advanced 2 min answer

A fleet platform adds a persistent reverse tunnel from every one of its 220,000 devices to a support broker, so engineers can open a shell on any unit and avoid a site visit. What does that buy, what does it pay, and when does the bill arrive?

fleetremote-accesssecurityblast-radiuskeepalive
Show the full answer Hide the answer

What is gained, quantified

A technician dispatch costs on the order of $150 to $300 in 2025 for a routine visit, more where access has to be scheduled with a building owner. At a 2% annual intervention rate across 220,000 devices, that is about 4,400 visits, roughly $0.9M a year. Moving remote resolvability from 40% to 80% of those cases saves on the order of $350,000 a year, and the saving is visible in the first quarter, which is why these proposals pass easily.

What is paid

  • A permanent inbound control path into every device is the single largest security liability a fleet can own. One compromised support credential, one broker misconfiguration, and the blast radius is a shell on 220,000 units in the physical world. Nothing else in the architecture concentrates risk like this.
  • Keepalive traffic is not free on a metered link. A 60-second keepalive at roughly 100 bytes each way is about 4 to 5 MB per device-month. Across the fleet that is on the order of 30 GB a day of packets that carry no information, and for a cellular fleet it is a line item in the connectivity contract.
  • Connection ceilings move the broker into a different class of system. 220,000 idle TLS connections at roughly 30 to 60 KB of kernel and user-space buffers each is 7 to 13 GB of memory before any application state, plus the reconnection storm every time the broker restarts.
  • Audit surface. Every regulated customer will ask who opened a shell, on which device, when, and what was typed. Session recording and approval workflow are now part of the product.

When the bill arrives

The data cost arrives immediately and quietly, inside a connectivity bill nobody attributes to the feature. The security cost arrives at the first credential compromise or the first customer security review, and by then the tunnel is load-bearing for the support organisation, which makes removing it a political problem rather than an engineering one.

How to keep the option to reverse

Make access on-demand rather than standing. The device already polls or holds its telemetry channel; deliver a signed, time-boxed instruction over it to open a session outbound, scoped to one device, expiring in 30 minutes, recorded, and gated on two-person approval in production. No listening socket, no permanent fan-in, and the keepalive problem disappears because the normal channel was paid for already.

The decision rule, and when not to

Yes, on-demand, for a mains-powered fleet behind customer NAT where a visit costs more than $200. Never for a battery or NB-IoT fleet: the keepalive alone can consume a meaningful share of a multi-year power budget, and it buys a shell on a device too slow to debug interactively.

The alternative that is usually underrated: an on-device diagnostic bundle, collected on the device's own schedule and uploaded with the next normal connection. It resolves most of the same cases, costs kilobytes, and adds no inbound path. Build that first and measure how many visits it removes before anyone builds a tunnel.