Hasty Briefsbeta

Bilingual

Dumb servers, smart clients: Distributing OS images with Quarry

13 hours ago
  • Quarry is a 'dumb' software delivery toolchain that uses static blobs on the server and places all smarts on the client for easy mirroring and caching.
  • Key requirements include granular ownership, flexible key escrow, autonomous updates, granular addressability, need-to-know access, and security against known attacks.
  • Quarry builds on The Update Framework (TUF) with separate roles for targets, snapshot, timestamp, and root, using static files for security against key compromises.
  • It introduces per-machine repositories and cross-repository links to achieve granular, need-to-know access without exposing fleet structure.
  • Quarry integrates with systemd-sysupdate for installation, using TUF metadata to generate ephemeral transfer files served via varlink.
  • Extensions include a custom repository listing algorithm and cross-repository links, both planned for proposal to the TUF specification.