← Back to Gateway Manager

Amplified Engineering · Whitepaper

Managing the Unattended Fleet

How Gateway Manager gives nodeG5, nodeMini, and third-party Linux edge devices secure activation, live health monitoring, and field-device control from one browser tab.

Why remote gateway management

A gateway that is out of sight is not out of risk. Every nodeG5 or nodeMini shipped into a switchboard, a pump shed, or a comms cabinet is a small computer running unattended, on someone else's network, for years at a time — and the failure modes are ordinary and expensive: a modem drops out silently, a card fills up, a firmware regression spikes CPU load until the device reboots itself in a loop.

Remote management closes that gap. Gateway Manager pairs a secure, technician-free activation flow with live monitoring, history, alerting, and field-device configuration — the same tools whether you're watching one gateway or five hundred.


STEP 1

Activate a gateway in seconds

Generate a single-use claim token from the dashboard, enter it once on the gateway — from its local console, or piped straight into gwm_claim <token> for a headless install — and the device is provisioned with its own random credential over TLS. The token is consumed the instant it's redeemed, so it can never be reused or shared between devices.

No inbound port is ever opened on the gateway, and no password is typed twice.

Gateway Manager claim token entry field
STEP 2

Watch the whole fleet from one screen

The dashboard answers the question a fleet owner asks first — is everything up? — before anything else. Every gateway reports its active network interface and IP, CPU and RAM load, board temperature, uptime, and cellular signal once every 30 seconds, with detected services such as Modbus or a Generic MQTT bridge tagged alongside it.

Gateway Manager dashboard showing three online gateways with live CPU, RAM, temperature and status

Live fleet view — status, active WAN, uptime, CPU/RAM load and connected services, updated every 30 seconds.

STEP 3

Drill into cellular connectivity

For cellular-connected gateways, a single click pulls a live carrier readout — network type and carrier, registration state, signal strength (RSRP), noise (SINR), and cell ID — without leaving the dashboard. Useful for confirming a marginal site before it becomes a support call.

Cellular signal detail modal showing RSRP, SINR and RSRQ readings
STEP 4

Get alerted before someone else notices

A dashboard only helps if someone is looking at it. Every plan shows live status and lets you reboot a gateway remotely. Pro & Business adds instant email alerts the moment a gateway goes offline — and again when it recovers — plus a full audit log of every claim, reboot, and alert event, timestamped against the account that triggered it.

STEP 5

Chart 24 hours to 30 days of history

A single bad reading is noise; a trend across days is a diagnosis. Every metric on the live dashboard is logged and charted — CPU load, RAM, temperature, cellular signal — alongside a connection-status timeline marking every offline event and how long it lasted.

History page showing CPU load and RAM usage charts over a 24 hour window

Basic 1 hr – 24 hr history  ·  Pro & Business full 30-day history, same charts.

STEP 6

Manage the gateway and its field devices

Beyond monitoring, each gateway has its own management page: rename it, set its cellular APN, and switch remote SSH on for a field fix — then off again — without a site visit.

Manage Gateway page showing identity settings, cellular APN and remote SSH access toggle

The iotasset.json file on every gateway defines the Modbus and CAN register map for whatever field device is wired into it. Pull it down for review, edit it offline, and push it straight back — the same configuration change that used to mean a laptop, a serial cable, and a site visit now takes as long as attaching a document to an email.

IoT Asset File section with download and upload controls, and Reboot action
STEP 7

Works with more than our own hardware

The same claim flow, transport, and dashboard row that runs on nodeG5 and nodeMini also runs, unmodified on the portal side, on third-party Linux single-board computers. Each board family gets its own lightweight installer — because a Jetson's serial ports and an x86 box's network stack are genuinely different — but every one of them lands on the identical secure activation and live monitoring.

Native

nodeG5 / nodeMini

Amplified's own industrial gateways — the reference platform.

Verified

NVIDIA Jetson Orin

JetPack / Ubuntu, for on-device inference at the edge.

Verified

Raspberry Pi 5

Debian — a low-cost option for lighter-weight sites.

Verified

Ubuntu x86 / AMD64

General-purpose mini PCs and industrial compute — installation and monitoring confirmed on real hardware.

Supported

Other Linux ARM64

Any general-purpose Debian-family board, industrial or off-the-shelf.

SECURITY

The architecture, not a feature

None of the above is safe to offer at fleet scale unless the plumbing underneath it is trustworthy by default.

No inbound exposureEvery gateway makes an outbound TLS connection — nothing to port-forward, nothing listening for the internet.
Per-device credentialsEach gateway authenticates with its own random secret and its own topic permissions.
Single-use activationClaim tokens are consumed on first use and removed from the database immediately.
On-demand SSHRemote access stays off by default and is switched on deliberately, per device, per fix.

Plans that scale with the fleet

Start on a single site for nothing. Move to fleet-wide alerting and 30-day history the day it starts to matter.

Plans and Upgrade page showing Basic, Pro and Business tiers

Bring your fleet in from the field.

Whether it's ten nodeG5 units on one site or five hundred mixed Amplified and third-party gateways across a continent, activation takes one token and monitoring starts the same second.