Dumb servers, smart clients: Distributing OS images with Quarry
13 hours ago
- Quarry is a 'dumb' software delivery toolchain that uses static blobs on the server and places all smarts on the client for easy mirroring and caching.
- Key requirements include granular ownership, flexible key escrow, autonomous updates, granular addressability, need-to-know access, and security against known attacks.
- Quarry builds on The Update Framework (TUF) with separate roles for targets, snapshot, timestamp, and root, using static files for security against key compromises.
- It introduces per-machine repositories and cross-repository links to achieve granular, need-to-know access without exposing fleet structure.
- Quarry integrates with systemd-sysupdate for installation, using TUF metadata to generate ephemeral transfer files served via varlink.
- Extensions include a custom repository listing algorithm and cross-repository links, both planned for proposal to the TUF specification.