Install
Two prompts, then it builds.
An account gets a hostname. That host serves an encrypted build document. The machine downloads the file, decrypts it locally, and applies it. The passphrase stays on the machine that encrypts and the machine that decrypts.
On the site
This half is specified on the account page. This site has no account form, and it does not submit a passphrase.
-
Sign in
Authentik at adsas.id, Google, or GitHub. There is no password stored here. The build passphrase is a second secret, chosen later, in the browser.
-
Register a label
You pick the name. The installer URL is https://ada.build.blunix.io/. You hand that URL to the person or the script that boots the machine. An earlier draft used a numbered host so the name would be hard to guess. A name you hand over can be guessed. The passphrase is what keeps the document closed.
-
Publish the build file
You choose the passphrase at publish time. The browser encrypts the build document with age passphrase mode and uploads only the ciphertext. The server cannot read the file and cannot reset the passphrase. Lose it, and that config is gone.
On the machine
The image is already Debian. The file names the disk, the network, and the access profile for this one machine. A shell script in that file is refused.
-
Pick the boot entry
Keys 1 through 5. Full speech or console speech if the next questions need to be read aloud. The menu beeps, because the voice starts only after the kernel. Details are on the access page.
-
The system boots
Signed image. Quiet services. A break-glass shell stays.
-
The network comes up
The first ethernet takes a DHCP lease. It has to. The document that might set a static address is the file we are about to fetch.
-
Say the build hostname
The console asks for the registered hostname, such as ada.build.blunix.io. On a speech profile it reads the name back and waits:
blunix: hostname ada.build.blunix.io. Say yes to keep it.
A typo must not hit someone else's host. Silence does not fetch. -
Say the build passphrase
The prompt is
blunix: passphrase. Type it. It will not be spoken.
Echo is off. The machine fetches https://that-host/ and decrypts on the box. A wrong passphrase saysblunix: could not decrypt. Nothing applied.
-
The document is the build
Disk layout, network, access profile, and which pinned tools to fetch from their vendors. Unknown fields are refused. Then the renderers exit. The next boot follows the document.
What the password covers
TLS proves the hostname is ours. The passphrase proves the file is yours.
- The server holds ciphertext. A stolen portal disk is an encrypted file, not a build.
- A swapped file still needs the passphrase. Replacing the ciphertext does not produce a document that decrypts.
- Debian stays Debian. The file selects layouts and pins inside the image. It does not paste a remote script onto the host.
- The build host is this step. A signed image release can live on GitHub later. The per-machine instructions come from the assigned hostname.
Publishing again changes the next install. An enrolled machine can take a later document at its apply window. That client is the service. It is not running. A new image is still a row on the log. The portal on this site does not submit.