getSerialNumber() is a BaseComponent method, so every component answers for
itself — and the bridge reads it off the flight controller. A Mavic Pro reports
08RDE1J00103H1 (what DJI Go labels "Flight Controller SN") where the airframe
sticker, and the registration, say 08QDE3H012032E. We were publishing the former
as the drone's serial, onto records that exist to satisfy BEK 1649 §5.
Same trap as 002e484, where a component's own firmware stood in for the
aircraft's, but with no correct source to switch to: MSDK v4 exposes no
aircraft-level serial at all — BaseProduct offers only the model and the
firmware package version — so the registered serial can only be typed by hand.
So split the two rather than pick one:
serial the airframe's, hand-entered, and the only one that
reaches the logbook and the CSV export
flight_controller_serial what the aircraft reports; auto-filled on connect,
and what POST /api/drones/auto now upserts on
Keying auto-add on the flight controller's serial keeps the fleet recognising a
connected drone without typing — it is stable per airframe — while leaving the
compliance record's serial to the pilot. A flight controller swapped in a repair
now costs a duplicate fleet entry to merge, where before it would have quietly
rewritten what the logbook claimed the drone was.
Note droneInput.payload() is a whole-record write, so any UI editing a drone must
round-trip flightControllerSerial; blanking it forks the drone into a duplicate
on its next connect. Drones.vue carries it through the edit form for that reason.
The migration copies existing serials into flight_controller_serial rather than
moving them: every current value came from auto-add and is therefore a flight
controller's, but a pilot may since have corrected one by hand and this cannot
tell them apart. Copying keeps auto-add matching the airframes it matched before.
Applied to the remote PocketBase, where drones held no records, so the backfill
was a no-op there.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PilotVault
A platform for drone operations management — remote control, live telemetry, intelligent flight scheduling, route management, and third-party integration — built on top of the DJI Mobile SDK V4.
Brand + design system live in
Design/PilotVault Project logo/ —
Vault Navy #0F1E3D with a single Signal Blue #3D7BF0 accent, Space
Grotesk (structure/display) · Space Mono (data, serials, timestamps, eyebrows),
and the Vector mark of two offset chevrons (flight, lift, parallax). All UI
surfaces implement it with a persisted light/dark toggle (data-*-theme
attribute); the Fly App follows the system theme.
Multiple surfaces sit in front of a shared PocketBase. The API Server is the only component that talks to PocketBase — the Web App and Fly App talk only to the API Server, which is the single gateway. Live device/telemetry state is held in memory by the API Server and fanned out over WebSockets.
┌────────────┐ ┌──────────────────┐ ┌──────────────┐
│ Web App │──/bff─►│ │ │ │
│ (Vue/Go) │ │ API Server │──auth─►│ PocketBase │
├────────────┤ │ (Go) │ │ 10.2.1.10: │
│ Fly App │──/ws──►│ in-mem devices │ │ 8026 │
│ (Flutter) │ └──────────────────┘ └──────────────┘
└────────────┘
Surfaces
| Folder | Stack | Port | Status |
|---|---|---|---|
API Server/ |
Go (+ embedded Vue 3 / Tailwind panel) | :8080 |
✅ Built & verified — gateway, panel, plugin system |
Web App/ |
Go BFF + Vue 3 + Tailwind | :8090 |
✅ Built & verified — control panel |
Fly App/ |
Flutter (Android) + Kotlin DJI MSDK V4 bridge | — | ✅ Built & run on a real device; live telemetry uplink |
Adobe Plugin/ |
— | — | 🚧 Placeholder |
Phone App/ |
— | — | 🚧 Placeholder |
Docker/ · Docker AIO/ |
Docker Compose | :8080 :8090 :8026 |
✅ Combined stack + single all-in-one container |
Data model (PocketBase)
PocketBase provides auth + persistence only; device and telemetry state are
in-memory in the API Server. Schema + seed ship as idempotent migrations in
API Server/pocketbase/pb_migrations/.
users— auth, plusrole(superadmin | admin | user),organizationrelation (nullable), and apreferencesJSON blob.organizations— tenant grouping for users.
Roles: superadmin = global (all orgs/users); admin = scoped to its own
org (manages that org's users, cannot cross orgs); user = no management.
Org-scoping is enforced in the API Server (internal/api/users.go, orgs.go).
User/org management requires a PocketBase superuser service account in
API Server/.env (POCKETBASE_ADMIN_EMAIL/PASSWORD, gitignored); without it,
/api/users and /api/orgs return 503.
Run order
- PocketBase — reachable at
http://10.2.1.10:8026(override withPOCKETBASE_URL). - API Server (
:8080):The embedded, superadmin-only panel is at http://localhost:8080/ (live health, PocketBase connection settings, and the plugins manager).cd "API Server" Copy-Item .env.example .env # set POCKETBASE_URL and POCKETBASE_ADMIN_* cd panel; npm install; npm run build; cd .. # build the embedded panel ./scripts/Run-ApiServer.ps1 - Web App (
:8090):Open http://localhost:8090 and sign in.cd "Web App/web"; npm install; npm run build; cd ../server ./Run-WebApp.ps1 - Fly App — see
Fly App/README.md(install Flutter- JDK, set your DJI App Key in
android/gradle.properties,flutter runon a connected Android device — the DJI SDK does not run on emulators).
- JDK, set your DJI App Key in
Docker
Docker/— combined stack (API Server + Web App) on a shared network:cd Docker; docker compose up --build.Docker AIO/— PocketBase + API Server + Web App in one container:cd "Docker AIO"; docker compose up --build.
Telemetry lifecycle
The Fly App connects on GET /ws/device?id={id} and streams typed events —
registration, connection, battery, telemetry (altitude, lat/lng,
velocity, GPS sats, flight mode…). The API Server merges each into a per-device
DeviceState, appends latitude/longitude to the device's GPS track, and fans
every update out to connected dashboards on /ws/ui as {type:"update", device, event}.
Plugins
The API Server integrates third-party services through a uniform plugin
contract (internal/plugins), managed by a superadmin from the panel. Two kinds
share one interface:
- Built-in — Go connectors compiled into the server (reference example: OpenSky Network live ADS-B flight data). Adding a new one needs a rebuild.
- External — a remote HTTP service registered at runtime, no rebuild;
answers
GET /health,GET /manifest,POST /invoke.
Enable-state and per-plugin config persist to a gitignored plugins.json. See
API Server/internal/plugins/README.md
for the developer guide.
Per-surface docs
- API Server README — full endpoint reference, panel, plugins
- Web App README — BFF proxy, dev/build
- Fly App README — Flutter + DJI MSDK V4 native bridge