Pre-alpha. Not for production.

Basalt OS

A secure, light Linux distribution with a local, offline assistant.

Secure defaults from the first boot, updates you can undo because the system takes a snapshot before and after every change, and an assistant that runs on your machine. Install it once and keep it current with dnf. Basalt OS is in early development and there is nothing to download yet.

Principles

Secure by default, light by design.

The safe choice is the default one. You should not need a hardening guide to get a system you can trust.

  • SELinux enforcing, always

    Mandatory access control is on in every installation and checked at build time. It is never switched to permissive to make something work.

  • Encrypted by default

    Full disk encryption with LUKS2 is on from installation. The TPM2 unlocks the disk only while the boot chain is unchanged, and you keep a recovery key.

  • Updates you can undo

    Install once and update with dnf; what you install stays across updates. A btrfs snapshot is taken before and after every package change, so you can roll back from the running system or pick a snapshot in the boot menu. Home, logs and databases live in their own subvolumes and a rollback never touches them.

  • Signed packages

    Packages and the repository metadata are signed, and the system checks signatures before it installs an update. Checksums of the installation media are signed too.

  • Light, server first

    The first edition is a small server system with only what it needs. A desktop edition comes later, on the same base.

  • A local assistant

    It diagnoses problems and proposes actions, and never acts without your confirmation. It works offline, and you can plug in a bigger model if you choose to.

Base

Based on Fedora.

Basalt OS is a traditional, package-based Fedora derivative. It uses Fedora packages from Fedora's own mirrors, the Fedora kernel and its signed boot chain. Basalt OS adds its own defaults, tools and assistant, and a small signed package repository.

Basalt OS is an independent project. It is not affiliated with or endorsed by the Fedora Project or Red Hat.

Roadmap

Small steps, each one usable.

The order of the work, not a schedule. Plans can change as we learn.

  1. Milestone 0

    In progress

    An installable system with disk encryption, automatic snapshots and rollback.

  2. Storage and Secure Boot

    Next

    Storage layout and tooling, and Secure Boot with the project's own keys.

  3. The assistant

    Planned

    The local assistant that diagnoses, proposes and asks before acting.

  4. Repository and installer

    Planned

    A package repository of our own and an installer.

  5. Desktop edition

    Later

    A desktop edition based on Sway, with the same secure defaults.

Get involved

Follow along.

Development happens in the open on GitHub. Issues and ideas are welcome.