Raspberry Pi: update it, key it, lock it
420-302-VA · WEEK 3 · FALL 2026

Stage 6 of 6 · Logistics, evidence, demonstration

A1 demo & hand-in

Today has a graded moment: the Assignment 1 demonstration (10 %). The security work feeds straight into it, because you push your last commits over the SSH key you just made. Here is the clock, what the teacher checks, and what goes on Omnivox.

The two hours

MinutesYou doCheckpoint before moving on
0–10Wire the station (Week 2 order, power last), boot, log in.Desktop or prompt shows your username and hostname.
10–30Update cycle; install ufw; reboot if the kernel moved. Read the key idea while apt runs.apt full-upgrade finished; get_throttled is 0x0.
30–55SSH keys: lab PC → Pi, then Pi → GitHub; switch the A1 remote to the SSH form.Passwordless ssh to the Pi; "Hi username!" from GitHub.
55–75UFW: defaults, allow 22 and 5900, enable, save the status output.SSH from the lab PC still works with the firewall active.
75–90VNC: enable, connect from the lab PC, take the screenshot.Desktop visible in the viewer.
75–110Rolling A1 demos: the teacher passes station by station while you finish the stages.Demo done and noted by the teacher.
110–120Assemble and upload the evidence, answer the exit ticket, clean shutdown, pack.Drive returned; station restored.

Pair rule, as in Week 2: swap the operator and verifier roles at the SSH-keys stage. Both members must generate a key and both must have pushed commits before the demo.

Assignment 1 demo: what the teacher checks

From the outline: Assignment 1 (Git and GitHub, 10 %) is demonstrated in class today; work not demonstrated is marked late. Have this ready before you call the teacher over:

AI tools and A1

Per the outline's policy: generative AI may help you learn (explain an error, clarify a command), but what you submit must be understood, tested and documented by you, and any use is acknowledged in your reflection log. The live-change part of the demo is where "understood" gets checked.

What to hand in

Create the evidence folder on the Pi and fill it as you go; bring it to the lab PC with scp exactly as in Week 2's practice, then upload to Omnivox:

$ mkdir -p ~/iot/week3/evidence && cd ~/iot/week3/evidence
FileCommand that produced itShows that
upgrade.txtsudo apt update 2>&1 | tail -n 3 > upgrade.txt after upgradingCatalogue fresh; zero (or few) upgrades pending
key-fingerprints.txtssh-keygen -lf ~/.ssh/id_ed25519.pub > key-fingerprints.txtThe Pi's key exists (fingerprints are safe to share; private keys never appear in evidence)
github-auth.txtssh -T git@github.com 2>&1 | head -n 1 > github-auth.txt"Hi username!": key-based GitHub authentication works
ufw.txtsudo ufw status verbose > ufw.txtFirewall active, deny incoming, 22 and 5900 allowed
vnc.pngScreenshot of RealVNC Viewer showing the Pi desktopRemote desktop works through the firewall
station.txttyped in nanoStation number, Pi model, boot-drive label, both names, exit-ticket answers if asked

Like Week 2, this hand-in counts as completion of in-class work and is the base the Week 4 lab builds on. The repository itself is graded through the demo and its history.

Exit ticket

Answer without looking at the hub; write the answers at the end of station.txt if the teacher asks for them.

  1. Which file of a key pair may travel, and where does it live on the Pi for logins?
  2. Why did allow ssh have to come before ufw enable?
  3. What did apt update change, and what did apt full-upgrade change?
  4. Your push to GitHub asked for no password. What exactly authenticated you?
  5. Name one task where VNC beats SSH, and one where SSH beats VNC.

Packing up

Homework and next week

This week's homework (2 h)

Finish, read, reflect

Finish any stage not completed in class (the pages stand alone). Skim the official remote-access documentation for what SSH can also do (scp you know; look at port forwarding). Note in your journal what you would tell a Week 2 student about passwords versus keys; the midterm reflection log (Week 7) starts from notes like these.

Week 4 · September 21

Python environment and GPIO

First circuit: a virtual environment, the gpiozero library, an LED and a button on the breadboard, driven over SSH. Bring the breadboard kit: breadboard, LEDs, resistors, jumper wires. Re-read the 40-pin header and the 3.3 V rules; they stop being theory next Monday.