Fleet Time Synchronisation (chrony)

NTS | Secure Timeserver

Project information

  • Category: Web
  • Client: INSTAR Deutschland GmbH (Waletech) Shenzhen, China
  • Project date: 01 Feb, 2020
  • Project URL: chrony.tuxfamily.org

The problem: every alarm, detection event, and log line across the fleet and the cloud backend needed a trustworthy timestamp — and "the two cameras disagree by 40 seconds" is an un-debuggable system.

What I did: Deployed chrony (NTP over NTS/TLS encryption + authentication) as a fleet-wide service behind a hardened nginx ingress: TLS 1.3 with OCSP stapling, HSTS, and a stream-mode L4 proxy that UDP-forwards NTP (123) and NTS (4460) to the chrony backend, with service-discovery from Consul templating the upstreams so the proxy follows the service if it moves. Let's Encrypt is provisioned and renewed by a separate Nomad batch job. Cameras, servers, and the AI inference pipeline all sync to a single time source.

That's what makes cross-device alarm correlation, log forensics, and the customer-facing event timeline actually reliable — and what keeps Elasticsearch honest when someone asks "what happened on my camera at 14:32?"

The payoff: it now runs all of INSTAR's cloud infra and is the default time-sync option in every IoT device we sell.

Designed with BootstrapMade