Account
Register a name. Hand over the URL.
An account signs in with an issuer, registers a label, and publishes an encrypted build document. The installer fetches that URL. This page describes the portal. It is not open, and it has no form.
Sign in
People use an issuer. The platform is a relying party. It does not run an OAuth server, and it does not keep a password.
-
Authentik at adsas.id
The discovery URL is filled in when that issuer is bound. It is not invented on this page, and no client id is stored in the site.
-
Google
OpenID Connect at https://accounts.google.com. Authorization code with PKCE. The audience has to be our client id, once that client exists.
-
GitHub
GitHub user sign-in uses GitHub's OAuth 2.0 authorization-code endpoints. The same rules: allowlisted issuer, live expiry, matching audience, algorithm allowlist.
noneis rejected.
A token from any other issuer fails closed. Binding these three is later work. Clicking around this site does not start a login.
The label
One account can hold many labels. Each label is one installer URL and one current ciphertext.
- Shape. One ASCII DNS label. The assumption is a letter, then letters, digits, or hyphens, up to 32 characters, no punycode. Reserved names stay blocked: www, api, updates, log, mail. Say if a userid needs other characters.
- Empty until you publish. GET / is a 404 until ciphertext exists. The installer applies nothing.
- Guessable on purpose, when the label is public. You chose a name you can hand to someone. Anyone who can guess a public label can download the ciphertext. They still need the passphrase. A bearer on that anonymous fetch would be a second secret. This draft does not add one.
- Visibility. A public label serves the ciphertext to anyone who can say the name. That is the spoken install. An enrolled label serves it only to a machine key bound to that profile. The service design defaults new profiles to enrolled. Neither mode is live.
- Lookalikes. Labels that mimic another label are not rejected yet. That check is still open.
Publish
The browser composes the node document, encrypts it, and uploads ciphertext. The passphrase stays in the browser and on the machine that installs.
-
The document is the build
Disk, network, access, the AI pin, and the update channel. The same schema the image accepts. Unknown fields are refused. A field named like key material is refused. A shell script is refused. The check happens before encrypt.
-
age passphrase mode
The browser encrypts with the age specification. The passphrase is stretched with scrypt, the way age defines it. There is no second cipher. Debian
agedecrypts on the machine. The browser build that speaks that format is not written. -
The server stores ciphertext
The passphrase is not uploaded, not hashed, and not logged. A lost passphrase means that config is gone. Publish again and create a new one. The account can see the size, the time, and the sha256 of the ciphertext. It cannot read the document back.
-
Hand the URL to the installer
The machine fetches https://ada.build.blunix.io/ over TLS, asks for the passphrase with echo off, and decrypts locally. The sequence on the box is the install page.
Publishing again replaces the file the next install fetches. An enrolled machine takes a later document at its apply window, through the service. That service is not running. A new image still follows the log.