Amargasaurus cazaui
An image-based Linux server OS built like a container, composed from freedesktop-sdk.
Bluefin Server targets the same use-case space as Flatcar Container Linux, Fedora CoreOS, and Talos, and is built with BuildStream 2. Its entire userspace, kernel, and boot chain compose from freedesktop-sdk (FSDK 26.08, systemd v261) components. No other distro's binaries ship in the image.
It is DDI first and diskless-first: one build produces a verity-sealed /usr image, signed UKIs, an OS DDI that a node pulls into RAM over HTTP, and an offline USB installer. Rebooting is how a diskless node updates. Installing to disk is optional.
The only thing worse than a nightmare is a factory of nightmares that makes other nightmares
Bluefin Server is currently in Alpha:
- Trust model: every boot is Secure Boot verified end to end (signed systemd-boot, signed UKIs, dm-verity
/usrpinned byusrhash=on the locked kernel command line). The release set carries a GPG-signedSHA256SUMSmanifest that bothsystemd-sysupdateand the diskless pull verify. - Suitability: Alpha builds are intended for evaluation, testing, and factory validation. Not yet recommended for production workloads.
- Readiness roadmap: Track completed criteria and remaining gates toward 1.0 in
docs/MVP_1_0_READINESS.md.
- Diskless-first boot — the netboot UKI pulls
bluefin-server_<ver>.rawinto RAM withrd.systemd.pull, verified against the signedSHA256SUMS(verify=signature), mounts a dm-verity erofs/usr, and runs from tmpfs. A diskless node updates by rebooting into a newer image, and flags/run/reboot-requiredwhen its boot server offers one that its next boot would pull (not when the node is pinned to a versioned image). - Optional disk install with A/B rollback — a running diskless node is the installer: see ddi-installer.md (
systemd-sysinstallcopies/usrinto slot A). The first disk boot creates slot B and a persistent xfs root.systemd-sysupdatefills the inactive slot on a timer and reboots into it nightly (Kubernetes nodes leave the reboot to kured), and UKI boot counting rolls back an update that does not boot cleanly: a boot-counted boot that has not reachedboot-complete.target(any failed unit counts) within 15 minutes reboots, or on Kubernetes nodes is flagged for kured, until systemd-boot falls back to the previous image, which then stays put until a newer release./run/reboot-lockor/etc/reboot-lockholds these reboots. - Secure Boot on — signed systemd-boot, signed UKIs, signed kernel modules,
lockdown=integrity. UEFI HTTP boot is supported; Booty serves the UKI, the OS DDI, the signed manifest, and a per-nodebluefin-node.ign. - Opt-in per-node state via Ignition — pass an
ignition.config/ignition.config.urlsystem credential (or, on UEFI HTTP boot, abluefin-node.ignnext to the UKI) and Ignition runs in the initrd on every boot; configs must be idempotent. - Opt-in sysexts — k0s (Kubernetes), KubeStellar, and OpenZFS ship as separate
systemd-sysextimages, never in the base/usr. ZFS and KubeStellar are version-locked to the image and follow OS updates through optional sysupdate features.
Remote diagnostics: OpenSSH is installed for on-demand diagnostics, but is disabled by default via systemd presets. It can be started manually with
systemctl start sshdwhen remote access is needed. Seedocs/skills/factory-integration.md.
You need only podman and just. BuildStream runs inside the FSDK bst2 container, so BuildStream is not installed locally.
just validate # resolve the element graph
just export-image # build the release set into dist/diskless/
just dogfood-check # headless QEMU diskless boot with Secure Boot
just dogfood-install # diskless boot, install to disk, boot it (QEMU)For network boot at scale, Booty syncs a
release (from GitHub or the OCI artifact) and HTTP-boots nodes with per-host
Ignition and optional doInstall to disk.
See AGENTS.md for the full build command matrix, hard rules, and agent skill routing.
See CONTRIBUTING.md for the contributor checklist, Conventional Commit rules, and docs/skills/index.md for task-specific guidance.
- Signed boot chain: Secure Boot keys enroll from the ESP on first boot (
secure-boot-enroll if-safein VMs, or manually via systemd-boot menu in firmware Setup Mode on bare metal); local builds use throwaway keys fromjust gen-dev-keys. - Signed manifests: the build signs one combined
SHA256SUMSover the whole image set (OS images, UKIs, sysexts) insideoci/bluefin-server-image.bst; a release publishesdist/diskless/as-is to GitHub Releases and as an OCI artifact. - Sysupdate verification: installed nodes verify updates against the signed manifest (
Verify=yes), and the diskless pull checks the same signature in the initrd; seedocs/skills/systemd-sysupdate-verification.mdfor details. - Vulnerability disclosure: See
SECURITY.mdfor policy details and how to report security issues.
Apache-2.0.