ListeningPost/open-firmware-manager

simple example of encrypted open firmware management using a PDS to sign firmware.

TypeScript

3

0 commits

updated Oct 5, 2026

See the code

README

Open Firmware

Production system for cryptographically signed software distribution over AT Protocol.

The distribution center is a PDS. Publishers write signed release chains (records + blobs). Edge agents and Sidekar pull, audit, and apply.

Products

PackageRoleDocker?
@open-firmware/coreChunking, Phase A audit, service windowsNo
@open-firmware/atproto-liteVanilla XRPC clientNo
@open-firmware/hostPublish releases to PDSNo
@open-firmware/clientIoT/edge pull + verify + apply hooksNo
@open-firmware/sidekarServer agent; optional Docker applyOptional
@open-firmware/iotDevice identity, factory reset, sealed jobsNo
@open-firmware/utilityAdmin: approve join, set password, jobsNo
@open-firmware/serverPrivate control plane APINo
ofw (Rust CLI)release / publish / pipeline-ack / auditNo

Trust model

  1. Author DID + PDS commit signatures authenticate records
  2. Content digests (SHA-256) on release + chunks
  3. Phase A validates the full chain before download
  4. Phase B verifies blobs and full-image hash before apply

AppViews and dashboards are never the trust root.

Quick start (guided walkthrough)

cd examples/full-stack
./scripts/gen-pds-secrets.sh
docker compose up --build -d

# Guided UI (plain language + live status):
#   http://localhost:8099
# Full written tour:
#   examples/full-stack/WALKTHROUGH.md

./scripts/publish-to-pds.sh "Hello from Open Firmware"
# Workload: http://localhost:8080
# PDS:      http://127.0.0.1:2583/xrpc/_health

Production publish

cd cli && cargo install --path .

ofw publish \
  --pds https://your-pds.example \
  --identifier your-handle \
  --password "$OFW_PASSWORD" \
  --product my-app \
  --version 1.0.0 \
  --kind container \
  --file ./image.tar \
  --yes

GitHub Actions: cli/examples/github-actions-publish.yml.

IoT management (join / password / factory reset)

pnpm --filter @open-firmware/iot build
pnpm --filter @open-firmware/utility build
pnpm --filter @open-firmware/server build
pnpm --filter @open-firmware/iot-camera-emulator test:e2e

See examples/iot-camera-emulator and docs/private-plane.md.

Specs & docs

Develop

pnpm install
pnpm --filter @open-firmware/core test
pnpm --filter @open-firmware/iot test
pnpm -r run build
cd cli && cargo test && cargo build --release

License

Apache-2.0

ListeningPost/open-firmware-manager

simple example of encrypted open firmware management using a PDS to sign firmware.

TypeScript

3

0 commits

updated Oct 5, 2026

See the code

README

Open Firmware

Production system for cryptographically signed software distribution over AT Protocol.

The distribution center is a PDS. Publishers write signed release chains (records + blobs). Edge agents and Sidekar pull, audit, and apply.

Products

PackageRoleDocker?
@open-firmware/coreChunking, Phase A audit, service windowsNo
@open-firmware/atproto-liteVanilla XRPC clientNo
@open-firmware/hostPublish releases to PDSNo
@open-firmware/clientIoT/edge pull + verify + apply hooksNo
@open-firmware/sidekarServer agent; optional Docker applyOptional
@open-firmware/iotDevice identity, factory reset, sealed jobsNo
@open-firmware/utilityAdmin: approve join, set password, jobsNo
@open-firmware/serverPrivate control plane APINo
ofw (Rust CLI)release / publish / pipeline-ack / auditNo

Trust model

  1. Author DID + PDS commit signatures authenticate records
  2. Content digests (SHA-256) on release + chunks
  3. Phase A validates the full chain before download
  4. Phase B verifies blobs and full-image hash before apply

AppViews and dashboards are never the trust root.

Quick start (guided walkthrough)

cd examples/full-stack
./scripts/gen-pds-secrets.sh
docker compose up --build -d

# Guided UI (plain language + live status):
#   http://localhost:8099
# Full written tour:
#   examples/full-stack/WALKTHROUGH.md

./scripts/publish-to-pds.sh "Hello from Open Firmware"
# Workload: http://localhost:8080
# PDS:      http://127.0.0.1:2583/xrpc/_health

Production publish

cd cli && cargo install --path .

ofw publish \
  --pds https://your-pds.example \
  --identifier your-handle \
  --password "$OFW_PASSWORD" \
  --product my-app \
  --version 1.0.0 \
  --kind container \
  --file ./image.tar \
  --yes

GitHub Actions: cli/examples/github-actions-publish.yml.

IoT management (join / password / factory reset)

pnpm --filter @open-firmware/iot build
pnpm --filter @open-firmware/utility build
pnpm --filter @open-firmware/server build
pnpm --filter @open-firmware/iot-camera-emulator test:e2e

See examples/iot-camera-emulator and docs/private-plane.md.

Specs & docs

Develop

pnpm install
pnpm --filter @open-firmware/core test
pnpm --filter @open-firmware/iot test
pnpm -r run build
cd cli && cargo test && cargo build --release

License

Apache-2.0