What updates over the air

HydroNode firmware 0.5.0 or later
Flashed with the device builder. This is the last USB flash the board needs. Older firmware asks for it once.
An ESP32 for new firmware
ESP32, S2, S3, C3 and C6 take new firmware and new config. The ESP8266 takes config only, because it has no room for a second copy of the firmware.
A saved setup for config
Config changes start from the setup the device builder saved on the sensor. A sensor flashed before setups existed needs one reflash first.
Owner or Admin share
Fleet lists every sensor you own and every sensor shared with you at Admin level. Both may start changes. Read and Write shares do not appear.
DeviceFirmware over the airConfig over the air
HydroNode firmware 0.5.0 or later on ESP32, S2, S3, C3 or C6Yes, signed images onlyYes
HydroNode firmware 0.5.0 or later on ESP8266No, new firmware needs USBYes
HydroNode firmware before 0.5.0No, reflash once via USBNo, reflash once via USB
Your own sketch with the HydroNode libraryNoNo
ESPHome with the HydroNode componentThrough ESPHomeThrough ESPHome
LoRaWAN sensorNoNo
Firmware is the program on the board. Config is everything the device builder asked you: which sensors sit on which pins, how often the board sends, how it sleeps and which values go out. WiFi and the sensor secret are never part of a config change. The board keeps the ones it has.

Four sections, one header

SectionWhat it is for
DevicesEvery device with its live state, firmware, config, contact, battery and error rate. Select devices here to change them.
TemplatesSaved setups for many boards of the same kind, with versions and the devices linked to each one.
Device builderThe wizard that flashes a board over USB, creates templates and flashes boards from a template.
Job historyEvery change of the last 30 days, with the outcome per device.

The header shows a green Live dot while HydroNode pushes every change to the page as it happens. Without that connection the page says Updates every 15 s and checks on its own while the browser tab is in front. Next to the tabs stands the latest firmware HydroNode can install, for example Latest firmware 0.5.1. If it reads Firmware 0.5.1 is not signed, no device is offered new firmware until a signed release is out. The buttons Device builder and Bulk change are always one click away.

Find a device and see its state

Six tiles sit above the list. Click one to show only those devices, click it again or click Sensors to show all. The active filter also appears as a chip next to the search, where its × removes it.

TileCounts
SensorsEvery device in your fleet. Click it to remove the filter.
HealthyDevices that report on time.
DelayedDevices whose readings arrive late.
OfflineDevices that stopped reporting.
Update availableDevices that can take a newer firmware over the air right now.
Jobs runningDevices with an open job, from Queued to Verifying.

The search looks at the name, the chip family, the firmware version and the template name. Type custom to find devices without a template. Group sorts the list by template (the default), by chip family, by status, or not at all. Every group has a Select group button. Columns turns the optional columns on and off and has Compact rows for long lists. The browser remembers your choice.

ColumnShows
DeviceHealth dot, name, chip family and template, or Custom setup.
Live stateWhat the device is doing right now. See the next section.
FirmwareThe version the board reports, with a hint below it.
ConfigConfig revision, plus drifted when the device left its template. Optional.
ContactLast contact (94 s ago, just now) and the next expected one (next in ~5 min, overdue). Optional.
BatteryBattery level from the battery channel, amber below 30 %. USB without a battery channel. Optional.
Errors 7dShare of refused readings and missed rounds over seven days, with a small trend line. Amber from 3 %. Optional.

Tick devices to select them. A bar appears at the bottom with Update firmware, which goes straight to the check for the latest firmware, and Bulk change… for everything else. The checkbox in the header selects every device the filter shows. On a phone each device is a card with the same facts, and the list never scrolls sideways.

The gear next to Columns opens Fleet settings with your Default verify mode. It appears once you own at least one sensor.

What each device is doing right now

The Live state column combines the open job, the monitoring status and what the board last reported. States that are happening right now pulse. A download shows a progress bar.

StateMeaning
Running stableHealthy, no open job. Right after an update it adds "Updated to 0.5.1 just now".
Sending readingA reading arrived within the last three seconds.
AsleepHealthy, in deep sleep or hibernate between rounds. Shows when it wakes.
QueuedA job waits for the next check-in of an awake device.
OfferedThe update went out with the reply to the last reading.
Waiting for check-inA job waits for a sleeping or silent device. It starts on the next contact.
Downloading updateThe board loads the new firmware. Shows the percentage and the size.
RestartingThe board boots into the new firmware.
Verifying firmwareThe new firmware checks itself, for example "Strict · try 1 of 3 · max 2 min".
Applying configThe board writes the new config. The old one stays as a backup.
Verifying configThe new config checks itself, the same way as new firmware.
Rolled backThe last update failed its check within the last 24 hours. The board runs its old version again. The reason is shown.
DelayedReadings arrive late. Shows how many rounds were missed.
OfflineNo contact for a long time. Check power or network.
No data yetThe device has never sent a reading.

