Fleet bootstrap

Two scripts, for the one moment a fresh machine can reach nothing else. Neither carries a credential: both stop at the step that needs one and hand it back to a human. Public keys are public by definition; an auth key is not.

Verify before you run

Fetching a script over the network and executing it as administrator is remote code execution by design. Check the hash first — it is the same habit the fleet already applies to the Ubuntu WSL image.

curl -fsSLO https://bootstrap.madbots.cloud/SHA256SUMS
curl -fsSLO https://bootstrap.madbots.cloud/setup.sh
sha256sum -c --ignore-missing SHA256SUMS   &&  bash setup.sh

Linux — Debian/Ubuntu or Arch

Run it as the account you want to reach the machine with. Not as root, and not through sudo bash: it uses sudo where it needs to, so the keys land in your home directory instead of /root.

curl -fsSL https://bootstrap.madbots.cloud/setup.sh | bash

Windows — one elevated window

Open PowerShell as administrator. Set the machine name first: the script refuses to guess, because the name is the key everything else is filed under.

$env:FLEET_HOST = "<name>"
irm https://bootstrap.madbots.cloud/windows.ps1 | iex
Prefer this when you can — it lets you read it before it runs:
irm https://bootstrap.madbots.cloud/windows.ps1 -OutFile w.ps1
Get-FileHash w.ps1 -Algorithm SHA256     # compare against SHA256SUMS
$env:FLEET_HOST = "<name>" ; .\w.ps1

What it will not do

Served from rootlord behind traefik. Source: /brain/bootstrap/public. The payloads are single-sourced from bootstrap/www/setup.sh and hosts/bin/bootstrap-windows-host.ps1 — there is no second copy to drift.