Edge appliance sn7d-jetnpd
sn7d-jetnpd is a Spot edge appliance (an NVR with on-box AI) at home, registered to a staging organisation in the product. It is the box under test for search-engine changes: seven simulated cameras from the build server, 22 agents created through the product, and a measurement script on the Mac. There are no real cameras and no customer data on it. Registered role: edge-nvr.
Access
Section titled “Access”ssh pi@sn7d-jetnpd-ssh.s2.spotai.co through the Spot SSH tunnel. The appliance accepts only Vault-signed certificates: the Mac’s shell wraps ssh so that any host matching *.spotai.co or sn<digit>* first gets a certificate signed at Vault (OIDC login when needed) into ~/.ssh/signed-cert.pub, valid 24 hours. On the LAN it is also 192.168.1.15 with the same certificate; the build server reached it that way with the Mac’s agent forwarded (ssh -A). pi has passwordless sudo. Nothing about the certificate or key is stored in this repository.
Baseline
Section titled “Baseline”Observed on 6 October: SpotOS IVR spotos-distro-1.0.6 (Yocto, kernel 5.15.119-intel), x86-64, 12 threads, 23 GB RAM, NVIDIA T1000 8 GB, read-only root with /data writable (215 GB, 71 GB used). Firmware 10.0.0 since the owner’s update from the product on 6 October: every container image is tagged 10.0.0. Interfaces: eno1 with 192.168.1.15 and two other addresses. Mender is installed and enabled; firmware and images come from the product, not from this repository.
What runs
Section titled “What runs”Twenty containers, all restart: always under Docker; nothing re-runs docker-compose at boot (the boot script, units and cron were read), so a container keeps its current image across a reboot. The ones the test bed touches:
| Component | Recorded facts |
|---|---|
| ingest (camera pipelines) | Status: observed Image: gcr.io/test-ai-243511/ingest12:10.0.0 Notes: One pipeline per camera in iot-config.json; pulls the seven simulator paths over RTSP |
| search-engine container | Status: observed Image: gcr.io/test-ai-243511/search-engine:10.0.0 Network: host; listens on 9801 Mounts: /config from /data/home/pi/config, /vault_secrets Compose: /home/pi/docker-compose/spot_ivr (root-owned; .env TAG=10.0.0) |
| TimescaleDB | Status: observed Container: spot-timescaledb Database: spotai Tables of interest: track_bboxes (detections), events_fire_log (agent actions), zones, video_paths Persistence: /data |
| Cloud link (tunnel and vault-agent) | Status: observed Containers: tunnel, vault-agent Notes: The product reaches the device-manager through the tunnel; vault-agent renews the appliance certificate. Both fail when the appliance certificate has expired. Identity path: /data/home/pi/vault_secrets |
The compose project is /home/pi/docker-compose/spot_ivr (root-owned; .env carries TAG=10.0.0). Logs are docker logs <container>; the search-engine’s log level is set in search-engine.json.
What the cloud owns
Section titled “What the cloud owns”/data/home/pi/config/iot-config.json (cameras) and ai-config.json (agents) are written by the product through the tunnel on every change; a hand edit lasts until the next rewrite. Camera streams are stored as raw addresses (192.168.1.12:554), and the appliance resolves no host names. Today the files hold cameras 12631-12637 (the seven simulator paths) and agents 1312-1333 (the test bed’s rules, each with two webhook actions to the receiver). Every hand edit is recorded with its revert in the appliance repository notes changelog.
Persistence and recovery
Section titled “Persistence and recovery”Durable: /data (database, configs, identity, logs), /home/pi/camera_simulator/videos (the original 24 GB library, unused on the box today). The three cameras that were on the box before 6 October were removed in the product. Recovery recipes: test bed runbook. The one repair exercised on this box is the identity reset after expired certificates (6 October), which needs the owner’s go.
Unknowns and verification
Section titled “Unknowns and verification”Read on 5 and 6 October. Not checked: how /home/pi relates to /data/home/pi; the transport between ingest and search-engine; whether the Docker login to the image registry is still fresh (spotcred --login-docker refreshes it). Firmware version on the box is read from the container tags, since the version files were empty.