Log
A new image is a new row.
The Blunix Log is the public record of image versions. Updating a channel appends a row. Withdrawing a bad image appends a row. An old row stays where it was written.
What a row holds
One version, one channel, the artifact digest, the signature, and the version it replaces on that channel. The files are a qcow2, a raw disk, and the sysupdate manifest.
| Version | Channel | Digest | Replaces | State |
|---|---|---|---|---|
| 0.1.0 | stable | sha256, example only | none | example |
| 0.1.1 | stable | sha256, example only | 0.1.0 | example |
| withdraw 0.1.1 | stable | same artifact | 0.1.1 | example, dropped from the manifest |
The signature column is empty until a key ceremony exists. A test key on a laptop is allowed for the spike. It is not a release.
How a machine moves
The node document names an update URL and a channel. The test document uses https://updates.blunix.io/blunix and stable.
-
The log is the source
A publisher appends a row through the API. An ordinary account cannot. The public page is a rendering of those rows.
-
The manifest is generated
systemd-sysupdate reads a manifest at the update URL. That file is produced from the current rows for the channel. Nobody edits it by hand to sneak a version in.
-
Mirrors are caches
A row can name more than one https mirror. The machine checks the digest. A mismatch is refused, and the running image stays. A region is a cache of those bytes, not a second configuration. The build is on the platform page.
-
The other slot boots
The new image installs beside the one that is running. The previous slot still boots. Rollback is that slot, which is the predecessor on the row.
-
A withdrawn version leaves the manifest
The row remains, so you can see that it shipped and that it was pulled. The artifact bytes can stay on the file server for a machine already mid-update. A new boot does not select them.
Config is the other pipe
Republishing https://ada.build.blunix.io/ changes the next install of that label. It does not rewrite a machine that already applied a document.
- Next install. The build file is ciphertext on the label. A new publish replaces what the next boot will decrypt.
- Already installed. An enrolled machine takes a new document at its next apply window. The client calls the same renderers and then exits. It does not edit
/etcby hand. A new image is still a new row on this log. That client is specified on the service page and is not running. - The log is not open. This page is the record we will keep. It is not connected to a file server, and the table above is an example.
The account that registers the label is on the account page. The publisher call is on the API page.