Field notes from the edge.
Deep dives on managing Linux fleets, OTA strategy, and the operational craft of keeping millions of devices online.

Admiral v00048: Local Time Sanity, Unpairing Flows, and Image Preloading
Introducing monotonic disk-backed time logging, factory reset reworks, Shipwright image preloading, and dynamic KCP controls.

Admiral v00047: Low-Level Watchdogs, Offline Telemetry Buffers, and Power Metrics
Introducing physical hardware watchdog petting, offline AirDetect buffering, integrated battery metrics, and emergency provisioning recovery.

Admiral v00044 - v00046: Mesh Fallbacks, Bandwidth Prioritization, and AirDetect
Launching AirDetect spatial analytics, KCP/FEC mesh resiliency, and adaptive bandwidth prioritization.

Admiral v00043: Hardware Endurance, Storage Optimizations, and High-Fidelity Edge Telemetry
Introducing ZRAM migration, native FS scrubs, rapid DHCP onboarding, and robust physical edge instrumentation.

Admiral v00041 & v00042: Streamlined ARM64 Pipelines, Native Snapshots, and Hardened Workload Control
Bringing major ARM64 system-level enhancements, and tighter workload environment alignment to edge environments.

Admiral v00039 & v00040: Hardening Edge Networking, Storage, and Resilience
From intelligent SD-WAN link selection and automatic 6-hour rollbacks to wear reduction and installer diagnostics, this release brings enterprise-grade stability to harsh environments.

The Case Against Kubernetes at the Edge
Kubernetes is the most successful infrastructure software of the last decade. It's also the wrong tool for the edge. Here's why lightweight distributions don't fix the architectural mismatch - and what edge fleets actually need instead.

Build a PS2 Emulator on the Edge with Admiral
We packaged PCSX2 as an Admiral workload; X11, ALSA, gamepad passthrough, remote SSH and all. A fun demo that happens to exercise nearly every hard part of the platform.

Zero Trust for Edge: Rethinking the Perimeter
The perimeter model assumed you could draw a line around your infrastructure. Edge fleets broke that assumption years ago. Here's what a coherent zero-trust model for edge actually looks like.

SSHing Into Your Containers on Admiral
How to run sshd inside your Admiral workload, pull authorized keys from GitHub at build time, and get a real shell on any device in the field - without opening a single inbound port.

Preparing Your Edge Fleet for the Post-Quantum Era
Why "harvest now, decrypt later" is a real threat for long-lived signage and edge devices, what an adversary actually does once they're in, and how Admiral's hybrid post-quantum cryptography removes the attack from the table entirely.

Why We Ship Our OS as an OCI Container
Why Admiral ships the entire root filesystem as a signed OCI image - and how that single decision eliminates drift, simplifies CI, and changes how embedded teams work.