Service
One client on every machine.
blunixservice dials out, takes a spoken hostname, and stages the next image and the next document. A laptop, Terraform, and Ansible call the same API. This client is not running.
What it does
The familiar picture is a host joined to an account, reporting what it runs, and taking errata from a console. Here the errata is a row on the log, and the configuration is the age ciphertext the account already publishes.
- It dials out. No listening port. A school, a NAT, and a bank all look the same on the wire. The local socket is a Unix socket.
- Boot does not wait. If the API is down, the machine keeps the document it already applied. The console still comes up.
- Apply calls the renderers. They exit. The client does not edit
/etcby hand, does not run apt, and does not fetch a tool from GitHub. - A patch is a new image. The question the console answers is which machines last reported the previous digest.
Two names
A profile is the label you can say. A machine is one host enrolled on that label. A classroom shares the profile and does not share the hostname.
| Which | Profile | Machine |
|---|---|---|
| Name | ada | ada-1 |
| Where | https://ada.build.blunix.io/ | The spoken hostname, and the inventory |
| Shared | Every machine on that profile | One machine |
| Secret | The age passphrase, which stays off the server | An Ed25519 machine key, generated on the box |
A public profile still serves ciphertext to anyone who can say the name. An enrolled profile serves it only to a bound machine key. The passphrase decrypts either way. The server cannot read the document. New service profiles default to enrolled. The spoken install still uses public.
Offline
The blunix CLI installs on your computer. It exports and imports a JSON bundle. The bundle holds ciphertext and metadata. It has no passphrase field and no API key.
-
Export
blunix service export lab.jsonwrites the bundle from the laptop that encrypted the document, or from a machine that already holds the ciphertext. -
Carry it
A USB stick is enough. One laptop can prepare a lab.
-
Import
On the machine,
blunix service import lab.json --hostname lab-3. The hostname is read back. Decrypt is a console prompt with echo off. A flag for the passphrase is refused. -
Check in later
When a link exists,
blunix service checkinregisters the machine. Until then the API does not know it, and the machine is still configured.
Speech and large print use the sentences in the next section. Silence means no. A quiet cloud profile may reboot inside a maintenance window. A speech profile may not.
Blind ready
Key 1 or key 2 at the beep. The menu does not speak. After the kernel, every question is one sentence, and the answer is the word yes or the word no. The same line goes to a braille display. Large print shows it in the 32-cell font and does not speak. The access page lists the five keys.
| When | Sentence |
|---|---|
| Hostname | blunix: hostname lab-3. Say yes to keep it. |
| Passphrase | blunix: passphrase. Type it. It will not be spoken. |
| Enrolled | blunix: enrolled as lab-3 on profile lab-west. |
| Token consumed | blunix: join token discarded. |
| API down | blunix: api unreachable. Keeping the applied document. |
| New document | blunix: new document for profile lab-west. Say yes to apply. |
| Reboot | blunix: image 0.1.1 is staged. Say yes to reboot.The version is the example row on the log. |
| Decrypt failed, first install | blunix: could not decrypt. Nothing applied. |
| Decrypt failed, later | blunix: could not decrypt. Keeping the applied document. |
| Document refused | blunix: document refused. Keeping the applied document. |
| Answer was not yes | blunix: keeping the applied document. |
| Troubleshoot asked | blunix: troubleshoot requested for lab-3. Say yes to start. |
| Troubleshoot finished | blunix: troubleshoot finished. Sent the report. |
| Troubleshoot refused | blunix: troubleshoot refused. |
| Troubleshoot expired | blunix: troubleshoot expired. |
The passphrase, the join token, and the account key are never in the sentence. Keystrokes at the passphrase prompt are not spoken. Silence, or any answer other than yes, does not reboot, does not apply, and does not collect. The machine asks once more, then keeps the document it already has. A collect is specified on the platform page. Three beeps mean speech was requested and did not start. Boot still continues.
On the web
Package selection is composing the node document: disk model, network model, access profile, channel, and tools that already have a digest. The Debian package set is the image. The web does not install packages onto a live host.
- The image still refuses a sysext list. That control stays closed. Orca remains an optional extension the cloud image does not install.
- The channel the schema accepts today is
stable. A second channel is a later change. - A tool with no digest is shown as waiting. It cannot be selected. The client does not go fetch a newer one.
- The browser encrypts. The upload is ciphertext. This page has no form, and it does not submit a passphrase.
Same client, four policies
The binary does not change. The profile does.
| Place | Policy |
|---|---|
| A blind school | The Blind ready sentences. Short spoken names. A USB bundle from one laptop. Key 1 or key 2. Orca stays an extension. |
| A link that drops | A small check-in. The last good document still boots. One laptop enrolls the lab. The API being down is a normal state. |
| An IT shop | One account, many profiles. Terraform stamps documents. No billing and no extra tenant layer in v1. |
| A bank | Enrolled fetch. Expiring join tokens. Machine keys. An audit of digests and fingerprints. A maintenance window. Their own DNS name recorded beside the spoken hostname. |
Terraform and Ansible
Both are clients of the API. The connection is HTTPS. SSH is the break-glass shell, not the way a playbook changes the host.
- The provider encrypts on your machine. State stores the ciphertext sha256. State does not store the API key, the passphrase, or the join token.
- The join token is shown once. State keeps the fingerprint. A refresh cannot read the token back.
- The passphrase is a file, mode 0600. A passphrase variable is refused, because a plan would keep it.
- Ansible may list machines so a person can open a shell. Collection playbooks do not run apt, and they do not mutate the host over SSH.
The provider and the collection are not written. The routes they will call are on the API page. No server is listening.