Zyvor Edge Stack

Suite CI is green. Hermetic contract smoke proves Device Agent → Yard, Nodra → Yard, Fleet → Yard, and relay-pubsub backends — so you can see how the stack works together without reading six repos.

How they fit → View suite CI
9 products · open source · suite CI

Infrastructure that doesn't stop when the connection does.

Nine Zyvor products for sites that keep running on their own — from the hardware in the rack through Yard (ops console) to the Relay reliability loop. This page is how they fit together.

9products in the stack
21suite-ci contract checks
0cloud dependency to keep a site running
A→N→A→A→Vthe durable loop every event ends in
The stack, in order
01Device Agent 02Nodra 03Fleet 04OTA 05Yard 06relay-edge 07relay-pubsub 08Zyvor Relay 09Zynera
01
Zyvor Device Agent
Discovers the box, first
v0.1.6 zyvorai/device-agent Rust · arm64/amd64

“Linux hardware edge agent for Zyvor — discover the box, expose physical interfaces, publish to Nodra, expose Fleet-compatible inventory.”

  • Discovers identity, health, GPIO, I2C, SPI, UART, CAN, USB, and watchdog state on real Linux hardware
  • Deliberately stays out of protocol semantics — decoding Modbus/OPC-UA/BLE is Nodra's job, not this agent's
  • arm64-first: built for the actual boxes running at the edge, not a server rack
  • Marked “production-hardening” — past prototype, not yet declaring 1.0
Generic reference / Linux edge hardware Zyvor Device Agent identity · health · GPIO · I2C · SPI · UART CAN · RX-only CAN capture · USB · watchdog Nodra protocol + data plane Fleet control plane Modbus · J1939 · OPC-UA BLE · serial · LoRaWAN
docs/assets/architecture.svg — zyvorai/device-agent
02
Nodra
Runs the site, with or without the cloud
v0.2.2 zyvorai/nodra public

“The open edge runtime that keeps sites running when the cloud doesn't.”

  • Local MQTT/HTTP ingress in front of a durable, WAL-backed store-and-forward buffer
  • Device twins and edge-app reconciliation, offline-first by design — not offline-tolerant
  • Publishes a direct, named comparison against Node-RED, EMQX/HiveMQ Edge, AWS Greengrass, and Azure IoT Edge in its own docs
  • Honest about limits: file mode is single-writer; Postgres mode has multi-writer delivery/DLQ HA. Staged OTA canary campaigns + outbound MQTT QoS2 are shipped
03
Zyvor Fleet
Holds the whole fleet together over a bad WAN
v0.3.0 zyvorai/fleet Go 1.27+

“Every site. Still running.” — offline-first edge fleet control plane for Linux, Kubernetes, containers, and virtual machines.

  • The fleet-agent caches its full desired-state revision locally and keeps reconciling straight through a WAN outage
  • No arbitrary remote shell exposed — a deliberately narrower attack surface than a generic RMM tool
  • Targets systemd, containers, k3s, QEMU/KVM, and GPU edge servers from one control plane
  • Its own README carries the authoritative map of how this whole product family fits together
04
Zyvor OTA
Updates the OS underneath everything else
v0.1.0 zyvorai/ota Go 1.27.1

“Signed, recoverable device OS updates for the Zyvor Platform.”

  • RAUC-managed A/B slot installs with Ed25519-signed bundles
  • Automatic health-check-gated rollback — a bad update reverts itself, no one has to notice first
  • An explicit needs_recovery interlock for the one ambiguous case: a crash mid-update that isn't safe to auto-resolve
  • Names its own comparison set in its docs: Mender, SWUpdate, balena
Fleetassigns a signed release VerifyEd25519 signature + metadata Installwrite inactive A/B slot Rebootboot into new slot Checking healthfile / systemd / HTTP probes Committedhealth held for stable window Rolled backold slot restored automatically needs_recoveryambiguous crash — operator runs recover-abort poll or push signature + digest OK InstallBundle boot confirmed healthy throughstable window fails ortimes out crash / unclean restart
docs/assets/readme/ota-lifecycle.svg — zyvorai/ota
05
Yard
Ops console — assets, incidents, connectors
open zyvorai/yard Go · React

“Open asset and operations platform — devices, sites, telemetry, incidents, and work orders. Zyvor connectors are optional. Yard runs alone.”