The Jobs running tile counts Queued, Offered, Waiting for check-in, Downloading, Restarting, Applying and both Verifying states. Healthy, Delayed and Offline follow the same rule as Sensor Monitoring.

What the board runs and what it can take

The version comes from the board itself. It reports it with every reading, together with its config revision (r14), restarts, WiFi signal and sensors that failed to read. The hint below the version says what the device can take.

HintMeaning
→ 0.5.1A newer firmware is ready for this board. Update it from the selection bar, the details or Bulk change.
latestThe board runs the latest firmware.
config onlyESP8266: config changes go over the air, new firmware needs USB.
needs USB onceHydroNode firmware that cannot update itself yet. Reflash it once with the device builder.
own sketchYour own code with the HydroNode library. Listed with health and errors, not updated by HydroNode.
ESPHomeBuilt with ESPHome. ESPHome installs its own updates.
not reportedThe board has not sent its version. Firmware before 0.5.0 and older libraries do not report it.
LoRaWANA LoRaWAN device. It takes no updates over the air.

The Config column shows the config revision. It counts up with every flash and every config change, so r15 after r14 means the board took the new settings. The chip drifted marks a device that came from a template but was changed on its own since.

One device, everything about it

Click a row to open its details on the right. The address bar gets ?device=…, so you can bookmark or share the view. Esc, the close button, a click next to the panel or the back button closes it.

  1. 1
    State
    The live state in large type with time since the last contact, a sentence that explains it and the five job steps from Queued to Installed.
  2. 2
    Problems
    What the device reported going wrong, in plain words: a power drop or crash that restarted it, WiFi that rejected the password or was not found, a sensor that does not answer (with the pins of its saved setup to check), and a round that keeps it awake far longer than its setup needs. Firmware 0.6.0 and later also report how long the last round was awake.
  3. 3
    Actions
    Update to the latest firmware, Change config or Reflash via USB. The first button reads Up to date, Needs USB reflash, Config only or Job running when an update is not possible, and its tooltip says why. Change config opens the device builder for this device; the arrow next to it offers Bulk change instead. When the device takes no config, the reason stands under the buttons.
  4. 4
    Facts
    Firmware, config revision, last and next contact, battery, signal (dBm, Ethernet, or RSSI and SNR for LoRaWAN), verify mode and template. Click Verify mode to choose Account default, Strict or Lenient for this device.
  5. 5
    Error rate
    Refused readings, missed rounds, refused commands, failed or rolled back updates and restarts, each for 24 hours and 7 days with a trend line.
  6. 6
    Device setup
    What the device builder put on the board: sensors with bus, pins and values, outputs, and how it reports. Marked "differs from template" when it drifted.
  7. 7
    Jobs
    The last ten jobs with who started them, the verify mode, the result and the reason.
  8. 8
    Console
    The last twelve lines of the Device Console, live. Open console jumps to the full console on the sensor page.

Change many devices in one pass

Bulk change in the header, in the selection bar or under the arrow next to Change config in the details of one device opens the same dialog. One device or forty, the same rules apply. Nothing is sent to a board before you press Create jobs.

Bulk change covers the basics: firmware, interval, the WiFi signal and the power mode. To change everything on one device, its sensors, pins, options and how often each value is sent, press Change config in its details. The device builder opens with the saved setup, the board stays fixed, and the last step sends the new setup over the air. A board on firmware 0.5.0 or later takes new sensors, other pins or another sleep mode this way without a firmware update. A sensor that needs a newer firmware says so in the builder, and the update goes first in the same job.

  1. 1
    Change
    Tick what changes and pick the new value. Choose the verify mode. Firmware and config combine into one pass.
  2. 2
    Devices
    Tick the devices, or use Quick pick: All from a template, All with update available, or Clear. From 20 devices on, a filter field helps.
  3. 3
    Check & review
    HydroNode checks every device and shows what changes where. Create jobs starts the change for every device that can take it; the others are skipped.
ChangeWhat it does
FirmwareInstalls a signed release. ESP32 family only. The latest is preselected; withdrawn releases are not offered.
Send intervalHow often the board reports: 1, 2, 5, 10, 15, 30 or 60 minutes.
Add valueSends the WiFi signal (RSSI in dBm) with every reading. WiFi boards only.
Power modeAlways on, Modem sleep, Light sleep, Deep sleep or Hibernate, as far as the chip supports it. A mode none of the picked devices can run is greyed out with the reason, for example SGP30 needs always-on.

