Offline Bundle Install
This is how you install on a customer edge site with no internet, no registry access, and no image building on the box. You install everything from a single self-contained release bundle that ships on USB media.
What you receive
Section titled “What you receive”A release bundle is one directory, named for its profile and version, for example
jetson-gpu-v1.58.4. The jetson-gpu profile targets the Jetson TX2 on
JetPack 4.5 and runs inference on the GPU through CUDA.
Inside the bundle:
Directoryjetson-gpu-v1.58.4/
Directoryimages/
- jetson-gpu-v1.58.4.images.tar.zst the three service images, compressed
- manifest.txt profile, version, image tags, checksum
Directorycompose/
- docker-compose.release.yml image-based stack (no build step)
- docker-compose.tls.yml HTTPS overlay (opt-in)
- docker-compose.certs.yml datasource TLS cert overlay (opt-in, see below)
- .env.template port and setting placeholders
Directorymodels/
- predictive_maintenance_op15.onnx demo seed model (random weights)
Directorylib/ installer helpers
- …
Directorysystemd/ boot-start unit template
- …
Directorycerts/
- …
Directorytls/
- …
- install.sh
- update.sh
- uninstall.sh
- compact-db.sh reclaims database disk space
- README.txt
Where the running stack lives
Section titled “Where the running stack lives”The installer copies what the running stack needs into /opt/aiboard: the
compose files, the seed model, the generated .env, tls/, certs/, and the
pre-update backups/. After a successful install or update, the bundle
directory is no longer needed by the running box.
Before you start
Section titled “Before you start”The target Jetson must already have these installed. They ship on the golden JetPack image. The installer checks for them and stops if anything is missing; it does not install them for you.
- Docker Engine 20.10 or newer, with the
docker composev2 plugin zstdandopenssl- The NVIDIA container runtime, registered with Docker
- About 6 GB of free disk where you copy the bundle
Install runbook
Section titled “Install runbook”-
Copy the bundle to the box
Section titled “Copy the bundle to the box”Copy the whole bundle directory from your USB media to the Jetson, then open a terminal in it:
Terminal window cd jetson-gpu-v1.58.4/ -
Run the installer
Section titled “Run the installer”The installer detects the Jetson, loads the container images, generates secrets, brings the stack up, and waits for health.
Terminal window sudo ./install.shUseful options:
Terminal window sudo ./install.sh --profile jetson-gpu # force the profilesudo ./install.sh --with-systemd # also start on bootsudo ./install.sh --no-backup # skip the pre-migration snapshot (see below)Under the hood
install.shruns these steps in order:- Preflight — checks the CPU architecture, Docker, Compose,
zstd,openssl, the Jetson and its NVIDIA container runtime, and free disk. - Verify the image archive checksum. This detects corrupt or tampered media.
- Load images —
docker loadfrom the bundled archive. No pull, no build. - Stage the runtime files into
/opt/aiboard. - Generate secrets — creates the JWT signing secret and admin password on
the box and writes the secret to
/opt/aiboard/.env(mode600). No secret ever ships inside the bundle. - Snapshot the database — if the box already holds a database, the installer backs it up before the new release can migrate it. See Database snapshots.
- Start the stack —
docker compose up -d. - Health gate — waits for the services to report healthy.
- Seed the admin and print the dashboard URL and admin password once.
- Preflight — checks the CPU architecture, Docker, Compose,
-
Save the admin password
Section titled “Save the admin password” -
Confirm the secret was written
Section titled “Confirm the secret was written”The installer generates the JWT signing secret automatically. You normally never touch it, but you can confirm the protected
.envexists:Terminal window sudo ls -l /opt/aiboard/.env # expect mode -rw------- (600)If a corporate policy requires your own value, set it in that file, then re-run
sudo ./update.shfrom the bundle you installed to apply it. Every signed-in session ends when the secret changes.# /opt/aiboard/.env (placeholder — generate a strong random value, do not reuse)AIBOARD_JWT_SECRET=your-strong-random-jwt-secret -
Replace the demo model
Section titled “Replace the demo model”The bundle ships a demo model with random weights. Replace it with your trained model so predictions are meaningful. Models for the TX2 must use ONNX opset 15 or lower.
- Upload from the dashboard (recommended). See Deploying Models.
