BrutlabsLLC Book a consult
Foundation layer

Sites that turn themselves up, and check their own work

Bare metal to production without an engineer on a console — day-0 configuration rendered from the source of truth, then verified before anyone calls it done.

Manual provisioning is slow, but the real cost is variance. Two engineers build the same site a week apart and produce two subtly different networks, and the difference surfaces eighteen months later during an outage.

Zero-touch provisioning removes the variance by making the source of truth the only input. A device boots, identifies itself, pulls the configuration its record says it should have, and reports back.

The step most implementations skip is verification. A device that came up is not the same as a device that came up correctly, and post-deploy validation is what closes that gap.

Deliverables

What we build

01

Boot and onboarding workflow

DHCP options, boot images and platform-native ZTP or POAP flows, with device identity tied to its source-of-truth record from first contact.

02

Day-0 configuration

Rendered from the same templates and the same data your day-2 changes use. One path, so provisioning and operations cannot drift apart.

03

Circuit and service provisioning

Carrier circuit turn-up, addressing and service configuration handled as part of the same workflow rather than a separate ticket queue.

04

Post-deploy validation

Automated checks that interfaces, routing adjacencies, reachability and policy match intent, with a pass or fail result recorded against the device.

05

Brownfield onboarding

Bringing existing devices into the same lifecycle, so you are not running two operating models indefinitely.

06

Runbook and handover

Documented, rehearsed procedures your team owns — including what to do when the automated path fails and remote hands are all you have.

Agent

What the agent does with this layer

Provisioning is where the agent earns trust cheaply, because the correct answer is already written down.

Day-0 verification

Confirming the build matches intent

The agent compares what the device reports against its source-of-truth record and flags the mismatch before the site carries traffic.

Turn-up triage

Diagnosing failed builds

When a device does not come up clean, the agent has the boot logs, the rendered config and the intended state side by side.

Fleet drift

Catching the slow divergence

Devices provisioned identically drift apart over months. Continuous comparison against intent surfaces it as a report, not an outage.

Stack

Tools we use here

ZTP / POAPvendor boot flowsDHCP / TFTPboot servicesAnsibleday-0 configNornirparallel turn-upNetBox / Nautobotdevice recordspyATSvalidationJinja2templating
Questions

Questions about zero-touch provisioning

Does zero-touch provisioning work across vendors?

Yes, though the boot mechanism differs — ZTP, POAP and vendor equivalents all solve the same problem in slightly different ways. The workflow above the boot layer, where configuration is rendered and validated, stays common across platforms.

We are mostly brownfield. Is ZTP still worth building?

Usually yes, because the value is not limited to new sites. The same templates and validation logic apply to refreshes, RMA replacements and hardware upgrades, which for most enterprises is a larger volume than greenfield.

What happens when the automated build fails?

It fails visibly, with the boot logs, rendered configuration and intended state captured together, and it falls back to a documented manual procedure. A silent partial success is far more dangerous than a clean failure.

How much does provisioning time actually improve?

In the engagements we have run, multi-day site turn-ups typically come down to under a day, with the remaining time spent on physical work and carrier dependencies rather than configuration. We will walk you through the specific arithmetic for your environment during the consult.

Book a 30-minute automation readiness consultation

In 30 minutes, we’ll evaluate your infrastructure maturity, identify operational risk areas, and highlight high-impact automation opportunities.

No scripts. No invasive discovery. Just clarity.