Reading the check

The check runs every rule for every device before anything is created. The box Same for every device shows the change most devices get, for example Send interval 10 min → 5 min. Below it, one row per device and one cell per change. A cell is yellow when a device starts from a different value than most, for example differs from the usual 10 min.

ResultMeaning
OKThe device takes the change as shown.
WarningThe device takes the change, but read the reason first. Skipped parts, low battery and a silent device land here.
Not possibleNothing is sent to this device. The reason stands in the row, which is dimmed.
The check saysWhy
Needs one USB reflash to 0.5.0The firmware on the board cannot update itself yet.
ESP8266 takes config onlyFirmware is skipped on an ESP8266. Config parts still go.
Not HydroNode firmwareOwn sketches and ESPHome are not updated by HydroNode.
No saved setup, reflash once with the builderConfig changes start from the saved setup.
EC probe needs always-onA sensor that samples all the time cannot sleep deep. The name comes from your setup.
Outputs need the board awakeRelays and LEDs cannot keep their state in deep sleep.
Deep sleep needs at least 30 sEach power mode has a shortest interval.
A job is still runningOne open job per device. Wait for it or cancel it.
Not reporting, the job waits for its next contactThe device is delayed or offline. The job starts when it is back.
Already reports sensor read errors, Strict may roll backA sensor failed in the last 24 hours. Fix it, or use Lenient for this change.
Changed by hand since the template, your edits are replacedA template apply overwrites the drifted setup.
The configuration is too large for the device.The new config does not fit into the 8 KB config area of the board.
The board cannot change over the airChange config keeps the board. For another board, flash it with the device builder.
SGP40 needs firmware 0.5.2 or newerThe sensor came with a later firmware. Update the firmware in the same change, or over USB on an ESP8266.
Below 30 % battery you confirm twice. A firmware download is the most power hungry thing a board does. The first click on Create jobs names the weak devices and turns the button amber. The second click creates the jobs. If the battery dies during the update, the old firmware starts again, but the board may stay quiet until it is charged.

From Queued to Installed

Every device in a change gets one job. The details panel draws it as five steps: Queued, Offered, Download, Verify, Installed. The board always starts the step itself, when it checks in. HydroNode never reaches into your network.

  1. 1
    Queued
    The job exists and waits for the board to check in. A sleeping board shows Waiting for check-in with the time of its next round.
  2. 2
    Offered
    The reply to the next reading carries the update. The board finishes its round first, so no reading is lost.
  3. 3
    Download
    The board checks the signature, then loads the firmware into its free slot and verifies its checksum. An interrupted download resumes where it stopped.
  4. 4
    Verify
    The board restarts into the new firmware and checks itself in its first wake cycle (section 09).
  5. 5
    Installed
    The check passed. The details show for example "Verified Strict in 41 s", and the saved setup follows the new version.

A config change takes the same path without a download: the board receives the new settings with the reply, keeps its old config, writes the new one, restarts and checks. A change with firmware and config runs the firmware first and the config right after, as one job.

WhenWhat happens
The board is asleepThe job waits for its next round. Nothing wakes a sleeping board early.
Offered three times, not takenThe job fails with "Offered 3 times, not taken". Check the console for refused offers.
The download stalls for 10 minutesThe job goes back to Offered, and the next reply offers it again.
HydroNode was unreachable during the checkThe board rolls back, the job is queued again and tried in a later round, up to five times.
No report after the restartAfter three intervals plus five minutes without a word, the job fails with "No report after restart".
The device changes owner or a share endsJobs the board has not taken yet end when the person who started them no longer manages the device.

Cancel a job

While a job is Queued, Offered or Waiting for check-in, a Cancel button stands next to its state. Cancelling keeps the board exactly as it is: nothing was downloaded yet. Once the download or the config change started, the job runs to its end, and a failed check rolls it back on its own.

New firmware has to prove itself

After a restart into new firmware or a new config, the board does not sleep. It checks itself in its first wake cycle: up to three tries, 15 seconds apart, at most two minutes. Until it passes, the old firmware and the old config stay on the board. If it fails, or if the board restarts before the verdict, it goes back to what it ran before and reports why. You change nothing for that.

Verify modeThe update counts as good afterUse it for
Strict (default)A signed reading accepted by HydroNode, and every configured sensor read.Almost everything. A sensor that stops answering after an update is caught.
LenientThe first signed reading accepted by HydroNode.A device with a sensor that is already broken and would fail Strict every time.

Set the mode on three levels. Fleet settings (the gear on the Devices tab) holds your account default. Verify mode in the details of a device overrides it for that device, or follows the account default again. The bulk change dialog sets it for one change. The details show where the mode comes from, for example Strict (account) or Lenient (override).