- Before first install, you can overwrite
models/predictive_maintenance_op15.onnxin the bundle. Every update refreshes the seed model from the new bundle, so use the dashboard for a lasting change.
-
Verify health
Section titled “Verify health”Confirm the services are up:
Terminal window docker ps --filter name=aiboard- --format 'table {{.Names}}\t{{.Status}}'Expect
aiboard-inference-realandaiboard-backend-realto show(healthy), andaiboard-frontend-realto showUp. Then open the dashboard URL the installer printed and sign in with the admin account.
Day-2 operations
Section titled “Day-2 operations”Deploy a newer bundle. Copy it to the box, open a terminal in it, and run:
sudo ./update.shupdate.sh reads the live configuration from /opt/aiboard/.env, so you do
not copy anything between bundle directories. It then:
- Snapshots the database with its writers stopped, and verifies the archive. See Database snapshots.
- Loads the new images and points the configuration at them.
- Recreates the stack. The backend migrates the database on start.
- Waits for health. If the stack does not become healthy, the update stops, prints how to roll back, and removes nothing.
- Cleans up, only after the new release is healthy:
- It keeps the newest
AIBOARD_BACKUP_KEEPsnapshot archives (default3) and removes older ones. SetAIBOARD_BACKUP_KEEP=0in/opt/aiboard/.envto keep every archive. See Environment Variables. - It keeps the images of the release it just installed and the release it replaced, and removes older Xisom images. When you re-run the same release, for example after a failed health gate, it skips image cleanup so the previous release stays available for rollback.
- It keeps the newest
To skip the snapshot, pass --no-backup. Only do this if you took a
snapshot by other means: database migrations are forward-only.
sudo ./uninstall.sh # stop the stack, KEEP all datasudo ./uninstall.sh --purge # also delete the database, models, and logs (confirmation prompt)Database snapshots
Section titled “Database snapshots”Both install.sh and update.sh back up the database before a new release can
migrate it:
- The snapshot is taken with the database’s writers stopped, so the archive is consistent. The stack starts again when the run continues; if the run fails before that point, the stopped containers are restarted.
- The archive is read back before anything else changes. If it does not read back, the run stops while the current database is still untouched.
- Archives are written to
/opt/aiboard/backups/asbackup-<UTC timestamp>.tgz. The run prints the exact restore command next to the archive name. - A snapshot covers the database only, not uploaded models. Back up the model volume separately if you need to roll models back.
--no-backupskips the snapshot on either script.
Datasource TLS certificates
Section titled “Datasource TLS certificates”Datasource-side TLS — the CA, client certificate, and key an MQTT or OPC UA
datasource uses to reach a secured broker or server — is separate from the box’s
own HTTPS certificate. It is off by default. Turn it on with a .env flag,
symmetric with AIBOARD_TLS_ENABLED:
AIBOARD_CERTS_ENABLED=1Put your MQTT/OPC UA CA and client certificate/key files in
/opt/aiboard/certs/. When the flag is on, the installer and update.sh
layer the bundled docker-compose.certs.yml overlay on top of the release
stack, and the backend mounts that directory read-only. Before the first
install, set the flag in the bundle’s compose/.env.template instead. On a
running box, re-run sudo ./update.sh after you change the flag.
If something goes wrong
Section titled “If something goes wrong”| Symptom | What it means |
|---|---|
Bundle manifest missing | You ran the installer from a source folder, not an assembled bundle. Use the bundle directory you copied from USB. |
Architecture mismatch | The bundle is for an arm64 Jetson, and this machine is not one. Copy the bundle to the Jetson. |
/etc/nv_tegra_release is absent | The machine is not a Jetson running L4T. Install on the Jetson TX2. |
NVIDIA container runtime not wired into Docker | Docker on this Jetson has no nvidia runtime. Fix the JetPack image so Docker lists it. |
Low disk | Not enough free space for the images. Free about 6 GB and retry. |
Inference shows starting | CUDA initialisation takes up to about 90 seconds on first start — wait. If it then turns unhealthy, check docker logs aiboard-inference-real. |
Found an existing install at: … | The box was installed before /opt/aiboard existed. Run the same script once with --migrate. |
| Archive checksum mismatch | Corrupted or tampered USB media. Re-copy the bundle and retry. |
See the full Troubleshooting runbook for symptom-keyed fixes.