A change proves itselfbefore the fleet sees it.

Broken never leaves the building, and a rollout that goes wrong stops on its own.

Three steps. That is the whole loop.

Nobody changes a laptop by hand, not even us.

Write

Change one line in the file that describes your laptops.

Test

It is built and checked first. Broken never leaves the building.

Ship

A few machines first, then the rest. It stops itself if something is off.

Waves, with a gate between them.

A test group goes first and signs off. Then ten percent, then thirty, then the rest. Each wave has to soak for a set time and stay healthy above a threshold before the next one is released. If it does not, the rollout stops where it is.

The Sextant rollout screen with the test group awaiting sign-off and the waves behind it
A release moving through the waves, with the gates that hold it.

Rolling back is booting yesterday’s version.

No manual steps, no restore to test, no image to rebuild. Every change is a new generation of the system next to the old one, so going back is starting the one that worked. The laptop does it by itself if the new one does not come up.

One document for every laptop.site.audit.

Take it, run it, help build it.

The software is yours under the EUPL 1.2 and needs nobody’s permission. What the project needs is people: a laptop model we have never imaged, a language nobody has translated, a bug found by running it for real.