Skip to content

Edge appliance sn7d-jetnpd

referenceobservedEvidence reviewed 2026-10-06

sn7d-jetnpd is a Spot edge appliance (an NVR with on-box AI) at home, registered to a staging organisation in the product. It is the box under test for search-engine changes: seven simulated cameras from the build server, 22 agents created through the product, and a measurement script on the Mac. There are no real cameras and no customer data on it. Registered role: edge-nvr.

ssh pi@sn7d-jetnpd-ssh.s2.spotai.co through the Spot SSH tunnel. The appliance accepts only Vault-signed certificates: the Mac’s shell wraps ssh so that any host matching *.spotai.co or sn<digit>* first gets a certificate signed at Vault (OIDC login when needed) into ~/.ssh/signed-cert.pub, valid 24 hours. On the LAN it is also 192.168.1.15 with the same certificate; the build server reached it that way with the Mac’s agent forwarded (ssh -A). pi has passwordless sudo. Nothing about the certificate or key is stored in this repository.

Observed on 6 October: SpotOS IVR spotos-distro-1.0.6 (Yocto, kernel 5.15.119-intel), x86-64, 12 threads, 23 GB RAM, NVIDIA T1000 8 GB, read-only root with /data writable (215 GB, 71 GB used). Firmware 10.0.0 since the owner’s update from the product on 6 October: every container image is tagged 10.0.0. Interfaces: eno1 with 192.168.1.15 and two other addresses. Mender is installed and enabled; firmware and images come from the product, not from this repository.

Twenty containers, all restart: always under Docker; nothing re-runs docker-compose at boot (the boot script, units and cron were read), so a container keeps its current image across a reboot. The ones the test bed touches:

ComponentRecorded facts
ingest (camera pipelines)Status: observed
Image: gcr.io/test-ai-243511/ingest12:10.0.0
Notes: One pipeline per camera in iot-config.json; pulls the seven simulator paths over RTSP
search-engine containerStatus: observed
Image: gcr.io/test-ai-243511/search-engine:10.0.0
Network: host; listens on 9801
Mounts: /config from /data/home/pi/config, /vault_secrets
Compose: /home/pi/docker-compose/spot_ivr (root-owned; .env TAG=10.0.0)
TimescaleDBStatus: observed
Container: spot-timescaledb
Database: spotai
Tables of interest: track_bboxes (detections), events_fire_log (agent actions), zones, video_paths
Persistence: /data
Cloud link (tunnel and vault-agent)Status: observed
Containers: tunnel, vault-agent
Notes: The product reaches the device-manager through the tunnel; vault-agent renews the appliance certificate. Both fail when the appliance certificate has expired.
Identity path: /data/home/pi/vault_secrets

The compose project is /home/pi/docker-compose/spot_ivr (root-owned; .env carries TAG=10.0.0). Logs are docker logs <container>; the search-engine’s log level is set in search-engine.json.

/data/home/pi/config/iot-config.json (cameras) and ai-config.json (agents) are written by the product through the tunnel on every change; a hand edit lasts until the next rewrite. Camera streams are stored as raw addresses (192.168.1.12:554), and the appliance resolves no host names. Today the files hold cameras 12631-12637 (the seven simulator paths) and agents 1312-1333 (the test bed’s rules, each with two webhook actions to the receiver). Every hand edit is recorded with its revert in the appliance repository notes changelog.

Durable: /data (database, configs, identity, logs), /home/pi/camera_simulator/videos (the original 24 GB library, unused on the box today). The three cameras that were on the box before 6 October were removed in the product. Recovery recipes: test bed runbook. The one repair exercised on this box is the identity reset after expired certificates (6 October), which needs the owner’s go.

Read on 5 and 6 October. Not checked: how /home/pi relates to /data/home/pi; the transport between ingest and search-engine; whether the Docker login to the image registry is still fresh (spotcred --login-docker refreshes it). Firmware version on the box is read from the container tags, since the version files were empty.