Mandatory Update (before first flight)¶
Do not fly before the mandatory update
Your aircraft and GCS ship at a baseline version. Before you fly for the first time, you must run this update. It brings both ends to a known-good, mutually-compatible release. Flying before the update can leave the command link or navigation in an unsupported state.
This is a hard pre-first-flight step, and it is designed to be safe. The update verifies its download, health-checks the result, and automatically rolls back if anything goes wrong — so a failed update cannot leave your aircraft in a broken state.
Why it is mandatory¶
Your aircraft and GCS are shipped at a known baseline so they can be provisioned and bound out of the box. The mandatory update then moves both ends to the current, supported release at the same time. This matters because:
- The command-link transport and the navigation pipeline are tuned together — a mismatched aircraft and GCS can degrade the link or the position aiding sent to your autopilot.
- The update is the supported way to pick up flight-safety fixes that landed after your hardware was built.
- It runs entirely over your own network and the satellite link — no cloud account or external service is required for the aircraft to update itself.
Before you start¶
- The aircraft is powered and has internet through its Starlink connection.
- The aircraft is reachable from a browser (over the GCS, once bound, or directly on its local network).
- The aircraft is on the ground or bench and disarmed, with propellers removed or the throttle safed. The update refuses to start while the airframe reads as armed — disarm before updating.
- You are not about to fly — allow several minutes for the update to complete.
- Leave the aircraft powered for the whole update; do not power-cycle it mid-update.
Update only on a safed, disarmed airframe
The update refuses to start while the airframe reads armed (the request
is rejected with a 423 response). This is a safety interlock — an update
restarts the aircraft, so it must not run on an armed vehicle. Perform the
update on a ground or bench airframe with propellers removed or the
throttle safed and the vehicle disarmed, then start the update again.
Run the update¶
The normal way to update is from the aircraft's own web app. A command-line fallback exists for depot and field-service use.
- Open the aircraft web UI in your browser. While the aircraft is on the shipped baseline, the update control is presented at the top of the app (see What "done" looks like below).
- Start the aircraft update.
- From here it is fully automatic — see What happens during the update.
No credential or sign-in is needed to update the aircraft — just click update.
The aircraft refuses with a 423 response if the airframe reads armed (see
the safety interlock above); update on a disarmed, safed airframe.
What happens during the update¶
Once you start it, the aircraft updates itself with no further action from you:
- it finds the newest release in the public release index — anonymously, with no account or token required — and downloads it;
- it verifies the download's signature and checksum before installing anything (a bad or tampered download is rejected, not applied);
- it installs the new version alongside the old one and swaps over to it, then runs a health check (several minutes) to confirm the aircraft comes back up correctly;
- if that health check does not pass, it automatically rolls back to the previous working version (within about five minutes) and comes back online on it.
The aircraft restarts itself as part of the update — this is expected. Wait for it to report the update complete and come back online. A full update, including an automatic rollback if one is needed, can take several minutes.
Update the GCS application if it prompts you, so both ends are on the same release.
Keep the aircraft powered
The update finishes on the aircraft itself, even across the restart. Leave it powered and connected until the app shows the update is complete.
Confirm it succeeded¶
After the aircraft comes back online, check the GCS dashboard:
- The aircraft shows online at the new version.
- The bridge link is healthy (transport state nominal).
- Navigation reports a position and the quality gate is satisfied.
- The aircraft and GCS report compatible versions — the app flags a mismatch if one remains.
The aircraft and GCS web UIs mirror each other once bound, so you can confirm the new version from either end.
What "done" looks like¶
While your aircraft is still on the shipped baseline, it reports that a mandatory update is still required, and a non-dismissible "update required" banner shows at the top of the app. It cannot be dismissed — it is the reminder that this aircraft has not yet had its mandatory update.
When the update succeeds, the aircraft reports that it is up to date and flight-ready, and the banner clears on its own — you do nothing. A cleared banner is the confirmation that the aircraft is on the supported release and ready for the pre-flight checks. The banner also mirrors to the GCS view once the aircraft is bound, so you see the same state from either end.
The banner is your single source of truth
Do not look for a separate "update done" toggle. The non-dismissible banner being gone is the done state. If it is still showing, the mandatory update has not completed yet — do not fly.
If the update fails¶
You cannot brick the aircraft with an update. The system is built to fail safe:
- If the new version does not pass its health check, the aircraft automatically rolls back to the last working version and comes back online on it — your aircraft is never left half-updated.
- Retry the update once the aircraft is back online and reachable.
- If it fails again, see Support & FAQ before flying.
Never fly on a failed or partial update
If the update did not report success on both the aircraft and the GCS, do not fly. Resolve it first, or contact support.