Account

Register a name. Hand over the URL.

An account signs in with an issuer, registers a label, and publishes an encrypted build document. The installer fetches that URL. This page describes the portal. It is not open, and it has no form.

The URL you give the installer: https://ada.build.blunix.io/

Sign in

People use an issuer. The platform is a relying party. It does not run an OAuth server, and it does not keep a password.

  1. Authentik at adsas.id

    The discovery URL is filled in when that issuer is bound. It is not invented on this page, and no client id is stored in the site.

  2. Google

    OpenID Connect at https://accounts.google.com. Authorization code with PKCE. The audience has to be our client id, once that client exists.

  3. GitHub

    GitHub user sign-in uses GitHub's OAuth 2.0 authorization-code endpoints. The same rules: allowlisted issuer, live expiry, matching audience, algorithm allowlist. none is rejected.

A token from any other issuer fails closed. Binding these three is later work. Clicking around this site does not start a login.

The label

One account can hold many labels. Each label is one installer URL and one current ciphertext.

Publish

The browser composes the node document, encrypts it, and uploads ciphertext. The passphrase stays in the browser and on the machine that installs.

  1. The document is the build

    Disk, network, access, the AI pin, and the update channel. The same schema the image accepts. Unknown fields are refused. A field named like key material is refused. A shell script is refused. The check happens before encrypt.

  2. age passphrase mode

    The browser encrypts with the age specification. The passphrase is stretched with scrypt, the way age defines it. There is no second cipher. Debian age decrypts on the machine. The browser build that speaks that format is not written.

  3. The server stores ciphertext

    The passphrase is not uploaded, not hashed, and not logged. A lost passphrase means that config is gone. Publish again and create a new one. The account can see the size, the time, and the sha256 of the ciphertext. It cannot read the document back.

  4. Hand the URL to the installer

    The machine fetches https://ada.build.blunix.io/ over TLS, asks for the passphrase with echo off, and decrypts locally. The sequence on the box is the install page.

Publishing again replaces the file the next install fetches. An enrolled machine takes a later document at its apply window, through the service. That service is not running. A new image still follows the log.