Container-native PXE boot server in Rust, designed as a clean-room
alternative to iVentoy that never touches the client OS trust store.
This is the first commit of the project; it lands the full output of
Phases 1, 2, 3, and 4 in one shot.
## Phase 1 — protocol stack
- 8-crate workspace (core, dhcp-proxy, tftp, http-api, iso-store,
ipxe-assets, webui, pxeforge bin).
- DHCP proxy (RFC 4578): replies with boot info only, never leases —
sidesteps CAP_NET_RAW. Architecture-aware bootfile selection from
option 93 (BIOS, IA32, x64-UEFI alias 0x0007/0x0009, ARM64).
- TFTP server with full OACK negotiation: blksize, tsize, windowsize.
Without it a 1 MiB iPXE binary takes 2000 packets and unusably long.
- Two-stage iPXE chain: firmware PXE -> TFTP iPXE binary -> iPXE
re-DHCPs with user-class iPXE -> HTTP /boot.ipxe -> kernel+initrd.
- HTTP server (axum) with byte-Range ISO streaming and an in-place
ISO9660 lookup so kernel/initrd are served from inside the ISO
without ever extracting it to disk.
- Linux ISOs boot via kernel+initrd extraction (memdisk/sanboot fail
for >1-2 GiB modern distros). Distro-family detection drives the
cmdline (Debian/Ubuntu, RHEL/Fedora, openSUSE, Arch, Alpine).
## Phase 2 — UX + Windows
- Hierarchical PXE menu (Default / Installers / Tools / Gated
Deployment) generated from settings — no hand-written .ipxe paths
surface in the UI. Number-key + letter hotkeys, BIOS+UEFI variants
for some RHEL ISOs.
- Gated Deployment "horse-race" queue: clients join, operator picks
one ISO, every gate launches simultaneously via tokio::sync::Notify.
- Bootimus-pattern Windows: WimPatcher injects a CRLF startnet.cmd
into boot.wim so vanilla WinPE net-uses an SMB share and runs
setup.exe. All Microsoft-signed; no test certs, no testsigning,
no httpdisk.sys. SmbManager supervises smbd start/stop/SIGHUP.
- Netbox-style dark UI, fully offline (no CDN, no external fonts).
## Phase 3 — MVP hardening
- TFTP retransmit rewrite with explicit window tracking — UEFI SNP
clients no longer hang on files that end mid-window. 4 new tests.
- DHCP broadcast-flag honored per RFC 2131 §4.1.
- Multi-arch container (linux/amd64 + linux/arm64). Entrypoint chowns
bind-mounts as root then drops to uid 10001 via gosu.
- /healthz + /readyz split from /api/status — readyz fails if no
iPXE binaries are bundled.
- pxeforge seed --from <path> CLI: same pipeline as web upload (slug,
sha256, introspection, boot-entry).
- All timestamps RFC 3339 (browser Date couldn't parse the 9-tuple).
- Gate poll retains assignment until operator releases — clients that
retry on transient network errors reuse the assignment instead of
falling back to the menu.
- Custom OpenShift SCC: hostNetwork + NET_BIND_SERVICE only, no
NET_RAW.
## Phase 4 — UI restructure + remote storage
- Web UI rebuilt around six tabs inspired by the iVentoy layout:
Dashboard / Network / Forge Gate / Storage / Terminal / About.
Old "Monitoring/Content/Configuration" sidebar groups are gone.
- NFS share manager (crates/iso-store/src/nfs.rs): mount NFSv3 or
NFSv4.1 shares as ISO sources instead of uploading every file
into the PVC. New IsoSource enum on IsoMeta lets the store resolve
Local vs NFS lazily. Persisted to <work_dir>/nfs.json; failed
mounts surface in the UI rather than blocking startup.
- Dockerfile gains nfs-common + iproute2; mounting NFS in-container
also requires CAP_SYS_ADMIN. Documented in docs/architecture.md.
- LogBus + tracing layer in core: 500-line ring buffer + broadcast
channel feed an SSE endpoint at /api/log/stream.
- Operator terminal at /api/terminal: whitelisted commands (status,
isos, clients, gate, nfs, smb, log) — deliberately not a shell.
Output mirrored onto the LogBus so the live tail and the terminal
pane share one timeline.
- Network tab: read-only nic_name / subnet_mask / gateway probed
from `ip` at startup; only DNS server is editable. Editing IP/mask
on a hot UI would silently break PXE for every client mid-boot.
- Bootimus parity (releases v0.1.55 -> v0.1.62): amber row tint on
un-bootable ISOs with inline reasons, dashboard "won't boot" panel.
## Tests
56 tests passing across the workspace:
- 16 core (LogBus, gate, settings, arch, client)
- 1 dhcp-proxy (raw option-93 extraction)
- 8 http-api unit (range parsing, terminal split/format)
- 13 http-api integration (gated deployment, range, settings, NFS,
terminal, log SSE, network endpoint, ui assets, no-external-urls)
- 12 iso-store (introspect, slugify, smb, windows wim, NFS options)
- 6 tftp (RRQ parsing, plan_window edges)
cargo build --workspace and cargo clippy --workspace --all-targets
both finish clean (warnings only, no errors).