What do you do with a fleet of edge AI devices?
One GB10 on a desk is a workstation, and it arrives knowing how to be one. A hundred of them across twelve sites is an estate, and nothing in the box knows how to be that. Nerv’s answer is a fleet manager: one server that installs new devices over the network, manages what is on them, and provisions GPUs and system resources centrally.
One server provisions the estate
The installer is a server you run on a machine you already have, and it provisions every other machine over the network. There is no USB stick and no live image to maintain. A target powers on, netboots a signed UKI over ordinary DHCP and TFTP, and installs itself, either attended through a TUI or unattended from a per-machine record.
The artifact a target netboots is the same artifact class an installed slot boots, so there is no separate live-media build to keep in step with the real system. Any Nerv machine can provision the next one.
Broker
Canary by client.
The server holds several generations and decides which one each client gets. Serve generation N+1 to one machine while the rest stay on N. That is the whole canary discipline, and it costs one field in a client record. It also caches, so installing eight machines fetches each package once.
Live view
N machines, each changing state.
One dashboard shows every target: its hardware identity, the generation it was given, the phase it is in, progress, and the tail of its log. Targets post typed phase events and the server renders them. Piped or over a serial line it degrades to plain streaming lines.
Upgrade
Reinstall and update are one operation.
Netbooting a machine that already runs Nerv does not mean wiping it. It composes into the inactive slot, through the same code path and the same boot-counted rollback as a local update. The rare frightening operation and the routine one are the same operation, so the frightening one never rusts.
Resources
Accelerators assigned, not configured.
axon owns the device and hands out pre-authenticated sockets, and
local and remote are the same path. A fleet’s GPUs become a pool
that work is placed into, not a list of boxes someone has to ssh to
one at a time. axon top answers where a given piece of
work actually ran.
The server issues no commands
Reporting runs one way, from client to server. The server offers a manifest and bits; it never drives a sequence of operations on a machine. A compromised server can serve a bad generation, which is what signing is for, and it cannot reach into a machine that has already booted.
This is a deliberate limit on what a central manager is allowed to be, and it is why the fleet manager does not need to be trusted the way a configuration-management agent has to be.
It will not be the only console in the rack
Nobody operating an estate wants another management plane. The machines that will run this are going into racks that are already managed from somewhere, by platforms that own virtualisation, inventory and lifecycle for everything else on the floor.
So the fleet manager is being built to present its machines, generations and accelerators as objects those platforms can already consume. An operations team should not have to adopt a second console to run these boxes. Integration work with established infrastructure platforms is underway, and we are not naming names yet.
Ship it on hardware you sell
This is the part that tends to surface late, in legal review, after a hardware programme has committed.
GPL-3 section 6 obliges anyone shipping object code inside a user product to hand over whatever is needed to install a modified version. Secure Boot with kernel lockdown is exactly the restriction that triggers it, so a signed, locked-down boot chain and a GPL-3 runtime pull against each other.
Nerv does not manage that tension. It never creates it.
No GPL-3 package is needed to boot a Nerv machine. The
core is MIT, 0BSD, BSD, and Apache, alongside the GPL-2 kernel and
LGPL-2.1 libraries, none of which carry the clause that matters. A Nerv
base can be signed, locked, and shipped without the licence review
turning into a redesign. The GPL-3 software people do want, rsync among
it, stays one dnf5 install away. Installing it is an
operator’s choice and commits the base to nothing.
Owning the whole base is what makes that possible. Nerv builds its own C library, allocator, compiler, init, shell, text tools, and package manager from upstream source. Its licensing is therefore something chosen, not something inherited.
What is running, and what is not
Uniform present tense makes a procurement conversation worse. This is where each piece actually stands.
| Capability | State | Where it stands |
|---|---|---|
| Netboot install over the network, no USB | running | Signed UKI over DHCP and TFTP, attended TUI on the target. |
| Version broker and caching mirror | running | Several generations held; publishing one is dropping a directory. |
| A/B slot updates and rollback | running | btrfs slots, promotion only after a proven boot. |
| Remote GPU execution, unmodified binaries | running | A dispatched kernel has run on a remote A800 and returned results bit-identical to native. |
| Unattended install, live client view, hardware-bound records | building | proxyDHCP, the server dashboard, and TPM-EK manifests. |
| Verified bootstrap | building | Open work, and the gate on the rest of the signing chain. |
| Adopting a machine from a peer rather than a mirror | designed | Specified. Depends on the provenance corpus landing first. |
| Per-peer identity and revocation across a fleet | designed | axon’s shared fleet key, per-peer identity, and revocation are specified and not yet built. Today a multi-machine deployment trusts its network. |
| Presenting the fleet to an external platform | designed | Underway, unannounced. |
Nerv targets NVIDIA GB-series unified-memory parts and nothing else. See Platforms for which, and why the list is short on purpose.