  • Optional connectors pull Device Agent, Nodra, Fleet, and OTA into one console without owning their planes
  • Actions: inventory.refresh, telemetry.receive, desired.progress, campaign.list
  • HTTP ingest for inventory/observations; severity policies and work-order checklists for day-2 ops
  • Cross-product contracts proven by this repo’s suite CI
06
relay-edge
The upstream brain for Zyvor Relay
v0.1.2 zyvorai/relay-edge Go 1.27+ · Apache-2.0

A synthetic IoT/farm site & event simulator — stamps realistic site topology onto four built-in simulators and publishes it into Zyvor Relay, so the rest of the stack has real traffic before real hardware shows up.

  • Four simulators: a 47-point NFPA-style fire-water plant, a 77-device / 18-class fleet catalog, a 24-asset remote-edge NOC, and a farm domain
  • Every event is stamped with season/site/zone/recipients/verification probe before Relay ever sees it
  • Three live browser control rooms, streamed over Server-Sent Events
  • Publishes direct to Relay or through relay-pubsub — the same two paths every other producer in this stack uses
relay-edge home control room, showing the setup checklist and live status
/ui — live capture, this session
07
relay-pubsub
Speaks Pub/Sub so nothing else has to
v0.4.0 zyvorai/relay-pubsub public GHCR

“Google Cloud Pub/Sub compatibility for Zyvor Relay.”

  • Implements the real gRPC/REST surface: topics, subscriptions, Publish, Pull, StreamingPull, Ack, Seek, Snapshots, a subset of IAM, SchemaService
  • Its production backend forwards straight into Relay's own /v1/events
  • Ships a second, in-memory backend built just for demos and CI
  • Public, versioned images at ghcr.io/zyvorai/relay-pubsub
08
Zyvor Relay
The loop everything else in this stack feeds
private zyvorai/relay continuously deployed

“On-prem and edge reliability control plane for durable events, acknowledged notifications, idempotent actions, and verified outcomes.”

“Never lose an accepted event. Never knowingly execute a critical side effect twice. Never call an action successful until the expected outcome is verified.”

  • The loop: Accept → Notify → Ack → Act → Verify
  • Multi-tenant, with fully isolated data and dispatch per tenant
  • Transactional outbox/inbox, leased jobs with a dead-letter queue you can list and replay, circuit breakers with exponential backoff
  • Custom JWT auth with per-token revocation — logout is immediate, not TTL-delayed
  • An L0–L13 verification suite, plus a Prometheus /metrics endpoint
  • Its own operator console, compiled straight into the Go binary
09
Zynera
The optional AI/GPU brain, when a site needs one
v1.0.0 zyvorai/zynera private formerly “Forge”

“The Kubernetes brain for AI infrastructure” — an enterprise control plane for GPU clusters.

“VMware vCenter for AI/GPU infrastructure + OpenShift-grade Kubernetes ops + an AI SRE that never sleeps.”

  • Seven operators and 75+ CRDs running the real GPU scheduling, via eBPF
  • An embedded AI operations engineer — Zeus — watching the cluster
  • Twelve capability domains by its own count: placement, FinOps, security/SIEM, network intelligence, a model catalog, RAG studio, federation/DR, live vGPU migration, and more
  • Steps in only when a site runs real AI/GPU workloads — every other product in this stack works without it
How a single event actually moves through this

Not a diagram of intentions — this is the real path, drawn from what each product's own docs say it hands off to next.

01
Device Agent discovers the hardware and hands off — protocol and data-plane work to Nodra, lifecycle and control-plane work to Fleet.
02
Yard optionally pulls Device Agent inventory, Nodra twins/campaigns, and Fleet rollout progress into one ops console via connectors.
03
Nodra (and, for synthetic/dev traffic, relay-edge) stamp and publish events — direct, or through relay-pubsub's Pub/Sub-compatible gateway.
04
Zyvor Relay runs the durable loop — Accept → Notify → Ack → Act → Verify — on every event, regardless of which producer sent it.
05
When a site runs AI/GPU workloads, Relay can gate a critical act behind a Zynera Decision Record — human freeze/attest, in Zeus, before Act proceeds.
06
Underneath all of it, Fleet assigns the signed releases that OTA installs, verifies, and — if health checks fail — rolls back on its own.