Skip to main content
Version: Torizon OS 7.x.y

First Steps with Secure Offline Updates

Introduction​

This article directs you through the steps to use the Secure Offline Updates with Torizon.

What is the Torizon Secure Offline Updates Feature?​

Secure Offline Updates is a feature of Torizon Cloud that updates devices you cannot reach over the network. You carry the update to the device on a storage medium, which suits devices with intermittent connectivity, limited bandwidth, or no network access at all.

Read the Secure Offline Updates Overview for a broader view of the feature, or the Torizon Updates Overview to compare it with the other update methods. For details about the underlying technologies, see the Torizon Updates Architecture.

Prerequisites​

In order to perform your first steps with offline updates, you should satisfy all of the following prerequisites:

First Steps​

Create the Packages​

The first step is to upload your OS Image and/or Application to the Torizon Cloud. Learn how Torizon manages Software Packages reading the Feature Overview

You can create a Torizon Application Package from the web UI, TorizonCore Builder or an IDE with Extension for Torizon:

You also need to push your application to a Docker registry, so TorizonCore Builder can download the container images when it creates the Lockbox. The device does not download anything during an offline update.

To create a Torizon OS Package, you should use TorizonCore Builder to push images built by you or other collaborators. Remember, you can always use Toradex's provided images out-of-the-box.

info

Do not bundle container images into a Torizon OS image if you plan to update your devices with Torizon Cloud. Bundled containers only reach a device when you flash the image with Toradex Easy Installer, so they cannot be delivered as an update. To deploy the OS and the application together, use the synchronous update feature of Torizon Cloud instead.

warning

To be compatible with Secure Offline Updates, the Docker Compose package must be canonicalized, which can be done using the --canonicalize argument.

If a name for the package is explicitly specified with --package-name, then it should also end with .lock.yml or .lock.yaml. Moreover, due to some known limitations, the package name must only employ basic ASCII characters excluding control ones and those in the set \/:*?" ><|, otherwise the Lockbox generation may fail later.

Define the Lockbox​

The next step is to define the Lockbox in the Torizon Cloud Web UI. This is the step where you decide exactly what software goes into the Lockbox, so that the Torizon Cloud can generate signed install instructions allowing your devices to trust the update.

To define a Lockbox you have to:

  1. Select the desired OS and/or application packages
  2. Give it a name, so you can refer to it in future steps

Create the Lockbox​

Once the Lockbox has been defined, you are ready to use TorizonCore Builder to download the files, metadata, and signatures that the device uses for validation. Use TorizonCore Builder for this step, and all the required files are downloaded onto your workstation.

You can then copy the files onto a storage medium of your choice.

Deploy the Offline Update​

Now that you have the update medium, you can take it to the device and deploy the update:

  1. Insert the update medium (loaded with the Lockbox) into the device
  2. Wait for the update to finish
  3. Remove the update medium. At this point, the device is updated
info

The update process is fully automated and no user intervention is required at any time. If you are performing an OS or synchronous update, the board automatically reboots once.

tip

Configure your device for offline updates before you deploy a Lockbox. Follow How to Use Secure Offline Updates with Torizon OS to set the correct path to the storage medium's mount location.

Send Feedback!