AuroraBoot is the official Kairos bootstrapper for building images, provisioning machines, and managing fleets. It creates ISO, UKI, raw disk, and system-extension images from Kairos flavors or container images, then provisions machines through PXE/netboot, Redfish, or USB. Its fleet server provides a browser dashboard for building artifacts, deploying them, and managing nodes. Registered nodes can receive upgrades, reboots, resets, cloud-config, and arbitrary shell commands with captured output. The guided Artifact Builder includes templates for Ubuntu, Fedora, Debian, openSUSE, Alpine, Rocky, and Hadron. AuroraBoot also includes a SecureBoot key store for several key types and a REST API with a Go client and Swagger UI. Documented architectures are amd64, arm64, and riscv64. The free, open-source software is licensed under Apache License 2.0 and is intended for self-hosting with Docker or a container engine. One security limitation is that its netboot HTTP server has no authentication and serves files over plain HTTP to reachable clients.
Who it is for
AuroraBoot suits administrators building Kairos images, provisioning machines, or managing fleets across its documented architectures. It requires a self-hosted setup with Docker or a container engine.
What is good
- Builds several image types from Kairos flavors or containers.
- Provisions through PXE/netboot, Redfish, or USB.
- Provides a browser dashboard for fleet operations.
- Includes a REST API and Go client.
- Free under Apache License 2.0.
What to know first
- Requires Docker or a container engine.
- Netboot HTTP server is unauthenticated.
- Netboot files are served over plain HTTP.
Freedom251 review
AuroraBoot: the full review
AuroraBoot combines image building, provisioning, and fleet management for self-hosted deployments. Its unauthenticated plain-HTTP netboot server is an important security limitation to consider.
Overview
AuroraBoot is Kairos’s official tool for building system images, provisioning machines and operating fleets. It is best suited to teams deploying and maintaining self-hosted Linux machines; its combination of image creation and node management is compelling, but plain-HTTP netboot creates a significant security trade-off.
It builds ISO, UKI, raw disk and system-extension images from Kairos flavors or container images, then provisions machines through PXE/netboot, Redfish or USB. A browser-based fleet dashboard brings artifact building, deployment and node management together. See our Bare Metal Provisioning Software directory for more options.
Key features
Image building and provisioning
The guided Artifact Builder has templates for Ubuntu, Fedora, Debian, openSUSE, Alpine, Rocky and Hadron. Documented integrations include Redfish BMC deployment, Canonical MaaS image generation, Docker or OCI images, and Pixiecore netboot serving. Support for amd64, arm64 and riscv64 gives it reach across common server and embedded architectures, though teams should confirm their target systems fit those documented architectures.
Fleet operations
Registered nodes can receive upgrades, reboots, resets, cloud-config and arbitrary shell commands, with command output captured. That makes AuroraBoot more than an imaging utility: it can support ongoing lifecycle work from the same fleet service. SQLite is the default storage backend, while PostgreSQL is supported through a configurable database DSN.
Security and API
A SecureBoot key store handles PK, KEK, db and TPM PCR policy keys, including signed export and import. The REST API and Go client mirror the UI, and Swagger UI is available at /api/docs, useful for teams automating workflows beyond the browser dashboard.
The main caution is its netboot server: it has no authentication and sends kernel, initrd, squashfs and cloud-config over plain HTTP to reachable clients. Rate limits on node registration, heartbeat and command polling help constrain those endpoints, but they do not protect the netboot payloads. Deploy it only where network reachability is appropriately controlled.
Pricing
AuroraBoot is open source under the Apache License 2.0. Its self-hosted plan costs 0.00 USD per free and requires Docker or another container engine. The free plan includes OS image deployment, PXE bootstrapping, lifecycle management, API access and out-of-band management, making it a strong fit for teams able to run and maintain their own service. There is no paid tier to move to for a different support model within this plan; bug reports and feature requests go to the kairos-io/kairos issue tracker, while Kairos lists enterprise support contacts on its website.
Platforms
AuroraBoot is listed for API, Linux, macOS, self-hosted, web and Windows environments. Its server is self-hosted, and the documented machine architectures are amd64, arm64 and riscv64.
Who it's for
Choose AuroraBoot if you need one self-hosted system for creating images, provisioning machines and issuing fleet-level lifecycle commands, and can manage the infrastructure and network controls that entails. It is less suitable for environments that require authenticated netboot or encrypted delivery of boot assets and configuration.
Pros and cons
- Pros: Builds several image formats and provisions through PXE/netboot, Redfish or USB, giving operators multiple deployment paths.
- Pros: Combines dashboard-based fleet management with a REST API and Go client, including captured output from node commands.
- Pros: The Apache-licensed self-hosted plan includes image deployment, lifecycle management and API access at no charge.
- Cons: Netboot is unauthenticated and uses plain HTTP, exposing boot assets and cloud-config to reachable clients.
- Cons: The free self-hosted setup requires a container engine and leaves service operation to the adopting team.
Alternatives
Canonical MAAS is worth considering for teams that want a free-for-all-machines self-support plan; its free tier does not include HA support, RBAC, a knowledge base, Sev 1 response SLA, or phone and ticket support.
Clonezilla is another free, open-source option for readers seeking software in this category.
Foreman is a free, self-managed alternative for teams looking for an open-source installation.
openQRM Enterprise offers a community edition with an open-source version, community support and plugin library, with an enterprise edition for those seeking enterprise add-ons and expert support.
Supermicro SuperDoctor 5 is a free option for Linux and Windows environments.
NVIDIA Base Command Manager has a free-to-use option limited to eight accelerators per server, node or system, with no limit on servers, nodes or systems.
NVIDIA ShadowPlay is another free Windows option.
Serva may suit personal, non-commercial use: its free Community plan limits PXE/BINL service to 50 minutes and two PXE clients.
Verdict
AuroraBoot is a strong fit for technically capable teams that want free, self-hosted image building, provisioning and fleet operations in one tool. Its breadth and API make it more useful than a one-off imaging utility, but the unauthenticated plain-HTTP netboot server is a serious reason to look elsewhere when boot traffic or configuration must be protected.
AuroraBoot plans and pricing
All plansCompared on bare metal provisioning software
- OS image deployment
- Yes
- PXE bootstrapping
- Yes
- Lifecycle management
- Yes
- API access
- Yes
- Out-of-band management
- Yes


