Fleet Time Synchronisation (chrony)
Project information
- Category: Web
- Client: INSTAR Deutschland GmbH (Waletech) Shenzhen, China
- Project date: 01 Feb, 2020
- Project URL: chrony.tuxfamily.org
The problem: every alarm, detection event, and log line across the fleet and the cloud backend needed a trustworthy timestamp — and "the two cameras disagree by 40 seconds" is an un-debuggable system.
What I did: Deployed chrony (NTP over NTS/TLS encryption + authentication) as a fleet-wide service behind a hardened nginx ingress: TLS 1.3 with OCSP stapling, HSTS, and a stream-mode L4 proxy that UDP-forwards NTP (123) and NTS (4460) to the chrony backend, with service-discovery from Consul templating the upstreams so the proxy follows the service if it moves. Let's Encrypt is provisioned and renewed by a separate Nomad batch job. Cameras, servers, and the AI inference pipeline all sync to a single time source.
That's what makes cross-device alarm correlation, log forensics, and the customer-facing event timeline actually reliable — and what keeps Elasticsearch honest when someone asks "what happened on my camera at 14:32?"
The payoff: it now runs all of INSTAR's cloud infra and is the default time-sync option in every IoT device we sell.