Two scripts, for the one moment a fresh machine can reach nothing else. Neither carries a credential: both stop at the step that needs one and hand it back to a human. Public keys are public by definition; an auth key is not.
Fetching a script over the network and executing it as administrator is remote code execution by design. Check the hash first — it is the same habit the fleet already applies to the Ubuntu WSL image.
curl -fsSLO https://bootstrap.madbots.cloud/SHA256SUMS curl -fsSLO https://bootstrap.madbots.cloud/setup.sh sha256sum -c --ignore-missing SHA256SUMS && bash setup.sh
Run it as the account you want to reach the machine with. Not as root, and
not through sudo bash: it uses sudo where it needs to, so the keys
land in your home directory instead of /root.
curl -fsSL https://bootstrap.madbots.cloud/setup.sh | bash
Open PowerShell as administrator. Set the machine name first: the script refuses to guess, because the name is the key everything else is filed under.
$env:FLEET_HOST = "<name>" irm https://bootstrap.madbots.cloud/windows.ps1 | iex
Prefer this when you can — it lets you read it before it runs: irm https://bootstrap.madbots.cloud/windows.ps1 -OutFile w.ps1 Get-FileHash w.ps1 -Algorithm SHA256 # compare against SHA256SUMS $env:FLEET_HOST = "<name>" ; .\w.ps1
Served from rootlord behind traefik. Source: /brain/bootstrap/public.
The payloads are single-sourced from bootstrap/www/setup.sh and
hosts/bin/bootstrap-windows-host.ps1 — there is no second copy to
drift.