Amutable presents Quarry, a software-delivery toolchain designed to distribute immutable Linux images using “dumb” static servers and intelligent clients. It starts from clear operational requirements: update payloads and metadata must be static blobs suitable for cheap CDN hosting; signing and distribution must allow granular ownership and flexible key escrow; updates must be autonomous and support rollout strategies; targeting must be fine-grained while preserving a need-to-know structure so a compromised node reveals only its own data; and the whole system must resist known repository attacks. Quarry builds on systemd-sysupdate’s transfer-file model for installing UKIs and DDIs and adopts The Update Framework (TUF) because TUF’s role-based signing (root, timestamp, snapshot, targets) and static metadata defend against freeze, mix-and-match, and key-compromise scenarios.
Quarry is a TUF-based client and publisher that fills gaps in upstream tooling by offering transactional, programmatic publishing and a few custom TUF extensions. To enforce minimal exposure, Quarry uses per-machine repositories: each node has its own repository of installable artefacts and can reference other managed repositories via cross-repository links, enabling deduplication for groups while keeping repository structure local and private. The result is a distribution system that favors simple, easily mirrored servers, strong cryptographic ownership boundaries, and autonomous, secure machine-level updates.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.