Skip to content

feat: router simulator - #440

Open
NickGhignatti wants to merge 9 commits into
masterfrom
feat/router-simulator
Open

NickGhignatti wants to merge 9 commits into
masterfrom
feat/router-simulator

Conversation

@NickGhignatti

Copy link
Copy Markdown
Owner

This pull request implements building-scoped device keys for telemetry collectors, extends the telemetry API with new endpoints, and refines how routers and connected devices are handled. It introduces a device key epoch for secure key rotation, adds support for router simulation, and ensures that both /telemetry/ingest and /telemetry/collector are ungated at the edge but HMAC-verified in-service. The changes also update documentation and acceptance tests to reflect these new behaviors.

API and Security Enhancements:

  • Added /collector endpoint to the telemetry API, allowing on-site collectors to fetch router lists, authenticated using a building-scoped device key derived from a master key and a per-building epoch. The endpoint is ungated at the edge and requires a signed timestamp for authentication. [1] [2] [3] [4]
  • Introduced /device-keys/buildings/{buildingId} endpoint to rotate and issue new device keys per building, with device keys derived (not stored) using TELEMETRY_DEVICE_MASTER_KEY and a per-building epoch. [1] [2] [3] [4] [5] [6] [7]

Router and Device Management:

  • Added /connected-devices/buildings/{buildingId} endpoint to return the total number of devices connected in a building, summing the latest reports from each room without double-counting. [1] [2] [3]
  • Extended the simulator configuration to support router simulation by adding ap-simulator for the router kind and clarified that only claimed kinds are sent for simulation. [1] [2] [3]

Database and Storage Changes:

  • Added device_key_epoch column to the buildings table to track device key rotations, with migrations to add and remove the column. [1] [2]
  • Implemented DeviceKeyStore for Postgres, supporting retrieval and rotation of the device key epoch. [1] [2]

Testing and Documentation:

  • Updated acceptance tests to verify that /telemetry/collector is ungated at the edge and HMAC-verified in-service, and added helper methods for collector authentication. [1] [2]
  • Improved documentation and comments throughout to clarify the handling of device keys, router simulation, and authenticated endpoints. [1] [2] [3]

Other Notable Changes:

  • Added a new method to fetch all sensors of a particular type from the database, supporting router enumeration for collectors.

References:
[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20]

Closes #433

Comment thread simulators/ap-simulator/api.py Fixed
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feat]: simulate the twin's routers and the devices connected to them

2 participants