Installing the controller
The controller is the meshint Python package, installed from a wheel. That package also provides meshint analyse and the evaluation harness. The probe is a separate program,...
The controller is the meshint Python package, installed from a wheel. That package also provides meshint analyse and the evaluation harness. The probe is a separate program, installed from its own archive: probe-installation.md.
The controller listens for probes on one HTTPS port and serves the admin page on a localhost HTTP port. It does not connect out to a probe.
What you receive
For a release <version>:
| File | Role |
|---|---|
meshint-<version>-py3-none-any.whl | The controller package |
SHA256SUMS | Checksum of that wheel and of the probe archive |
The wheel contains the controller program, the admin page, and the map geography. It does not contain the probe, a private key, or a certificate. NumPy, SciPy, Matplotlib, and h5py are installed with it from the Python package index.
What you need
- Python 3.11 or newer, and pip
- A network path to the Python package index, for those four libraries
- A network address probes can reach, for the probe port
- A directory for controller state, on a disk you can keep private
Check and install
sha256sum -c SHA256SUMS
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install meshint-0.1.0-py3-none-any.whlOn macOS, shasum -a 256 -c SHA256SUMS checks the same file. Use the wheel file name you were given. Install only after that wheel is reported OK.
Confirm the install:
meshint --versionThe version is printed as meshint plus the package version. The admin page shows that same version in the header.
First start
meshint controller serve \
--bind 192.0.2.10:8443 \
--admin 127.0.0.1:9444 \
--state ./controller-state \
--sapient ./sapient.jsonl--bind is the address probes use. Use the address they will put in --url, not a name they cannot connect to. --admin must be localhost (127.0.0.1, localhost, or ::1). Any other admin address is refused. --state is the directory for the key, the certificate, and state.json. --sapient is the JSON-lines log of every SAPIENT message the controller builds.
The process prints:
Probe URL, which is the--urla probe should usePin, the certificate file a probe must be given with--pinAdmin interface, which ishttp://127.0.0.1:9444/in the example aboveSAPIENT, the log path
The certificate and the private key are created in --state the first time the controller starts, and reused after that. The certificate's name list includes the bind host. Give probes the certificate file only. Do not copy the private key onto an aircraft.
Open the admin URL in a browser on the same machine. The page is localhost only and has no separate credential. Do not publish the admin port.
Layout after the first start
controller-state/
state.json approvals, scan plan, subjects, airframes, cues, SAPIENT settings
audit.jsonl the latest 1000 admin actions
<certificate> the pin, printed at start
<private key> stays on this machine
updates/ a staged software-update file, when one has been sent
sapient.jsonl SAPIENT messages, whether or not emission is enabledaudit.jsonl records the action and its object. It does not record update bytes, positions, or credentials from a SAPIENT URL.
Stopping and starting again
Stop the process with Ctrl-C. Start the same command with the same --state directory. Approvals, the scan plan, and the certificate persist. The London mesh simulation does not. It starts off and has to be turned on again from the admin page.
The admin page is part of the installed package and is read when the controller process starts. Install a newer wheel and start the process again when you need a new page or a new controller build.
What this install does not do
- It does not install
meshint-probe. - It does not open an SDR.
- It does not enable SAPIENT emission. Emission stays off until an administrator sets an endpoint, as described in controller-administration.md.
Updated 1 day ago
