First Steps with Secure Offline Updates
Introduction
This article directs you through the steps to use the Secure Offline Updates with Torizon.
What is the Torizon Secure Offline Updates Feature?
Secure Offline Updates is a feature of Torizon Cloud that updates devices you cannot reach over the network. You carry the update to the device on a storage medium, which suits devices with intermittent connectivity, limited bandwidth, or no network access at all.
Read the Secure Offline Updates Overview for a broader view of the feature, or the Torizon Updates Overview to compare it with the other update methods. For details about the underlying technologies, see the Torizon Updates Architecture.
Prerequisites
In order to perform your first steps with offline updates, you should satisfy all of the following prerequisites:
- Device running a Torizon OS image without containers or with a previous version of your application containers
- Commercial license for your Torizon Cloud account
- Device provisioned on the same account
- Device configured for using offline update
- The credentials.zip file download from your Torizon Platform account section
- The Torizon OS images and/or application files for the updates readily available
- TorizonCore Builder installed on your host machine
First Steps
Create the Packages
The first step is to upload your OS Image and/or Application to the Torizon Cloud. Learn how Torizon manages Software Packages reading the Feature Overview
You can create a Torizon Application Package from the web UI, TorizonCore Builder or an IDE with Extension for Torizon:
- Use the Torizon IDE Extension to Create a Container Project, or
- Select a Docker Compose file on your host machine from the Torizon Cloud Web UI, or
- Push a Docker Compose file to the Torizon Cloud with TorizonCore Builder
You also need to push your application to a Docker registry, so TorizonCore Builder can download the container images when it creates the Lockbox. The device does not download anything during an offline update.
To create a Torizon OS Package, you should use TorizonCore Builder to push images built by you or other collaborators. Remember, you can always use Toradex's provided images out-of-the-box.
Do not bundle container images into a Torizon OS image if you plan to update your devices with Torizon Cloud. Bundled containers only reach a device when you flash the image with Toradex Easy Installer, so they cannot be delivered as an update. To deploy the OS and the application together, use the synchronous update feature of Torizon Cloud instead.
To be compatible with Secure Offline Updates, the Docker Compose package must be canonicalized, which can be done using the --canonicalize argument.
If a name for the package is explicitly specified with --package-name, then it should also end with .lock.yml or .lock.yaml.
Moreover, due to some known limitations, the package name must only employ basic ASCII characters excluding control ones and those in the set \/:*?" ><|, otherwise the Lockbox generation may fail later.
Define the Lockbox
The next step is to define the Lockbox in the Torizon Cloud Web UI. This is the step where you decide exactly what software goes into the Lockbox, so that the Torizon Cloud can generate signed install instructions allowing your devices to trust the update.
To define a Lockbox you have to:
- Select the desired OS and/or application packages
- Give it a name, so you can refer to it in future steps
Create the Lockbox
Once the Lockbox has been defined, you are ready to use TorizonCore Builder to download the files, metadata, and signatures that the device uses for validation. Use TorizonCore Builder for this step, and all the required files are downloaded onto your workstation.
You can then copy the files onto a storage medium of your choice.
Deploy the Offline Update
Now that you have the update medium, you can take it to the device and deploy the update:
- Insert the update medium (loaded with the Lockbox) into the device
- Wait for the update to finish
- Remove the update medium. At this point, the device is updated
The update process is fully automated and no user intervention is required at any time. If you are performing an OS or synchronous update, the board automatically reboots once.
Configure your device for offline updates before you deploy a Lockbox. Follow How to Use Secure Offline Updates with Torizon OS to set the correct path to the storage medium's mount location.