and config, its last and next contact, and its error rate over seven days.

In the columnMeans
→ 0.7.0New firmware is available and the board can take it over the air.
config onlyAn ESP8266, config over the air only.
needs USB onceFirmware older than 0.5.0. Reflash once, everything after that goes over the air.
r14The config revision. Counts up with every change.
driftedCame from a template but was changed on its own since.

Change one device

  1. Open the deviceClick its row. The details open on the right with the state, the last round and error rates.
  2. FirmwareUpdate to 0.7.0 installs the newest signed firmware.
  3. ConfigChange config opens the Device Builder with the saved setup. The board stays fixed; you change wiring, sleep mode or timing, and the last step sends it all over the air.
Device details in Fleet with state, update button and key figuresDevice details in Fleet with state, update button and key figures
The details: state, the five steps of a job, firmware, config and verify mode.

Many devices at once

Bulk change at the top right, or tick devices in the list and press Bulk change… in the bar at the bottom. One device or forty, the same rules apply, and nothing goes out before you press Create jobs.

  1. ChangeFirmware, send interval, an extra value (such as the WiFi signal) or the power mode, plus the verify mode for this change.
  2. Pick devicesWhich boards get the change.
  3. CheckHydroNode runs every rule for every device. Yellow marks a device that starts from a different value than most.
The bulk change dialog with firmware, interval, value and power modeThe bulk change dialog with firmware, interval, value and power mode
Firmware and config in one pass. Nothing is sent until you confirm it.
Battery below 30 % A firmware download is the most power hungry thing a board does. With a weak battery you confirm twice. If the battery dies mid update, the old firmware starts again.

How a job runs

Every device in a change gets its own job. The board starts each step itself when it checks in; HydroNode never reaches into your network. A sleeping device therefore picks up its update with its next round.

  1. QueuedWaits for check-in
  2. OfferedWith the next answer
  3. DownloadSigned image
  4. VerifyStrict or Lenient
  5. InstalledOr rolled back
You can cancel while a job is Queued or Offered. After that it runs to its end.

After the restart the board does not sleep but checks itself: up to three tries 15 seconds apart, two minutes at most. Until it passes, the old firmware and old config stay on the board. If it fails, it goes back on its own and reports why, for example sensor_read_failed:bme280.

Verify modeGood afterUse it for
StrictAn accepted signed reading and every configured sensor readAlmost everything. A sensor that stops answering after an update is caught.
LenientThe first accepted signed readingA device with a sensor that is already broken and would fail Strict every time.

Templates for identical boards

A template is a saved setup without a sensor and without WiFi: board, wiring, power and timing. Flash every identical board from it and change all of them later in one go. When you save a new version, Fleet shows which linked devices still run the old one, and Apply to linked devices… brings them up to date after the usual check.

Templates in Fleet with versions and linked devicesTemplates in Fleet with versions and linked devices
Up to 50 templates, each versioned. Devices changed on their own carry drifted.

The history

FleetJob history lists every change of the last 30 days with a number: J-0140 for one device, B-0142 for a bulk change. Filters for firmware, config and problems help you find things. Whoever started a change gets a push when all devices are done, and one right away on a rollback.

Job history in Fleet with changes, outcomes and devicesJob history in Fleet with changes, outcomes and devices
Running changes update live, and the newest opens by itself.

Security

  • Every firmware image is signed with ECDSA P-256. The board checks the signature before it installs anything.
  • The WiFi password and the secret are never part of an update.
  • HydroNode never connects to your device. The device asks, HydroNode answers.

Read more