◈ iPXE how it works dashboard →
Network boot · bare metal

A blank machine, powered on, becomes a registered, provisioned server — over the network, no install media.

Plug in ethernet, power on, and the machine boots straight from the network. It gets discovered by its MAC, an operator assigns it a role, and it installs itself unattended — each step gated a little more tightly than the last. Here's the whole chain, and exactly what is trusted where.

The boot chain

From power-on to a running OS

Each hop hands off to the next. The early hops carry nothing secret; trust tightens as the machine proves who it is.

1

Firmware asks the network to boot it

unauthenticated
PXE firmware · broadcast DHCP

On power-on the machine's PXE firmware broadcasts a DHCP request. The bootstrap container answers in proxy DHCP mode — it runs alongside whatever real DHCP server already hands out IP addresses and never assigns one itself. It only says: here is a boot filename, and here is the TFTP server to get it from — and it says so only to MACs on its BOOTSTRAP_ALLOWED_MACS list. Every other PXE request on the LAN goes unanswered.

2

Firmware downloads iPXE over TFTP

unauthenticated
TFTP · dnsmasq in the bootstrap container

The firmware pulls an iPXE binary over TFTP. The container picks the right one from the PXE client-architecture option — undionly.kpxe for BIOS x86, ipxe.efi for UEFI x86-64, ipxe-arm64.efi for UEFI ARM64. These are our reproducible iPXE builds (pinned TLS roots, an embedded "chain to whatever DHCP names" script) with no secret baked in; nothing secret rides this hop, which is why TFTP having no transport security is acceptable here.

3

iPXE reaches the Worker through the bootstrap's boot proxy

bootstrap bearer
iPXE · TFTP bootstrap.ipxe → HTTP boot proxy :8080 → HTTPS ipxe.cloudcompute.com/boot.ipxe

iPXE runs its own second DHCP round (user-class iPXE) and is handed a short, non-secret bootstrap.ipxe over TFTP. That script chains to the bootstrap container's boot proxy on the LAN with the machine's architecture and MAC. The proxy checks the client is inside BOOTSTRAP_CLIENT_CIDR and the MAC is allowlisted, then fetches /boot.ipxe from the Worker over HTTPS with Authorization: Bearer <BOOTSTRAP_TOKEN> — a long-lived secret held only by the container and the Worker. The device never sees it. The bearer proves the request crossed the managed bootstrap; it is not the machine's identity, and the MAC stays a selector, not proof.

4

Menu, or straight to install

server TLS
Worker · /boot.ipxe branches on the machine's state — only behind the bearer

If the request carries the bootstrap bearer and the machine's MAC is already assigned a role, the Worker serves the role script — an unattended install, or the diskless RAM boot for RAM roles — carrying a short-lived, one-use nonce (with an escape hatch: press ESC to force the menu). Otherwise it renders the boot menu — a list of operating systems plus Discovery, the ephemeral RAM node that registers the machine. The menu is public: a downloaded ISO, a USB stick, UEFI HTTP boot, or a direct chain to the Worker all reach it, and none of them can select a role — without the bearer an assigned MAC gets the menu, and no nonce is minted.

5

Discovery registers the machine

trust on first use
Alpine (in RAM) · POST /api/machines/register

Discovery is a small Alpine image that boots entirely into RAM, reads the hardware inventory, and posts it with the MAC. The first machine to claim a MAC is minted a per-machine token — returned exactly once, and only its SHA-256 hash is stored. Any later claim on that MAC must present the token; one that doesn't is rejected and logged as a spoof attempt. The machine lands in the registry as discovered.

6

An operator assigns a role

dashboard token
Dashboard · POST /api/machines/:id/assign

From the fleet dashboard, an operator picks a role (what to name it, what packages to fold in). This is the one human decision in the loop, gated by the dashboard bearer token. The machine moves to assigned.

7

Unattended install, gated by a one-time nonce

single-use nonce
Debian installer · GET /config/:id/preseed.cfg?n=…

The assigned machine reboots into the install script, which carries a single-use, one-hour nonce in the preseed URL — the installer can't send an auth header, so the nonce is the gate. Fetching the preseed consumes the nonce, rotates the machine's token (the fresh one is delivered exactly once, baked into the installed OS), and advances it to installing. The preseed installs the operator's SSH key and locks the root password, so the key is the only way in.

