01 · principles
Principles
cairn splits in exactly one place: the whole build path is public, and the machines that boot the images are private. The catalog holds the image recipes, the CI components that gate them, and the signing and verification tooling, all published so anyone can build the same images; what stays private is the hosts and their host-specific config. No verification anyone runs depends on trusting those hosts or the registry. The base image is boot-gated: every candidate is sealed and booted under enforcing Secure Boot in a nested-KVM job before its :stable moves; host images build on that earned base and promote on a green build of their own.