deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Amutable's Quarry distributes immutable OS images with dumb servers and TUF metadata

Amutable has unveiled Quarry, a software delivery toolchain that serves signed immutable OS images as static blobs, pairing systemd-sysupdate with TUF's role-based signing for survivable key compromise.

Amutable's Quarry distributes immutable OS images with dumb servers and TUF metadata

Amutable, a company working on what it calls high-integrity Linux systems, has introduced Quarry, a software delivery toolchain built around one guiding principle: keep the server as unintelligent as possible and put every decision in the client. The announcement, published on the company's blog and surfaced on Hacker News's front page, is the second installment of a series — an earlier post introduced tine, Amutable's tool for building immutable images, and Quarry covers how those images are distributed securely.

Static blobs, intelligent clients

In Quarry's model, update payloads and their metadata are plain static files that any static web host can serve. No server-side logic generates responses; the client parses metadata, verifies signatures and orchestrates the update itself. According to the post, this pays off in several ways: mirrors are trivial to stand up, caching becomes flexible and inexpensive because static files are precisely what CDNs are built to serve, and the design leaves room for alternative transport mechanisms later.

The requirements driving the design

Amutable spells out a set of hard requirements for the toolchain:

  • Granular ownership: the signing model must let different parties own their signed data. The post warns against a third-party signing key arrangement that would force Amutable into acting like a certificate authority, because an object signed for one vendor often ends up authorized on every machine.
  • Flexible key escrow: customers should be able to move between keys held in escrow by Amutable or another party and keys they fully own, with no client-visible impact. The post notes that hardware-backed signing keys are frequently non-exportable or bound to bespoke protocols, and not every signing model permits the signing entity to be replaced safely.
  • Autonomy: metadata must be descriptive enough for machines to update themselves completely, while still supporting staged rollouts and blue-green deployments.
  • Granular addressability: beyond pushing OS updates to millions of machines, the system must reach small groups or individual machines, letting delivery double as a general control and provisioning mechanism.
  • Least privilege: because repository structure mirrors an organization's fleet and deployment scheme, a compromised node should only see provisioning data pertaining to itself, never the wider organization.
  • Security: resistance to all known attacks against comparable distribution schemes.

systemd-sysupdate handles installation

Quarry does not invent its own installer. It builds on systemd-sysupdate, a low-level tool focused on installing and updating Unified Kernel Images (UKIs) and Discoverable Disk Images (DDIs), which provides a generic scheme for immutable, image-based OS updates. It can flash DDIs to disk partitions, install them as system extensions (sysexts and confexts), place UKIs in the EFI boot partition, and copy files from remote sources to local targets more generally. What Amutable singles out is its declarative approach: on-disk transfer files describe which payloads exist, how they are versioned, where they are fetched from, how they are installed, and which payloads must be updated together as a group.

TUF supplies the trust layer

For signing and compromise recovery, Quarry turns to The Update Framework (TUF). TUF emerged in the mid-2000s after high-profile attacks on software repositories prompted researchers to examine what such systems actually protect against; around the same time the Tor Project needed an update scheme resistant to man-in-the-middle attacks, and a joint paper describing the design followed.

Amutable's core observation is that most distribution schemes weaken security by reusing single signing keys across distinct purposes, mixing rare, high-risk operations with common, low-risk ones. TUF instead separates the publishing flow into roles with segregated keys and defines clear in-band procedures for recovering from any role's key compromise. The targets role signs lists of artefact names, sizes and hashes, and can delegate to other parties so many entities can distribute software in one repository. The snapshot role pins a consistent view of targets metadata so clients see a coherent repository state. The timestamp role signs only a version and hash of the snapshot, allowing very short metadata expiries that defend against freeze attacks. The root role, whose keys are almost always kept offline, defines which public keys may sign each top-level role and with what threshold.

Why it matters

For anyone building image-based deployments, Quarry sketches a distribution model where the costly pieces — update servers, mirror infrastructure, key management services — collapse into commodity static hosting plus client-side logic. The TUF foundation treats key compromise as a planned-for, recoverable event rather than a catastrophe, and the ownership model lets third parties sign their own artefacts without a central authority vouching for everything. The least-privilege repository structure also bounds the damage of any single compromised machine. It is a notable data point in the broader shift toward treating entire operating systems as versioned, signed artefacts that ship like any other software.

  • #immutable-os
  • #systemd
  • #tuf
  • #software-delivery
  • #security

Related posts