-
Notifications
You must be signed in to change notification settings - Fork 178
Add documentation about mbed dm
#681
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 2 commits
0dd6a93
a01cdbb
e987f72
3985136
3bbde13
8b3053a
40a757f
72f1710
6137ca5
91cee41
3d9066d
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,76 @@ | ||
### Updating Devices with Mbed CLI | ||
|
||
Mbed CLI includes features that help prepare and ship updates for devices managed through the Device Management Portal. Mbed CLI uses the subcommands starting with `mbed device-management`, `mbed dev-mgmt` or `mbed dm` to manage devices. | ||
|
||
Start by configuring your Mbed Cloud SDK API key, target and toolchain. Obtain the API key from the the Device Management Portal. | ||
|
||
``` | ||
$ mbed config -G CLOUD_SDK_API_KEY <API_KEY> | ||
$ mbed target K64F | ||
$ mbed toolchain GCC_ARM | ||
``` | ||
|
||
Next, initialize the device management feature of Mbed CLI with the following command: | ||
|
||
``` | ||
$ mbed device-management init -d "<company domain name>" -m "<product model identifier>" | ||
``` | ||
|
||
First, this command asks for information about your update certificate. When Mbed CLI has enough information, it creates several files: | ||
* A certificate in `.update-certificates/default.der`. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Don't think this will render as a list without an empty line before the first bullet |
||
* A matching private key in `.update-certificates/default.key.pem`. | ||
* A set of default settings in `.manifest_tool.json`. | ||
* Mbed Device Management settings in `.mbed_cloud_config.json`. | ||
* Mbed Device Management developer credentials in `mbed_cloud_dev_credentials.c` | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Ditto about the "Mbed" prefix for "Device Management" here. Since you mentioned Pelion above I think you're ok just saying "Device Management" here. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Again, @MelindaWeed Asked for this name change. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. That'd just be Device Management. Sorry for not communicating the standards clearly. |
||
* Mbed Device Management update credentials in `update_defalut_resources.c` | ||
|
||
The default settings include: | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. These are the default settings in mbed_cloud_config.json? Would help to make them sub-bullets of that, rather than make the reader go back to figure out where default settings come in (this is only obvious to people who already know - most readers won't remember that they've just read about default settings two lines ago). There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. And needs an empty line to render the bullets |
||
* A unique vendor identifier, based on the domain name supplied to `init`. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. When did I supply things to There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. You supplied them to |
||
* A unique model identifier, based on the vendor identifier and the model name supplied to `init`. | ||
* The path of the certificate and private key. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Which certificate? Developer? Update? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Update. |
||
|
||
If you do not want to enter the subject information for your update certificate (country, state, city, organization and so on), add the `-q` flag to the command above. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. How far above? Why not add this as a note right below the command? |
||
|
||
As `device-management` is very long to type, the remainder of this document will use the `mbed dm` alias for all device management subcommands. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. You should have said that right after you listed the three possible forms and never used the full form again. It's so random here. |
||
|
||
<span class="notes">**Note:** The certificate created in `mbed dm init` is not suitable for production. Use it for testing and development only. To create a certificate for production purposes, please use an air-gapped computer or a Hardware Security Module. When going to production, conduct a security review on your manifest signing infrastructure, as it is the core of the security guarantees for update client.</span> | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I would like someone from Update to look at this note. @bremoran ? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Also it should come earlier (right around where I asked about a production flow) |
||
|
||
#### Single-device update | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Need empty line after headers, too |
||
Once you have run `mbed dm init`, you can perform updates on a single device by: | ||
|
||
``` | ||
$ mbed compile | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. But what am I compiling? Where should I be at this point? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. probably immediately after |
||
$ mbed dm update device -D <device ID> | ||
``` | ||
theotherjimmy marked this conversation as resolved.
Show resolved
Hide resolved
|
||
|
||
This will perform several actions: | ||
1. Upload the payload, generated by `mbed compile`, to Mbed Device Management. | ||
1. Hash the payload and create a manifest that links to its location in Mbed Device Management. | ||
1. Create an update campaign for the supplied device ID, with the newly created manifest. | ||
1. Start the campaign. | ||
1. Wait for the campaign to complete. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It's waiting? Even though devices could take ages to come on line and receive an update? What happens if it fails? Do I see that here? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The whole point of the command is to update a device. so, yes it waits for that to happen, and yes that can take a while. |
||
1. Delete the payload, manifest and update campaign out of Mbed Device Management. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Ditto about the "Mbed" prefixes. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. ditto about the name changes. |
||
|
||
This allows development with a device for testing purposes. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. That should come before you start giving me commands - I want to know why I'm bothering to compile and run things. |
||
|
||
#### Multidevice update | ||
If you need to update more than one device, you can use the Mbed Device Management portal to create device filters that can include many devices into an update campaign. First, you need a manifest. Once you have run `mbed dm init`, you can create manifests by: | ||
|
||
``` | ||
$ mbed compile | ||
$ mbed dm update prepare | ||
``` | ||
|
||
Optionally, a name and description for the payload and corresponding manifest can be provided: | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Why passive? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. copy paste. |
||
|
||
``` | ||
$ mbed dm update prepare -n <PAYLOAD_NAME> -d <PAYLOAD_DESCRIPTION>\ | ||
--manifest-name <MANIFEST_NAME> --manifest-description <MANIFEST_DESCRIPTION> | ||
``` | ||
|
||
Both methods of creating a manifest use the defaults created in `mbed dm init`. You can override each default using an input file or command-line arguments. See below for more details. | ||
|
||
Once you execute `mbed dm update prepare`, Mbed CLI automatically uploads to Mbed Device Management and you can then create and start an update campaign using the Mbed Cloud portal. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Mbed CLI automatically uploads to Mbed Device Management" What does Mbed CLI upload? |
||
|
||
### Advanced usage | ||
Mbed CLI allows for significantly more flexibility than the model above shows in exactly the same way as Manifest Tool. You can override each of the defaults that `mbed dm init` sets by using the command-line or an input file. Mbed CLI supports a variety of commands. You can print a full list of commands by using `manifest-tool --help`. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Mbed CLI keeps its name as far as I'm aware. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Also looks like in our manifest tool documentation, it's not capitalized, and instead referred to as "the manifest tool." There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Link to the tool's docs There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Seeing how this is the first mention of the manifest tool, I would provide a link to the tool's page. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. /docs/working/updating-firmware/manifest-tool.html |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do we really need "first" here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Total nit pick: The line "When Mbed CLI has enough information" tripped up my brain for a second (enough information from the command line args? Where is it coming from?). How do you feel about this as an alternative:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Removed.