Living Document Notice
Published 2026-09-13. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.
Bootstrapping Nodes Without Ansible Bloat (POSIX shell, SSH keys, nftables baseline)
Summary
Automated configuration management tools often require extensive Python dependencies, large module collections, and high memory overhead during execution. Bare-metal nodes and low-memory virtual servers can be securely bootstrapped using a minimal POSIX shell script, ed25519 SSH keys, and an nftables packet filter baseline.
The Pitfalls of Heavyweight Configuration Frameworks
Standard orchestration workflows favor complex automation frameworks such as Ansible, Puppet, or Chef. While capable across large corporate fleets, these tools demand substantial dependencies. Ansible requires a complete Python 3 installation, multiple Python libraries, and large temporary payload transfers over SSH. On a lightweight edge node with 512 MB of RAM, executing a single Ansible run can trigger process swapping or invoke the Linux Out-Of-Memory killer.
Bootstrapping a node requires a limited set of operations: creating administrative user accounts, deploying public SSH keys, setting kernel sysctl parameters, and loading a restrictive firewall ruleset. A pure POSIX /bin/sh script accomplishes these tasks using native system binaries in under two seconds.
By relying strictly on utilities present on any minimal Linux base image, the Quartermaster bootstrap process remains fast, auditable, and light on memory.
Deterministic POSIX Bootstrap Script
The bootstrap script executes over SSH or during initial image generation. It avoids bash-specific extensions to run uniformly across Debian, Ubuntu, and Alpine Linux installations.
#!/bin/sh
set -eu
ADMIN_USER="bosun"
SSH_PUBKEY="ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIG12gK5aJvF7D4q0H8w9XeLmNpQrStUvWxYzAbCdEfGh quartermaster-ops"
# 1. Ensure dedicated unprivileged system user
if ! id "$ADMIN_USER" >/dev/null 2>&1; then
useradd -m -s /bin/sh "$ADMIN_USER"
fi
# 2. Configure locked SSH credential directory
USER_HOME=$(getent passwd "$ADMIN_USER" | cut -d: -f6)
SSH_DIR="$USER_HOME/.ssh"
AUTH_KEYS="$SSH_DIR/authorized_keys"
mkdir -m 0700 -p "$SSH_DIR"
echo "$SSH_PUBKEY" > "$AUTH_KEYS"
chmod 0600 "$AUTH_KEYS"
chown -R "$ADMIN_USER:$ADMIN_USER" "$SSH_DIR"
# 3. Kernel hardening parameters
SYSCTL_CONF="/etc/sysctl.d/99-quartermaster.conf"
cat <<'EOF' > "$SYSCTL_CONF"
net.ipv4.tcp_syncookies = 1
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
fs.protected_hardlinks = 1
fs.protected_symlinks = 1
EOF
sysctl -p "$SYSCTL_CONF" >/dev/null
# 4. Deploy nftables firewall configuration
NFT_CONF="/etc/nftables.conf"
cat <<'EOF' > "$NFT_CONF"
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
chain input {
type filter hook input priority filter; policy drop;
# Allow established connections and loopback
ct state established,related accept
iifname "lo" accept
# Drop invalid connection states
ct state invalid drop
# Rate-limited ICMP ping
ip protocol icmp icmp type echo-request limit rate 10/second accept
ip6 nexthdr icmpv6 icmpv6 type echo-request limit rate 10/second accept
# SSH ingress with connection rate-limiting
tcp dport 22 ct state new meter ssh-meter { ip saddr limit rate 15/minute } accept
# Edge reverse proxy web ingress
tcp dport { 80, 443 } accept
}
chain forward {
type filter hook forward priority filter; policy drop;
}
chain output {
type filter hook output priority filter; policy accept;
}
}
EOF
chmod 0600 "$NFT_CONF"
nft -f "$NFT_CONF"Security Invariants Enforced by the Baseline
The bootstrap script establishes a minimal operational surface. Every parameter choice maps to an explicit security constraint.
| Component | Target File | Enforced Mode | Operational Invariant |
|---|---|---|---|
| SSH Key Store | ~bosun/.ssh/authorized_keys | 0600 (rw-------) | Only user bosun can read or modify authorized keys |
| SSH Directory | ~bosun/.ssh | 0700 (rwx------) | Prevents traversal by unprivileged daemon accounts |
| Kernel Sysctl | /etc/sysctl.d/99-quartermaster.conf | 0644 (rw-r--r--) | Enables reverse-path filtering against IP spoofing |
| Firewall Rules | /etc/nftables.conf | 0600 (rw-------) | Restricts packet filter modifications to root execution |
| Network Ingress | Linux Packet Filter (nftables) | Default Policy DROP | Closes all ports except SSH, HTTP, and HTTPS |
Bootstrap Verification and Execution
Executing the bootstrap over a pristine SSH connection establishes the baseline without remote client state.
# Stream bootstrap script directly into remote shell
cat bootstrap-node.sh | ssh -o StrictHostKeyChecking=accept-new [email protected] "sh -s"
# Verify active nftables ruleset on target node
ssh [email protected] "nft list ruleset"- Directus Target: quartermaster
- Garden Source Reference: MOC - Fleet Operations
- Garden Source Reference: MOC - Bosun PKM Tools
- Garden Source Reference: [QTM-1004 - Bootstrapping Nodes Without Ansible Bloat (POSIX shell, SSH keys, nftables baseline)](QTM-1004 - Bootstrapping Nodes Without Ansible Bloat (POSIX shell, SSH keys, nftables baseline))