The fleet lived as a tab inside the Logbook, which buried it, and every
drone had to be typed in by hand — model, serial and firmware copied off
an airframe the app was already talking to.
Promote it to its own nav section above Logbook, and let a connecting
drone register itself. The Fly App already forwarded model, serial and
firmware upstream; the hub was keeping only the model. It now carries the
identity through to DeviceState, and the Web App offers it to a new
POST /api/drones/auto, which upserts keyed by serial. The auto path only
writes what the aircraft is authoritative about (model, both firmware
versions) and never touches what the pilot curates.
Serial and the firmware versions resolve on their own schedules after
connect — the serial in seconds, the aircraft firmware sometimes a minute
later — so nothing along the path treats an absent value as a cleared one,
and a later event filling firmware in still reaches the server. The auto
call rides every telemetry frame, so the client remembers the identity
tuple it last sent and only a change goes out; a 4xx is the server's
settled answer and is not retried, or one drone connected for an hour
would mean one request per frame for an hour.
New fields on drones: firmware, controller_firmware, and registration for
the FAA/CAA aircraft number — distinct from operator_number, which stays
the EU operator ID. Controller firmware is the remote controller's own
version, read from its component; the flight controller's version is a
different quantity and stays off this field (see 002e484). name becomes
optional and is now the pilot's custom name: auto-added drones arrive
unnamed, so the API serves a computed displayName (name, else model +
serial) for the fleet table, the flight picker and the CSV export. A
unique index on serial is what keeps the find-then-create path from
forking a drone's history across two records.
The schema is applied to the remote PocketBase; the migration is here for
fresh deployments, which the remote does not read.
Verified against a simulated device over the real socket with identity
resolving late: one record from four events, both firmware versions
filled, curated fields intact across re-registration, and a drone deleted
while connected coming back on the next frame.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PilotVault
A platform for drone operations management — remote control, live telemetry, intelligent flight scheduling, route management, and third-party integration — built on top of the DJI Mobile SDK V4.
Brand + design system live in
Design/PilotVault Project logo/ —
Vault Navy #0F1E3D with a single Signal Blue #3D7BF0 accent, Space
Grotesk (structure/display) · Space Mono (data, serials, timestamps, eyebrows),
and the Vector mark of two offset chevrons (flight, lift, parallax). All UI
surfaces implement it with a persisted light/dark toggle (data-*-theme
attribute); the Fly App follows the system theme.
Multiple surfaces sit in front of a shared PocketBase. The API Server is the only component that talks to PocketBase — the Web App and Fly App talk only to the API Server, which is the single gateway. Live device/telemetry state is held in memory by the API Server and fanned out over WebSockets.
┌────────────┐ ┌──────────────────┐ ┌──────────────┐
│ Web App │──/bff─►│ │ │ │
│ (Vue/Go) │ │ API Server │──auth─►│ PocketBase │
├────────────┤ │ (Go) │ │ 10.2.1.10: │
│ Fly App │──/ws──►│ in-mem devices │ │ 8026 │
│ (Flutter) │ └──────────────────┘ └──────────────┘
└────────────┘
Surfaces
| Folder | Stack | Port | Status |
|---|---|---|---|
API Server/ |
Go (+ embedded Vue 3 / Tailwind panel) | :8080 |
✅ Built & verified — gateway, panel, plugin system |
Web App/ |
Go BFF + Vue 3 + Tailwind | :8090 |
✅ Built & verified — control panel |
Fly App/ |
Flutter (Android) + Kotlin DJI MSDK V4 bridge | — | ✅ Built & run on a real device; live telemetry uplink |
Adobe Plugin/ |
— | — | 🚧 Placeholder |
Phone App/ |
— | — | 🚧 Placeholder |
Docker/ · Docker AIO/ |
Docker Compose | :8080 :8090 :8026 |
✅ Combined stack + single all-in-one container |
Data model (PocketBase)
PocketBase provides auth + persistence only; device and telemetry state are
in-memory in the API Server. Schema + seed ship as idempotent migrations in
API Server/pocketbase/pb_migrations/.
users— auth, plusrole(superadmin | admin | user),organizationrelation (nullable), and apreferencesJSON blob.organizations— tenant grouping for users.
Roles: superadmin = global (all orgs/users); admin = scoped to its own
org (manages that org's users, cannot cross orgs); user = no management.
Org-scoping is enforced in the API Server (internal/api/users.go, orgs.go).
User/org management requires a PocketBase superuser service account in
API Server/.env (POCKETBASE_ADMIN_EMAIL/PASSWORD, gitignored); without it,
/api/users and /api/orgs return 503.
Run order
- PocketBase — reachable at
http://10.2.1.10:8026(override withPOCKETBASE_URL). - API Server (
:8080):The embedded, superadmin-only panel is at http://localhost:8080/ (live health, PocketBase connection settings, and the plugins manager).cd "API Server" Copy-Item .env.example .env # set POCKETBASE_URL and POCKETBASE_ADMIN_* cd panel; npm install; npm run build; cd .. # build the embedded panel ./scripts/Run-ApiServer.ps1 - Web App (
:8090):Open http://localhost:8090 and sign in.cd "Web App/web"; npm install; npm run build; cd ../server ./Run-WebApp.ps1 - Fly App — see
Fly App/README.md(install Flutter- JDK, set your DJI App Key in
android/gradle.properties,flutter runon a connected Android device — the DJI SDK does not run on emulators).
- JDK, set your DJI App Key in
Docker
Docker/— combined stack (API Server + Web App) on a shared network:cd Docker; docker compose up --build.Docker AIO/— PocketBase + API Server + Web App in one container:cd "Docker AIO"; docker compose up --build.
Telemetry lifecycle
The Fly App connects on GET /ws/device?id={id} and streams typed events —
registration, connection, battery, telemetry (altitude, lat/lng,
velocity, GPS sats, flight mode…). The API Server merges each into a per-device
DeviceState, appends latitude/longitude to the device's GPS track, and fans
every update out to connected dashboards on /ws/ui as {type:"update", device, event}.
Plugins
The API Server integrates third-party services through a uniform plugin
contract (internal/plugins), managed by a superadmin from the panel. Two kinds
share one interface:
- Built-in — Go connectors compiled into the server (reference example: OpenSky Network live ADS-B flight data). Adding a new one needs a rebuild.
- External — a remote HTTP service registered at runtime, no rebuild;
answers
GET /health,GET /manifest,POST /invoke.
Enable-state and per-plugin config persist to a gitignored plugins.json. See
API Server/internal/plugins/README.md
for the developer guide.
Per-surface docs
- API Server README — full endpoint reference, panel, plugins
- Web App README — BFF proxy, dev/build
- Fly App README — Flutter + DJI MSDK V4 native bridge