Install

Two prompts, then it builds.

An account gets a hostname. That host serves an encrypted build document. The machine downloads the file, decrypts it locally, and applies it. The passphrase stays on the machine that encrypts and the machine that decrypts.

Example URL: https://ada.build.blunix.io/

On the site

This half is specified on the account page. This site has no account form, and it does not submit a passphrase.

  1. Sign in

    Authentik at adsas.id, Google, or GitHub. There is no password stored here. The build passphrase is a second secret, chosen later, in the browser.

  2. Register a label

    You pick the name. The installer URL is https://ada.build.blunix.io/. You hand that URL to the person or the script that boots the machine. An earlier draft used a numbered host so the name would be hard to guess. A name you hand over can be guessed. The passphrase is what keeps the document closed.

  3. Publish the build file

    You choose the passphrase at publish time. The browser encrypts the build document with age passphrase mode and uploads only the ciphertext. The server cannot read the file and cannot reset the passphrase. Lose it, and that config is gone.

On the machine

The image is already Debian. The file names the disk, the network, and the access profile for this one machine. A shell script in that file is refused.

  1. Pick the boot entry

    Keys 1 through 5. Full speech or console speech if the next questions need to be read aloud. The menu beeps, because the voice starts only after the kernel. Details are on the access page.

  2. The system boots

    Signed image. Quiet services. A break-glass shell stays.

  3. The network comes up

    The first ethernet takes a DHCP lease. It has to. The document that might set a static address is the file we are about to fetch.

  4. Say the build hostname

    The console asks for the registered hostname, such as ada.build.blunix.io. On a speech profile it reads the name back and waits: blunix: hostname ada.build.blunix.io. Say yes to keep it. A typo must not hit someone else's host. Silence does not fetch.

  5. Say the build passphrase

    The prompt is blunix: passphrase. Type it. It will not be spoken. Echo is off. The machine fetches https://that-host/ and decrypts on the box. A wrong passphrase says blunix: could not decrypt. Nothing applied.

  6. The document is the build

    Disk layout, network, access profile, and which pinned tools to fetch from their vendors. Unknown fields are refused. Then the renderers exit. The next boot follows the document.

What the password covers

TLS proves the hostname is ours. The passphrase proves the file is yours.

Publishing again changes the next install. An enrolled machine can take a later document at its apply window. That client is the service. It is not running. A new image is still a row on the log. The portal on this site does not submit.