The theme: v2 turns the stack from software you install into a machine you boot. One immutable appliance image — Debian 13 + Rugix A/B updates, running the stack on Podman/Quadlet — serving both the flashable USB path and a raw self-deployable image, plus a curl installer for the DIY channel, which stays on Docker Compose unchanged. The 2026-07-22 plan supersedes the earlier Ubuntu-autoinstall phasing (#77) and the open runtime question (#78 → outcome A, spike pending). Deployment flexibility — remote Tari (#103) and co-hosting (#181) — is out of the dual-distribution plan's scope: both are stack config features that apply to every channel, and they sequence independently.
#78 Quadlet spike on Debian 13 ──► binding go/no-go (netavark firewall port first)
│ hand-written units become renderer fixtures
▼
#77 dual distribution (the epic — plan ratified 2026-07-22)
phase 1: curl installer + render-quadlet + mandatory cosign
phase 2: Rugix appliance — exit bar: boots / atomic update / rollback /
7-day unattended soak on the #54 bench
phase 3: first-boot provisioning (config.json pre-seed, then the #33 wizard)
phase 4: release os-image lane, stable/beta channels, boot-test per cut
Deployment-flexibility facet — independent of the dual-distribution plan:
#103 tari.mode: remote — verdict GO (trusted-network-only); implementation
open as PR #754. With Monero remote mode, a full-remote stack runs
zero node containers — the nodes' runtime decoupling completes here
#181 co-hosting — DIY-channel concern (the appliance assumes a dedicated box);
auth-fail-closed rule applies
pithead doctor --json; migration-deadlock rule (data_migration-flagged chain services start only post-commit); updates over Tor with manual clearnet fallback; Secure Boot + at-rest/dataencryption decided out for v1; x86_64-only, AVX2 hard-fail stands.Far-off: appliance-style Monero (and Tari) node-starter repos for easy remote nodes #105 — node-starter appliance repos.Closed as not-planned 2026-07-23 (the Add Kubernetes support #17 pattern: speculative deploy target, no demand signal). Its substance shipped as the remote-node modes (Evaluate a remote Tari base-node option (tari.mode: remote), mirroring Monero remote #103/feat(tari): remote Tari base-node mode (#103) #754 + Monero remote); the repo-split decision record (one combined repo, images-are-the-interface,build/moneromigration mechanics) is preserved on the issue. Reopen trigger: real users asking for a standalone node appliance once the Bootable USB installers: self-provisioning appliance images for the stack host and RigForge miner #77 tooling exists.tari.mode: remote). Verdict GO 2026-07-22 (trusted-network-only — the merge-mine gRPC is plaintext-unauthenticated); implementation open as PR feat(tari): remote Tari base-node mode (#103) #754 (addslocal_tariprofile, drops p2pool's nodedepends_onedges). Completes the protocol-layer node decoupling: after it, both nodes are optional containers behind profiles, remote-able, and the stack↔node interface is RPC/ZMQ/gRPC.Release status — tier not open
Gates: #78 spike passes its go/no-go · #77 phase-2 exit bar (boots / atomic update / rollback / 7-day soak on the #54 bench) · #77 phase-4 boot-test wired into the release cut · #103 lands via PR #754 (verdict was GO; different-machine e2e folds into its release) · #181 split merged with the auth-fail-closed rule.