Display vs. control
A core design rule: only auditable instruments can affect safety. Cameras and video streams that exist for you to look at are explicitly forbidden from feeding the supervisor.
Why
Two reasons:
Camera analysis is fuzzy. "Are those clouds in the all-sky frame?" is a question with no defensible single answer. Different ML models, different thresholds, different lighting conditions. If the supervisor relied on a fuzzy signal, every false-positive would either close the dome unnecessarily or — worse — keep it open during a real cloud bank.
Auditability matters. When a roof unexpectedly closes at 2am, you need a clean answer to "why?". Solo reported UNSAFE: rain detected at 02:14:33 is a clean answer. The AI thought clouds in frame 4218 looked >0.7 dense is not.
Display sources
These are display-only. They give you eyes on the sky and the observatory, but they never feed the supervisor:
- All-sky camera — polls a snapshot URL (e.g.
http://allsky.local/current.jpg) on a configurable interval and shows you the latest frame. A local self-signed HTTPS all-sky (a Pi on your LAN) is handled by the "accept self-signed certificate" option, scoped to that one URL. - CCTV — one or more cameras watching the dome and the gear. Each camera runs as a full live stream (RTSP transcoded by ffmpeg) when it can, and falls back to periodic snapshots otherwise; a misconfigured camera just shows as offline in the UI.
- Anything we add later in the same vein.
Both publish their frames on the bus (allsky.snapshot, cctv.snapshot) purely so the dashboard can show them live. Nothing subscribes to those events to make a decision, and by default they are excluded from the audit log — they fire many times a second and would otherwise drown the record while adding nothing you'd ever need to answer "why did the roof move?". (See the All-sky and CCTV topic for how to set these up.)
Control sources
These can affect the supervisor verdict:
- Solo (AAG CloudWatcher) — the primary safety source. Its own clouds / wind / rain / humidity / light / pressure verdicts are what the supervisor arbitrates on.
- Future: dedicated weather stations, rain sensors, an all-sky in advisory mode, a hardware e-stop / lockout.
Note that Manual Mode (Settings → Safety → uncheck "Safety monitoring enabled") is not a control source — it's the master switch that turns monitoring off entirely for a backyard or portable rig, so the verdict reads DISABLED and nothing is gated. It doesn't feed the supervisor a "safe" signal; it stands the supervisor down and hands responsibility to the present operator. See the Safety supervisor topic.
The bright line stays. A display source can never be "actionable unsafe" — it cannot open, close, or hold the roof. If a feature can affect safety, it gets reviewed for auditability and reliability before going in.