basalt-os
OrganizationThe GitHub organization for Basalt OS.
Pre-alpha. Not for production.
A secure, light Linux distribution with a local, offline assistant.
Secure defaults from the first boot, updates you can undo because the system takes a snapshot before and after every change, and an assistant that runs on your machine. Install it once and keep it current with dnf. Basalt OS is in early development and there is nothing to download yet.
Principles
The safe choice is the default one. You should not need a hardening guide to get a system you can trust.
Mandatory access control is on in every installation and checked at build time. It is never switched to permissive to make something work.
Full disk encryption with LUKS2 is on from installation. The TPM2 unlocks the disk only while the boot chain is unchanged, and you keep a recovery key.
Install once and update with dnf; what you install stays across updates. A btrfs snapshot is taken before and after every package change, so you can roll back from the running system or pick a snapshot in the boot menu. Home, logs and databases live in their own subvolumes and a rollback never touches them.
Packages and the repository metadata are signed, and the system checks signatures before it installs an update. Checksums of the installation media are signed too.
The first edition is a small server system with only what it needs. A desktop edition comes later, on the same base.
It diagnoses problems and proposes actions, and never acts without your confirmation. It works offline, and you can plug in a bigger model if you choose to.
Base
Basalt OS is a traditional, package-based Fedora derivative. It uses Fedora packages from Fedora's own mirrors, the Fedora kernel and its signed boot chain. Basalt OS adds its own defaults, tools and assistant, and a small signed package repository.
Basalt OS is an independent project. It is not affiliated with or endorsed by the Fedora Project or Red Hat.
Roadmap
The order of the work, not a schedule. Plans can change as we learn.
An installable system with disk encryption, automatic snapshots and rollback.
Storage layout and tooling, and Secure Boot with the project's own keys.
The local assistant that diagnoses, proposes and asks before acting.
A package repository of our own and an installer.
A desktop edition based on Sway, with the same secure defaults.
Get involved
Development happens in the open on GitHub. Issues and ideas are welcome.
The GitHub organization for Basalt OS.
The source of the system and its tools.
Basalt OS is part of OpenBasalt, open source on solid ground.