Do
These are the things Kawa is allowed to carry out, and they are the only ones. Each goes down a channel the shops already use — the job queue a manager's panel writes to, or a script that already lives on the server. There is deliberately no box here that runs whatever is typed into it: this page answers on plain HTTP, and such a box would be a root shell on the internet with five tills behind it.
Morning round safe
Before a shop opens: ask every screen how it is, take its picture, and check the menu it is holding. Changes nothing.
Look at one screen safe
A photograph of what a customer is looking at, taken by the machine itself.
Put the ordering app back on a screen touches one screen
For a machine that is on and talking but showing a Windows desktop: stop the app if it is stuck, start it again, then prove it with a picture.
Put the app back on a screen safe
Something is covering a screen — Android's own "isn't responding" box after a half-finished update, a settings page somebody opened, a dialog nobody can reach. This takes it off and brings the ordering app back to the front, from here, without anybody walking to the screen. It changes nothing on the machine: no reboot, no settings, no orders touched.
Restart a screen takes one screen down for a minute or two
Switches an Android screen off and on again — the kitchen displays, the customer boards, the menu boards, the self-order kiosks. It is the thing to try when a screen has stopped answering the hub, or when adb keeps dropping half way through an install: a screen that has been up for weeks comes back and the next install goes through first time. Nothing is wiped and no setting changes. The screen is blank while it boots, so a kiosk somebody is ordering on loses that order.
Update the app on one screen takes one screen down for about a minute
Sends the current build to one machine and restarts it into the new one. One machine at a time on purpose: a kiosk that has not re-attached to the hub takes its order number from the cloud, does not print, and does not reach the customer board.
Update an Android screen takes one screen down for about a minute
Puts the current build on a kitchen display or customer board, over the shop's own network, from the hub. Windows screens use 'app.update' — this is the other half of the estate, which until now could only be updated by somebody standing in front of it with a cable.
Update the hub the shop cannot print for a few seconds
The hub fetches its own new code and hands over to it — and then, because it reports that handover without doing it, the handover is finished here as well. Reads the code date back afterwards rather than trusting either step.
Hand the menu round safe
The hub takes the current menu from the cloud and gives it to every screen attached to it, and says which ones confirmed.
Test a printer prints a slip
Sends a test slip to one printer socket in the shop.
Sweep the shop network safe
The hub looks over the shop's own network and reports the machines and printers answering on it. This is how a newly plugged-in printer or screen becomes visible.
Take Windows out of the customer's reach restarts the Windows shell on each screen, not the ordering app
Turns off the Windows gestures a customer can reach from inside the ordering app: the right-edge swipe that opens the Action Centre over an order, and the long press that offers to move the app to another display. Reads every screen first, then sets whatever is not already set. Safe to run again.
Take a machine on and give it a job installs on a new machine
Sends the current build to a machine that has been let in, starts it, and creates its record so it knows which shop it belongs to and what it is for. Use it after 'Take a new machine on' has shown the machine knocking and you have let it in.
Which build would go out safe
The build a machine would receive if it were updated right now, and when it arrived.
Back everything up now safe
Dumps every database on every server, opens each archive to prove it is readable, and puts a copy on Nextcloud. Takes the things no repository holds too — the .env files, the TLS keys, the enrolment register — sealed with AES-256 before they leave.
Back up one system now safe
The same, for a single system — the tills before a risky change, say, rather than waiting for tonight.
Learn the projects again safe
Pulls every project's repository, rereads its documents, reads its servers, and rewrites what Kawa knows. This happens by itself at 04:20 every morning; press it when you have just written something down and do not want to wait.
Bring one shop fully up to date each screen is down for about a minute, in turn; the shop cannot print for a few seconds when the hub swaps
Everything a shop runs, in the order that does not break it: check the build against the repository first, then the screens one at a time, then the hub, then the menu. Reads each one back rather than trusting that it worked.
Install an app on an Android screen change
Put a build on an Android screen. The silent path needs Kawa to OWN the screen (device-owner); otherwise it is the shop's Windows hub over adb, or — where neither exists — the app updating itself.