helium/router
52.4
Adequate · 2 October 2026
23.8k
lines of production code
Erlang
primary language
2
measurements over time
What this system is
This system is a Helium LoRa Network Server (LNS) Router, an Erlang-based backend that manages LoRaWAN device lifecycle, packet routing, and state channels. It integrates with the Helium blockchain for data credit tracking and location services, while exposing device data through gRPC, WebSocket, and various cloud channel integrations like Azure IoT and HTTP. The platform includes comprehensive operational tooling for monitoring, CLI management, and automated decoding of sensor payloads.
How it got here
2019–2020 — Initial Helium Router release and core feature development
13 changes.
This period marks the initial release of the Helium LoRa Network Server Router, establishing the core Erlang codebase for device management, state channels, and blockchain integration. It involved building essential subsystems for LoRaWAN MAC command handling, multi-channel data routing (including Azure and HTTP), and decoder infrastructure, alongside comprehensive test coverage and operational tooling.
2021–2022 — gRPC integration and CLI tooling
4 changes.
This period focused on establishing a new gRPC router service architecture to synchronize state with the IoT Config Service, introducing workers for device and gateway reconciliation. Concurrently, the team expanded operational capabilities by adding CLI management scripts for devices and organizations, alongside utilities for block monitoring and log archival.
Features
Added utility scripts for log saving and block monitoring
Two new shell scripts have been added to the repository to assist with operational tasks. The \scripts/monitor\_blocks.sh\ script continuously compares the local router's block height against the public chain head height, reporting the lag in blocks at a configurable interval (defaulting to 30 seconds). The \scripts/save\_logs.sh\ script copies log files from \/var/data/log/\ into a timestamped, slugified directory to facilitate archival and debugging.
scripts · high confidence
Automated build script for LoRaMac-node library
Added a new compile.sh script that automates the build process for the LoRaMac-node library. The script clones the repository at a specific commit, then builds and copies the LoRaMac-classA binary for US915, EU868, AS923, and CN470 regions into the priv directory.
_c\src · high confidence
Initial release of the Helium LoRa Network Server (LNS) Router
This change introduces the initial codebase for the Helium Router, a LoRa Network Server backend. It provides the core Erlang application logic, including device management, state channel handling, and integration with the Helium blockchain. The release includes comprehensive operational tooling: Dockerfiles for building and running the router locally or in CI, docker-compose configurations for deploying with Prometheus and Node Exporter, and a Grafana dashboard for monitoring metrics. Configuration is managed via a new .env-template file exposing settings for NAT, state channels, console endpoints, and device queue limits. The build system has been standardized using Rebar3 with specific profiles for mainnet and testnet, and the project includes a CONTRIBUTING guide and an expanded README detailing CLI commands for device and organization management.
(repo-wide) · high confidence
Initial router configuration and gRPC code generation setup
This change introduces the foundational configuration files for the router service, including \sys.config\ (with environment variable placeholders for deployment), \sys.config.src\, \test.config\, and \testnet.config.src\. It also adds \grpc\_gen.config\ to define the protocol buffer generation rules for router, packet router, and IoT config services, and \vm.args\ to set Erlang runtime parameters such as process limits and garbage collection tuning.
config · high confidence
Introduce dedicated Console API and Data Credit tracking subsystems
The router now includes a new \router\_console\_api\ module to handle API interactions with the Console, featuring caching for device and organization lookups, and a new \router\_console\_dc\_tracker\ module to manage Data Credit balances, including refill, charge, and unfunded organization tracking. These components are managed by a new \router\_console\_sup\ supervisor and communicate with the Console via a new \router\_console\_ws\_handler\ and \router\_console\_ws\_worker\ for real-time WebSocket events, such as device queue clearing and downlink commands.
src/apis · high confidence
Introduce new Router CLI commands for device, organization, and migration management
The CLI now includes a comprehensive set of new commands for managing router state and device data. Users can inspect and manage devices via \device\ (listing, looking up by EUI, tracing, and queueing downlinks), view router status with \info\ (block height, name, block age, device/hotspot stats), and manage organization data credits using \organization\ (info, update, unfunded). Additionally, a \migration\ command allows syncing EUIs and Session Key Filters to the config service, and a \filter\ command provides tools to update, rebalance, report on, and migrate XOR filters.