A rolled back device shows Rolled back for 24 hours with the reason in code style. The details spell it out, for example: "The last update to 0.5.1 booted, but the BME280 did not answer in three tries. The device went back to 0.5.0 by itself and is running fine." Relays and LEDs keep their last state over every restart.

ReasonMeaning
sensor_read_failed:bme280Strict only: this sensor did not answer in three tries.
ingest_failed:401HydroNode refused the readings of the new version, here with this HTTP status.
server_unreachableWiFi worked, HydroNode did not answer. The job is tried again later.
wifi_failedThe board did not get onto WiFi with the new version or config.
timeoutThe check did not finish within two minutes.
config_invalidThe board could not read the new config and kept the old one.
boot_failedThe board restarted before the verdict, for example after a crash.

One setup for many boards

A template is a saved device builder setup without a sensor and without WiFi: board, wiring, power and timing. Flash every board of the same kind from it, and change all of them later in one pass. Create one with + Create template on the Templates tab, with Save as template on the last step of the device builder, or from a sensor's Device setup settings. You can keep up to 50 templates. Each name is used once.

You seeMeaning
v4The current version. Every saved config change adds a version with a summary, for example "Send interval 10 → 5 min · + WiFi signal".
currentA linked device runs the current version.
behindA linked device runs an older version. The card shows for example "2 behind v4".
driftedA linked device was changed on its own since it took the template.
Check setupThe template no longer fits today's device builder, for example a sensor that is no longer offered. Open it and check the marked steps before you flash.

Change a template and its devices

  1. 1
    Edit
    Opens the template in the device builder: board, wiring, power, timing. Save changes stores the next version. Save as new template keeps the old one as it is.
  2. 2
    Decide on the linked devices
    Back on the Templates tab, a banner asks whether the linked devices should take the change too. Not now keeps them as they are; the new version then only counts for future flashes.
  3. 3
    Apply to linked devices…
    Opens the bulk change dialog on its check. Devices that are behind are preselected, drifted ones are marked, because their own edits get replaced. Firmware can go along in the same pass.
  4. 4
    Flash from template
    Puts the template on a new board in four steps: template, sensor, WiFi, flash. The sensor can be created on the spot.

Rename changes only the name. The bin icon deletes the template after a confirmation. Linked devices keep running exactly as they are and only lose the link.

Every change of the last 30 days

Each change has a number: J-0140 for a change to one device, B-0142 for a bulk change or a template apply. Filter by All, Firmware, Config or Problems. A row shows when, what, who started it (Owner or Admin share), a bar with the outcome of every device and the result, for example All installed, Running · 2 of 3 done or 2 of 3 installed.

Click a row to see every device with its change (0.5.0 → 0.5.1, r13 → r14), status and reason, for example Verified Strict in 41 s or Offered 3 times, not taken. The newest change opens by itself, and running changes update live.

Told when an update is done

Whoever started a change gets one push on iPhone and Android when all its devices are done: Update finished, for example "3 of 3 devices installed firmware 0.5.1.", or Update failed when none made it. A rollback is reported at once, for example "Tank A rolled back". Tapping it opens the sensor, or the sensor list for a change with several devices. On Android the messages have their own channel, Device updates, which you can mute in the system settings. The apps need a current version; older ones never receive these messages.

Signed, checked and never with your WiFi

Signed firmware
Every firmware image is signed with a key that stays offline on a hardware security key. HydroNode checks the signature before it offers an image, and the board checks it again before it installs anything.
Config without secrets
Config changes travel over TLS, signed like commands. They never contain the WiFi password or the sensor secret. The board keeps its own.
Always a way back
The old firmware and the old config stay on the board until the new one passed its check. The bootloader and the partition table never change over the air.
Limits
Up to 30 changes per hour per account and 200 devices per change. HydroNode sends only a few firmware downloads at the same time; the others start a round later.

When an update does not arrive

You seeWhat to do
Waiting for check-in does not endThe board sleeps or is offline. The job starts with its next reading. Check power and WiFi if it stays offline.
needs USB onceReflash the board once in the device builder. From then on, it updates over the air.
Change config is greyed outThe reason stands under the buttons. Usually the sensor has no saved setup or its firmware is older than 0.5.0: reflash it once with the device builder.
Rolled back with sensor_read_failedCheck the wiring of that sensor. If it is broken on purpose, set the device to Lenient and update again.
Offered 3 times, not takenOpen the console. A refused offer names its reason, for example a wrong family or too little space.
Firmware 0.5.1 is not signedThe release is not signed yet. No board is offered new firmware until it is. Config changes still work.
A device is missingFleet shows sensors you own or administer. Read and Write shares do not appear.

Each step of an update also appears in the Device Console as an OTA line, for example ota download 62% or ota installed 0.5.1 in 41 s.