Connecting to Your TEMPEST CubeSat
The TEMPEST image ships pre-provisioned: instead of joining an external wifi
network, each Pi Zero W broadcasts its own WiFi Access Point that workshop
attendees connect to directly. For a fleet of 25 units, you'll see
TEMPEST-1 through TEMPEST-25 advertised on the air — one SSID per
satellite, matching its hostname.
Connecting from Your Laptop
- Open your laptop's wifi settings.
- Find the SSID matching the TEMPEST unit you want to use (e.g.
TEMPEST-3). - Join using the shared workshop key:
Hack Space(default — your instructor may have rotated it). - NetworkManager on the Pi runs DHCP + NAT in
sharedmode, so your laptop automatically picks up a lease in the10.42.0.0/24range. - SSH into the satellite at its AP gateway address:
bash ssh tempest@10.42.0.1Default SSH credentials:tempest/tempest. Note that these are not the WiFi key — the AP password (Hack Space) gets you onto the network, the login above gets you a shell.
The Pi Zero W has a single radio, so each TEMPEST is its own isolated network — you can only be connected to one satellite at a time.
Rotating the AP Password
Once SSH'd in, change the PSK with:
sudo nmcli con modify tempest-ap wifi-sec.psk "new-password-here"
sudo nmcli con down tempest-ap && sudo nmcli con up tempest-ap
The down/up cycle is required — modifying the connection alone does not push the new key to the running AP. Every connected client (including your current SSH session) drops and must reconnect with the new key.
To check what the current PSK is set to (run as root for -s):
sudo nmcli -s con show tempest-ap | grep 802-11-wireless-security.psk:
Querying the AP Over Radio
If the satellite is in radio range but you can't see its SSID for any reason, the ground station can ask the FSW directly:
WIFI_INFO
The satellite responds with a WIFI telemetry packet containing the active
SSID (32 bytes) and IPv4 address (15 bytes). See
Command Protocol and the
Telemetry Reference.
Imaging a Fresh microSD Card
If you're setting up a new TEMPEST from scratch (e.g. replacing a damaged SD
card or upgrading the image), use Raspberry Pi Imager:
- Download and install Raspberry Pi Imager for your OS.
- Download the TEMPEST image that matches your OBC — pick the variant for the
Pi Zero model in your unit:
- TEMPEST v1 (Pi Zero W, deployed before 2025-01-01):
TEMPESTv1-2.0.img.gz
—
SHA256: e54cd213f92620a667ebb81847de100791ffc617d98a7f76770968632c304b58 - TEMPEST v2 (Pi Zero 2W, deployed after 2025-02-01):
TempestV2-2.0.img.gz
—
SHA256: 67cca06f24f098bfa778dc5b13c7e40fffa8018e986cd3c7a62aab77afad22b5
- TEMPEST v1 (Pi Zero W, deployed before 2025-01-01):
TEMPESTv1-2.0.img.gz
—
- Take the microSD card out of TEMPEST by removing the four T8 screws on the X+ Solar Panel (the panel to your left when facing the RBF pin / charging port).
-
In
Raspberry Pi Imager, chooseCHOOSE OS→Use customand select the downloaded.img.gzfile (Imager decompresses it on the fly), then choose your microSD card underCHOOSE STORAGE.

-
Click
NEXT. When Imager asks whether to apply OS customization, chooseNO— the v2.0 images ship fully provisioned (hostname, AP, SSH, user, and FSW) and don't need any Imager-side settings. ConfirmYESto overwrite the card. - Wait for
Raspberry Pi Imagerto write and verify the image. - Eject the microSD card, reinstall it in the Pi Zero, and power the satellite up. The Pi will shut down after ~30 seconds on first boot — this is expected. Insert and remove the RBF pin to reboot it.
- After a few minutes the AP will be live. Look for the
tempest-apSSID (matching the unit's hostname, e.g.TEMPEST-3) from your laptop and follow the Connecting from Your Laptop steps above.
Recovering an Unreachable Unit
If a satellite's AP is misconfigured or you've forgotten the PSK and can't SSH in:
- Power the Pi off, pull the microSD card, and mount it on your laptop.
- Edit
/etc/NetworkManager/system-connections/tempest-ap.nmconnection— adjust thessidorpskfield directly. - Reinsert the card and boot the Pi.
Alternatively, with physical access to the Pi (USB OTG keyboard + a USB→HDMI
adapter), log in directly on the console and run the nmcli con modify
commands from the Rotating the AP Password
section above.