Settings, About gains "Report this build": works or a problem, five tick boxes for what you actually exercised, how long you have run it, an optional line. It posts to the report service and lands on wadamesh.com/beta, which is what the next promote is decided on. Ticking matters: "it works" from somebody who watched it boot and "it works" from somebody who messaged on it all week are not the same claim, and a board only goes green on two of the second kind. "Report a bug" draws a QR for a prefilled GitHub issue form. The issue is filed from the reporter's phone under their own account, so no write token has to exist in a public firmware image and the reporter gets the replies. "Count this device" is off by default. It lets the update check say which board and version it is running, so a board with no reports can be told apart from a board nobody owns. Those need opposite responses and nothing could tell them apart before. Mechanics: the POST rides the existing core-0 tile/update worker and its WiFiClient/HTTPClient, like the version check, because a second pair on that ~8 KB stack overflows it. The device id is a salted SHA-256 of the public key truncated to 64 bits, so a second report replaces the first without saying who sent it. Sending is two taps and the second lists every field that leaves. Prefs v64 appends report_ping + report_done_n at the tail, which the schema's trailing static_assert now checks. Also here: scripts/build/matrix-check.sh prints what testers reported for a tag, and release.sh runs it before a --promote. It never blocks; a board nobody owns can never go green. With no reports at all it now says so rather than reporting a clean bill of health, which is the habit this is meant to replace. Built on all eleven S3 envs and the T-Display P4. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
wadamesh.com infrastructure
Distribution stack for wadamesh: a VPS nginx origin behind Cloudflare.
tiles.wadamesh.com →CF (HTTP, edge-cached) → nginx → OpenStreetMap / OpenTopoMap
firmware.wadamesh.com →CF (cache bins) → nginx → /srv/wadamesh/firmware
flasher.wadamesh.com →CF (HTTPS) → 301 → wadamesh.com
wadamesh.com →CF (HTTPS) → nginx → /srv/wadamesh/site
Map tile styles. The default /{z}/{x}/{y}.jpg route serves OpenStreetMap
(the firmware default). An opt-in OpenTopoMap topographic style is served from
/opentopo/{z}/{x}/{y}.jpg (explicit OSM alias at /osm/...); the device requests
it only when the user enables Map → Options → Topographic map. Legal: OpenTopoMap
map tiles are © OpenTopoMap (CC-BY-SA) over © OpenStreetMap contributors
(ODbL) + SRTM — the touch UI shows that attribution when topo is active, and the
14-day disk cache keeps each tile hitting OpenTopoMap at most once per fortnight
(their tile-usage policy asks for a contactable UA + caching, both of which the
transcode service provides). Deploying the topo routes = update
tiles.wadamesh.com.conf + tile-transcode.py, then
systemctl restart wadamesh-tile-transcode && nginx -t && systemctl reload nginx
and purge the Cloudflare cache for tiles.wadamesh.com/opentopo/*.
The firmware fetches tiles + the update-check over plain HTTP (on-device HTTPS isn't viable — mbedTLS needs ~30 KB heap, only ~5 KB is free post-Wi-Fi), so the tile + firmware hosts must stay reachable over HTTP. Cloudflare provides the edge cache, HTTPS for the flasher, and hides the origin IP (so no IP lives in this repo or the firmware).
1. VPS (origin)
sudo apt install nginx
sudo mkdir -p /srv/wadamesh/firmware/releases/TOUCH /var/cache/nginx/wadamesh-tiles
sudo cp deploy/nginx/tiles.wadamesh.com.conf /etc/nginx/sites-available/
sudo cp deploy/nginx/firmware.wadamesh.com.conf /etc/nginx/sites-available/
sudo ln -s /etc/nginx/sites-available/tiles.wadamesh.com.conf /etc/nginx/sites-enabled/
sudo ln -s /etc/nginx/sites-available/firmware.wadamesh.com.conf /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx
2. Cloudflare
- DNS:
A/AAAArecords fortiles,firmware,flasher,@→ the VPS IP, all Proxied (orange cloud). - SSL/TLS: mode Flexible (CF↔origin HTTP) is enough since the origin is
HTTP-only. Do NOT enable "Always Use HTTPS" on
tiles.orfirmware.— the firmware needs plain HTTP there. - Cache Rules:
tiles.wadamesh.com/*→ Eligible for cache, Edge TTL ~14d.firmware.wadamesh.com/releases/*/*.bin→ cache, Edge TTL ~1d.firmware.wadamesh.com/releases/TOUCH(the listing) → short TTL (~60s) or Bypass, so new releases appear promptly.
3. Publishing a release
From a wadamesh checkout (builds both boards, refreshes the listing, rsyncs up):
WADAMESH_VPS=user@your-vps scripts/release.sh beta_2
The on-device check GETs http://firmware.wadamesh.com/releases/TOUCH, finds the
highest beta_<N>, and (once OTA-over-Wi-Fi is re-enabled) pulls
…/releases/TOUCH/beta_<N>/<board>.bin.
Done
- Web flasher ✅ — the guided install page at
wadamesh.com, served fromdeploy/site/and published byscripts/deploy-site.sh(esp-web-tools / Web Serial, per-board install buttons + .bin downloads, manifests generated per release byscripts/build/gen-flasher-meta.pyinto the/latest/and/latest-beta/feeds thatrelease.shrefreshes each publish). flasher.wadamesh.com301-redirects to the apex (seedeploy/nginx/flasher.wadamesh.com.conf) — it is an alias, not its own page.deploy/flasher/is the original standalone flasher page. No deploy script publishes it —deploy-site.shshipsdeploy/site/only — so it is effectively an offline/local copy kept in parity by hand. Retire it or wire it into a deploy target; until then, treatdeploy/site/index.htmlas the only install page users can reach.
TODO before public launch
- Re-enable OTA-over-Wi-Fi in the firmware (currently it version-checks then defers to manual flashing).
- Flip
wadameshrepo public = launch. - Decide tile-proxy sharing: dedicated
tiles.wadamesh.com(this config) vs reusing the meshcomod proxy.
Never commit the VPS IP, SSH keys, or
WADAMESH_VPS. Cloudflare fronts the origin; the deploy target is supplied via the environment at publish time.