src/cli · high confidence
Introduction of LoRaWAN network schema and router device state definitions
This change introduces a comprehensive set of Erlang record definitions and type specifications that establish the data model for the LoRaWAN network and router components. The new include files define the structure for network configuration (including region and delay settings), device profiles, and gateway details. It introduces a versioned device state system (device\_v1 through device\_v7) to manage device credentials, frame counters, and metadata, alongside specific records for handling Adaptive Data Rate (ADR) offers and packets. Additionally, it defines the schema for join and frame caches, downlink parameters, and a suite of Prometheus metrics for monitoring router performance and device status.
include · high confidence
New Azure IoT Hub and IoT Central integrations, plus HTTP template and security enhancements
Users can now connect device data to Azure IoT Hub and Azure IoT Central via new channel handlers (router\_iot\_hub\_channel, router\_iot\_central\_channel) and their connection modules, which manage device provisioning, SAS token generation, and MQTT communication. HTTP channel integrations now support Mustache templating for dynamic URL parameters, headers, and body content, including support for indexing into lists and built-in data transformation functions (e.g., base64/hex conversions). To improve security, HTTP channel requests now validate URLs against private/reserved IP ranges (e.g., 127.0.0.0/8, 10.0.0.0/8, link-local) and enforce a 2-second timeout on requests.
src/channels · high confidence
New CLI commands for device, filter, info, migration, and organization management
Added new shell scripts in the \scripts/extensions\ directory that expose CLI commands for managing devices, filters, system info, migrations, and organizations. These scripts act as wrappers that format user arguments into a specific JSON-RPC payload and send them to the \router\_console\ via \relx\_nodetool\. Notably, the migration command automatically extends the RPC timeout to 900 seconds to accommodate longer-running operations, while other commands use the default timeout.
scripts/extensions · high confidence
New decoder infrastructure with built-in Cayenne and Browan Object Locator support
The system now includes a new decoder framework that manages custom JavaScript decoders via a dedicated supervisor and worker pool, featuring automatic context recovery and execution timeouts to prevent crashes. Out of the box, it supports the Cayenne Low Power Payload (LPP) protocol for standard sensor data and a new Browan Object Locator decoder that parses GPS, battery, and configuration data from ports 136 and 204.
src/decoders · high confidence
New device routing and management subsystem
The \src/device\ area now implements a complete device lifecycle and routing pipeline. This includes a new \router\_device\ record (v7) for device state, an ETS-backed \router\_device\_cache\ for fast lookups, and a \router\_device\_devaddr\ gen\_server for allocating and reconciling DevAddrs. Packet routing is handled by \router\_device\_routing\, which uses a Bloom filter for initial offer checks and a multibuy ETS table to limit packet counts. Device communication is managed by \router\_device\_worker\ (handling joins, frames, and downlinks) and \router\_device\_channels\_worker\ (managing state channels and channel refreshes). A \router\_devices\_sup\ supervisor orchestrates these workers, and \router\_device\_stats\ tracks offer and packet metrics.
src/device · high confidence
New gRPC router service and IoT Config Service (ICS) integration workers
This change introduces a new gRPC server architecture and a suite of workers to synchronize router state with the IoT Config Service. The \helium\_router\_service\ and \helium\_packet\_service\ modules handle incoming gRPC streams, including packet routing with idle timeout management and signature verification. New workers (\router\_ics\_eui\_worker\, \router\_ics\_skf\_worker\, \router\_ics\_gateway\_location\_worker\) manage reconciliation of device EUIs, Session Key Filters (SKFs), and gateway locations via gRPC client streams. Supporting infrastructure includes \router\_grpc\_server\_worker\ and \router\_grpc\_client\_worker\ for managing gRPC channels and services, and various handler modules (\router\ics\\*\_handler\) to process streaming responses from the config service.
src/grpc · high confidence
New router metrics endpoint and Prometheus integration
The system now exposes a dedicated metrics endpoint at /metrics for Prometheus scraping, implemented via a new gen\_server-based router\_metrics module that tracks routing packet latencies, console API performance, and WebSocket state. Additionally, a /devaddr endpoint is introduced to export device location and address data in JSON or CSV formats, supporting visualization tools like Kepler.gl by pulling hotspot location information from the blockchain.
