Linux delivery

Signed OTA updates for Linux devices

The current Linux path updates application-level artifacts without replacing the base operating system. Each device authenticates with its own certificate and verifies update metadata against a pinned TUF root.

Good fit

When to evaluate it

  • +Industrial Linux gateways and appliances
  • +Connected products behind NAT
  • +Mixed arm64 and amd64 fleets

Product boundary

What the current product does

A1

Pinned bytes

Registry tags resolve to immutable digests before signing, so a later tag move becomes a different artifact version.

A2

Staged rollout

Canary waves, approval gates and failure thresholds limit exposure before a release reaches the full fleet.

A3

Health-driven recovery

The selected adapter retains prior state where supported and restores it when its configured health contract fails.

A4

Air-gap path

A site gateway uses one outbound tunnel while devices retain end-to-end control-plane and TUF verification.

Explicit limit

Whole-system A/B Linux updates require a product image with a qualified RAUC layout, keyring and bootloader policy. DEB and RPM delivery is not available because package recovery semantics are not enforced.

Console proof

See the operational record

Meshanics rollout detail screen
Rollout detail - waves, device outcomes and halt state in one operational record.

Questions

Does Meshanics require changes to application code?

No. The static Linux agent installs on the device and activates signed payloads through typed adapters. Health behavior and recovery limits are configured for the artifact, not embedded in customer application code.

Does Meshanics certify CRA compliance?

No. Meshanics records and exports evidence for the manufacturer's compliance work. The manufacturer remains responsible for product scope, risk decisions, conformity assessment, reporting, and declarations.