Devices
That is the honest production state. Pelagio Defense defines the secure telemetry boundary a future physical node will use without presenting simulator state as hardware.
0
The map contains public observation stations, not Pelagio Defense hardware. A physical device appears only after authenticated admin registration; connected state begins only after valid telemetry.
Telemetry contract 2.0
The minimum real packet may contain only host measurements and software identity. Position, battery, and sensors remain absent until installed.
POST /api/v1/device-telemetry
Authorization: Bearer <device credential>
Content-Type: application/json
{
"schemaVersion": "2.0",
"sourceMode": "DEVICE_TELEMETRY",
"deviceId": "TW-YOUR-ID",
"messageId": "device-unique-message-id",
"deviceTimestamp": "ISO-8601 timestamp",
"bootId": "OS boot/session identity",
"sequence": 1,
"platform": {
"internalTemperatureC": 48.2,
"uptimeSeconds": 312,
"systemLoad1m": 0.34
},
"communications": { "linkType": "WIFI" },
"software": { "softwareVersion": "installed-version", "buildSha": "installed-build" }
}Per-device bearer credentials are shown once, hashed at rest, rotatable, revocable, and bound to one device, organization, and origin.
Device/message idempotency, boot identity, sequence gaps, and delayed-packet protection preserve history without corrupting latest state.
64 KiB envelopes, strict numeric bounds, five-minute future rejection, a 30-day offline-queue window, clock-skew flags, and credential-scoped throttling.
Allowlisted binary files are stored outside PostgreSQL with device ownership, size, MIME, and SHA-256 metadata.
The Linux client reads available OS, network, power, and NMEA GNSS inputs, persists sequence state, and retries from a bounded offline queue.
TW-EMU-001 is explicit, disabled and hidden by default, and cannot claim physical origin or a physical identifier.