src/metrics · high confidence
Router introduces new core modules for blockchain, state channels, and device management
The router application now includes a comprehensive set of new Erlang modules to handle core networking and device lifecycle tasks. \router\_blockchain\ provides a unified interface for blockchain interactions, including DC calculation, hotspot location retrieval, and state channel fee estimation. \router\_sc\_worker\ manages the lifecycle of state channels, ensuring two are kept active and handling expiration logic. \router\_xor\_filter\_worker\ and \router\_db\ introduce persistent storage via RocksDB and logic for managing XOR filters for device routing. \router\_discovery\ and \router\_handler\ implement the libp2p stream handlers for device discovery and packet routing, while \router\_utils\ centralizes event generation for the console. The application startup (\router\_sup\) has been expanded to initialize these new workers, ETS tables, and caches, and \router.app.src\ has been updated to include dependencies like \helium\_proto\, \blockchain\, and \rocksdb\.
src · high confidence
Behavioural changes
1 commit (0 fixes) modifying priv
A change to existing behaviour in priv — 1 commit, 2 files.
priv · medium confidence · unverified
New LoRaWAN MAC command handling and RxDelay state management
This change introduces dedicated modules for LoRaWAN MAC command processing and receive delay (RxDelay) management. The new \lorawan\_mac\_commands\ module handles the parsing and generation of MAC frame options (FOpts), including support for Link Check, Device Time, Adaptive Data Rate (ADR), and RX Window settings, ensuring proper state updates for device parameters like RSSI/LSNR quality statistics. The new \lorawan\_rxdelay\ module implements the state machine for managing RxDelay values, allowing the system to track requested changes from the Console, negotiate the delay via \rx\_timing\_setup\_req\/\ans\ commands, and correctly handle the implicit ACK behavior defined in the LoRaWAN specification for Join Accept frames. These modules replace ad-hoc logic with a structured approach to MAC command handling and timing configuration.
src/lora · high confidence
Test coverage
Added test infrastructure and suites for router channel integrations
Added a new \blockchain\_test\_utils\ module to facilitate test blockchain initialization and block creation, along with a \console\_test.hrl\ header defining mock configurations for HTTP, MQTT, AWS, Azure IoT Hub, Azure IoT Central, decoder, and console channels. New Common Test suites were introduced to verify router behavior across these integrations: \router\_SUITE\ covers core LoRaWAN MAC commands and join procedures; \router\_channel\_http\_SUITE\ validates HTTP uplink/downlink flows; \router\_channel\_aws\_SUITE\ tests AWS IoT Core connectivity; \router\_channel\_iot\_hub\_SUITE\ and \router\_channel\_iot\_central\_SUITE\ verify Azure IoT integrations; and \router\_channel\_console\_SUITE\ ensures console-specific channel handling and inactive device scenarios.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 45 → 52 (+7.2)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 87 → 87 (+0.0)
- Architecture 100 → 84 (-16.3)
- Maturity 69 → 74 (+4.8)
- Readiness 59 → 51 (-7.7)
- Security 30 → 51 (+20.8)
- Event-Driven 45 → 45 (+0.0)
Resolved (2)
- Coverage not measured — no coverage collector is wired up
- Off-boarding risk: anonymized user #1
New (21)
- Floating source dependency: bbmustache
- Floating source dependency: clique
- Floating source dependency: e2qc
- Floating source dependency: erlang_lorawan
- Floating source dependency: erlang_v8
- Floating source dependency: grpcbox
- Floating source dependency: helium_proto
- Floating source dependency: httpc_aws
- Floating source dependency: iso8601
- Floating source dependency: router_utils
- High CVE: [GHSA redacted] (rebar.lock)
- High CVE: [GHSA redacted] (rebar.lock)
- Medium CVE: [GHSA redacted] (rebar.lock)
- Off-boarding risk: anonymized user #1
- Outdated: erl_cidr
- Outdated: hackney
- Outdated: meck
- Outdated: observer_cli
- Outdated: prometheus
- Outdated: websocket_client
- …and 1 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
helium/router was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0cc7bcabcd26eef0b9d6b67df8b17c5157c70f5c — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.