8

First boot checks in — done

rotated token
Installed OS · POST /api/machines/:id/checkin

On first boot the installed OS checks in with its rotated token and the machine flips to active. From here it authenticates with a token the registration flow never saw, and state only ever moves forward — a replayed check-in can't walk it backward.

Architecture

Two repositories, one system

The system splits along a clean seam: a small container that lives on the boot network and knows nothing about your fleet, and a stateless Worker at the edge that holds all the identity, state, and logic.

on your network

bootstrap container

A dnsmasq proxy-DHCP + TFTP server plus a small boot proxy. It answers PXE requests alongside your existing DHCP — only for allowlisted MACs — hands out iPXE binaries, and relays each machine's boot request to the Worker with a server-side bearer. It holds no fleet state: just the allowlist and the bearer.

  • proxy DHCP (assigns no IPs; allowlisted MACs only)
  • TFTP serves iPXE + the non-secret bootstrap script
  • arch-detects the binary
  • boot proxy adds the bearer over HTTPS
Alpine · dnsmasq · ghcr.io/fairchild/ipxe-bootstrap
at the edge

Worker service

A Hono app on Cloudflare Workers. It generates the boot menus and install scripts, serves binaries, and is the source of truth for machine identity and provisioning state.

  • D1 — machine registry & state
  • KV — boot & spoof telemetry
  • R2 — custom binaries & overlays
  • the dashboard & the API
Hono · Cloudflare Workers · ipxe.cloudcompute.com

bootstrap.ipxe → local boot proxy → HTTPS + bearer to ipxe.cloudcompute.com ← everything past here is the Worker

Machine lifecycle

Five states, forward only

Every machine walks the same one-way path. It can skip ahead — a freshly discovered box can jump straight to installing — but it can never regress, so a spoofed or replayed check-in cannot walk an active machine back to discovered.

discovered
Registered by MAC. Token minted, awaiting a role.
→
pending
Seen again, still unassigned. Also assignable.
→
assigned
Operator picked a role. Next boot installs.
→
installing
Preseed served, token rotated, OS installing.
→
active
Booted and checked in with its rotated token.

Roles can only be assigned from discovered or pending — never mid-install.

Trust model

What's trusted at each hop

PXE is unauthenticated by design — the firmware has no credentials, and the earliest hops carry nothing worth stealing. Authentication is layered in exactly as soon as something secret is at stake, and each credential is used for one job.

HopAuthenticated?What guards it
DHCP + TFTP none Inherent to PXE. Only a public iPXE binary and a non-secret bootstrap script cross here — no secret to protect. Offers go only to allowlisted MACs.
iPXE → boot proxy LAN allowlist Plain HTTP on the PXE LAN, gated by source CIDR and the MAC allowlist. The LAN is a trust boundary: an on-path host could observe or race the one-use nonce in the returned script, so keep the proxy on a boot VLAN or trusted LAN and the CIDR narrow.
boot proxy → Worker bootstrap bearer HTTPS to ipxe.cloudcompute.com with a long-lived bearer shared only by the container and the Worker (a Worker secret), constant-time compared. The menu is public; the role/install branch and its nonce exist only behind the bearer. Missing or wrong bearer fails closed to the menu. A MAC remains a selector, never proof.
register TOFU token First claim on a MAC mints a token (hash stored, plaintext returned once). Later claims must present it; failures are logged as spoofs. Rate-limited per IP.
assign dashboard token Operator bearer token (a Worker secret), constant-time compared, fails closed if unset.
preseed fetch one-time nonce Single-use, 1-hour nonce in the URL — the installer can't send headers. Consumed atomically; the assigned→installing transition is a second gate so a leftover nonce can't re-rotate the token.
token rotation delivered once At preseed time the token is rotated and baked into the installed OS. The registration token is retired; the machine authenticates with the new one thereafter.
check-in rotated token Per-machine rotated token, constant-time compared. Forward-only state transitions blunt replay.

See the fleet

Live lifecycle board, boot feed, and health. Needs the dashboard token.

Open dashboard →