Skip to content

Rebuild PXE provisioning with iPXE and ProxyDHCP - #1

Merged
greksw merged 7 commits into
mainfrom
portfolio/v2-ipxe-provisioning
Sep 15, 2026
Merged

greksw merged 7 commits into
mainfrom
portfolio/v2-ipxe-provisioning

Conversation

@greksw

@greksw greksw commented Sep 15, 2026

Copy link
Copy Markdown
Owner

Summary

Rebuilds the legacy PXE installer into a portfolio-ready Linux provisioning toolkit while preserving repository history.

Main changes

  • replaces the old PXELINUX/ThinStation-centric flow with iPXE chainloading;
  • keeps the existing site DHCP server authoritative and uses dnsmasq in ProxyDHCP mode;
  • supports both legacy BIOS (undionly.kpxe) and x86_64 UEFI (ipxe-snponly-x86_64.efi);
  • uses TFTP only for the small iPXE chainloader and HTTP/nginx for boot assets;
  • removes hard-coded internal production addresses and uses documentation-safe example values;
  • removes embedded SMB credentials and CIFS mount management;
  • removes personal GitHub SSH key generation and interactive chroot automation;
  • separates PXE service installation from OS-media publishing;
  • verifies local ISO images with an operator-supplied SHA-256 before publishing them;
  • adds example AlmaLinux and Ubuntu Server boot profiles;
  • leaves firewall policy and the primary DHCP server untouched;
  • adds a comprehensive README and reference iPXE menu template;
  • adds Bash syntax and ShellCheck CI.

Architecture

Existing DHCP provides IP/gateway/DNS. dnsmasq only answers PXE discovery in proxy mode. Firmware receives an iPXE chainloader over TFTP, then iPXE retrieves the menu and installation assets over HTTP.

Follow-up

After review, the repository can be renamed to linux-pxe-provisioning. The separate pxe_server2 repository can then be archived because its useful multi-distribution provisioning concept is represented in this v2 implementation.

Validation status

GitHub Actions Bash syntax validation and ShellCheck pass on the current branch. End-to-end BIOS/UEFI network boot should still be validated on a disposable VM or isolated provisioning VLAN before production use.

@greksw
greksw marked this pull request as ready for review September 15, 2026 09:46
@greksw
greksw merged commit 5394822 into main Sep 15, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant