OTA Updates
Updating firmware over a flaky link, with rollback, and without bricking the device.
5 to work through
-
advanced
A connected-vehicle fleet needs over-the-air firmware updates. What must the architecture guarantee, and why is this unlike a server deployment?
2 min answer -
advanced
A firmware update bricked 4% of a deployed fleet. Each recovery requires a site visit. What went wrong and what prevents recurrence?
2 min answer -
advanced
A staged over-the-air rollout reaches 100% over two weeks. What happens to the 12% of devices that were offline for the whole window and come back three weeks later on the old firmware?
3 min answer -
advanced
An OTA firmware update has bricked 3% of a 50,000-device fleet. What do you do, and what should have prevented it?
1 min answer -
advanced
Design over-the-air updates for devices where a failed update means a physical service visit.
2 min answer
6 terms in this topic
A/B Partition Update
Writing a new device image to an inactive partition and switching to it only after verification, so that a failed update falls back to the known-good…
patternA/B Partition Update
Writing firmware to an inactive partition and switching on next boot, so a failed update falls back to the previous image rather than bricking the device.
conceptDevice-Side Refusal
The rule that a device must refuse an unsafe instruction regardless of what the server commanded, because the server does not know the device's physi…
patternLocal Revert
A device automatically returning to its previous known-good software or configuration when the new one fails, without needing to contact a server - t…
practiceOver-the-Air Update
Updating software on deployed physical devices remotely, where a failed update can require someone to physically visit the device.
conceptUpdate Long Tail
The persistent stratum of devices running old firmware because they were offline during rollouts - which grows across releases and is measured by ver…
Neighbouring topics
Edge, Mobile & IoT
General material on architecture beyond the data centre boundary.
Mobile App Architecture
Layering, navigation, background execution, and the platform rules you do not set.
Offline-First
Treating connectivity as an optimisation, with a local store as the source of truth.
Sync & Conflict Resolution
Two devices that both changed the same record while neither could see the other.
CRDTs
Data types that converge without coordination, and the semantics you must accept.
Mobile Release Strategy
Store review, staged rollout, and supporting versions you can never force off.
Push & Background Work
Delivery that is best-effort, and an operating system that will kill your process.
Device Identity
Identifying a thing rather than a person, and rotating a credential you cannot type.
Edge Compute Topologies
Regional, metro, on-premises and on-device, and what each tier is genuinely for.
Edge Functions
Short-lived compute at the CDN, its runtime limits, and what must stay at origin.
Edge Data Consistency
Replicated read state at hundreds of locations, and writes that still go to one.
IoT Ingest Architecture
Millions of small, unreliable, frequently duplicated messages arriving continuously.
Device Provisioning
Getting identity and configuration onto hardware at manufacture or first boot.
Fleet Management
Inventory, health, configuration and grouping across devices you will never see.
Constrained Protocols
MQTT, CoAP and their kin, chosen for power, packet size and intermittent links.
Device Telemetry at Scale
Deciding what a device sends, how often, and what is aggregated before it leaves.
Digital Twin
A server-side model of a physical thing's reported and desired state.
Edge Security & Attestation
Secure boot, hardware roots of trust, and proving what is running on a device.
Physical-World Failure Modes
Power loss, tampering, clock drift, thermal limits, and a truck through the fibre.