feat: router simulator - #440
Open
NickGhignatti wants to merge 9 commits into
Open
NickGhignatti wants to merge 9 commits into
NickGhignatti wants to merge 9 commits into
Conversation
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request implements building-scoped device keys for telemetry collectors, extends the telemetry API with new endpoints, and refines how routers and connected devices are handled. It introduces a device key epoch for secure key rotation, adds support for router simulation, and ensures that both
/telemetry/ingestand/telemetry/collectorare ungated at the edge but HMAC-verified in-service. The changes also update documentation and acceptance tests to reflect these new behaviors.API and Security Enhancements:
/collectorendpoint to the telemetry API, allowing on-site collectors to fetch router lists, authenticated using a building-scoped device key derived from a master key and a per-building epoch. The endpoint is ungated at the edge and requires a signed timestamp for authentication. [1] [2] [3] [4]/device-keys/buildings/{buildingId}endpoint to rotate and issue new device keys per building, with device keys derived (not stored) usingTELEMETRY_DEVICE_MASTER_KEYand a per-building epoch. [1] [2] [3] [4] [5] [6] [7]Router and Device Management:
/connected-devices/buildings/{buildingId}endpoint to return the total number of devices connected in a building, summing the latest reports from each room without double-counting. [1] [2] [3]ap-simulatorfor therouterkind and clarified that only claimed kinds are sent for simulation. [1] [2] [3]Database and Storage Changes:
device_key_epochcolumn to thebuildingstable to track device key rotations, with migrations to add and remove the column. [1] [2]DeviceKeyStorefor Postgres, supporting retrieval and rotation of the device key epoch. [1] [2]Testing and Documentation:
/telemetry/collectoris ungated at the edge and HMAC-verified in-service, and added helper methods for collector authentication. [1] [2]Other Notable Changes:
References:
[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20]
Closes #433