secureblue’s hardening. Recommended: stock Trivalent plus extra locks.
Or Brave Origin, or no browser. Terminal, no curator store.
Install · Features · Privacy · Compared · Brand · Changelog
Not affiliated with secureblue. Overlay on their signed Fedora Atomic images. Not a fork. Their kernel hardening,
hardened_malloc, SELinux, no Xwayland by default, and automatic updates stay.
The product name is Unwoke SecureBlue. Unwoke is the modifier. SecureBlue is one word (S and B capped) — not “Secure Blue”, not unwoke-secureblue in titles. Git and GHCR stay lowercase (unwoke-secureblue, unwoke-silverblue) because registries and rebase commands are slugs.
We strip Bazaar and GUI stores on every image.
Trivalent *-trivalent |
Origin (unsuffixed) | Browserless *-browserless |
|
|---|---|---|---|
| Recommended default | Named choice | Named choice | |
| Browser | Stock Trivalent jail + extra reversible Chromium policies | Brave Origin RPM in brave_t (looser SELinux) |
None. Seatbelt until ujust set-allow-browsers on ALLOW |
| Store | None | None | None |
| Userns | Stock (Flatpak + Trivalent) | Stock + brave_t allow-list |
Stock with Trivalent gone |
*-trivalent equals stock on the house browser and is stricter on extra Chromium policies + house locks. Extra JSON is not a new compiler patch. brave_t is not Trivalent’s tight confinement.
Already on secureblue (or any Fedora Atomic). First switch cannot check our stamp yet. After reboot, first-boot queues the signed image — reboot once more when rpm-ostree status shows it staged.
rpm-ostree rebase ostree-unverified-registry:ghcr.io/sergi270710267/unwoke-silverblue-trivalent:latest
systemctl rebootIf it did not auto-stage (no network on first boot):
rpm-ostree rebase ostree-image-signed:docker://ghcr.io/sergi270710267/unwoke-silverblue-trivalent:latest
systemctl rebootcosign verify --key cosign.pub ghcr.io/sergi270710267/unwoke-silverblue-trivalentKDE → unwoke-kinoite-trivalent. NVIDIA → add -nvidia-open before -trivalent. Brave Origin → drop -trivalent. No browser → -browserless.
Empty disk: flash a USB from Actions (artifact, GitHub login) or a secureblue ISO then rebase. Encrypt, wheel, enroll their Secure Boot key. Not Ventoy.
After first graphical login: Unwoke setup (ujust setup). ujust why if something looks broken. ujust unwoke-test proves every overlay lock on this disk (PASS/LOOSE/FAIL with a path). Nothing unlocks unless you pick it. Everyday tasks: Tutorials. Proton.me: ujust install-proton. IVPN: ujust install-ivpn. Mullvad: ujust install-mullvad.
Published as ghcr.io/sergi270710267/<name>:latest. OS images are public. No GitHub login to pull.
Current bake receipt (pubkey + verified digests, not the OS, not a USB): Releases / receipt. Ignore the source zip GitHub adds. The factory rewrites that tag; it does not attach the ISO.
Stock secureblue is a serious hardened Fedora Atomic. It also ships a house browser and a house app store that decide what you may install.
| Stock secureblue | Origin | Trivalent | Browserless | |
|---|---|---|---|---|
| Browser | Trivalent — their Chromium, SELinux-confined | Brave Origin standalone RPM. Runs in brave_t |
Stock Trivalent + extra reversible policies | None |
| App store | Bazaar | None. Flathub off until ujust set-flathub verified |
None. Same | None. Same |
| User namespaces | Off for unconfined; on for Flatpak and Trivalent | Same, plus brave_t on their userns allow-list |
Same as stock. No brave_t |
Unconfined blocked, Flatpak allowed, no extra domain |
Browserless is safer than Origin until you install a browser. Easy host installs are blocked until ujust set-allow-browsers on ALLOW (Flatpak mask + rpm-ostree exclude). Seatbelt only: toolbox, brew, AppImage, and rpm-ostree --disableexcludes still work.
Stock ujust still works (ujust set-unconfined-userns, ujust set-kargs-hardening, ujust audit-secureblue, …). We did not gut SELinux, kernel args, hardened_malloc, disk encryption, or Secure Boot enrollment.
Overlay ujust extras
ujust unwoke-status
ujust audit-unwoke
ujust setup
ujust why
# Origin and Trivalent (restart the browser after policy changes)
ujust set-brave-hardening on|off # HTTPS, no metrics, no autofill/passwords (default on)
ujust set-brave-devices on|off # camera/mic/geo/USB/BT/serial blocked (default on)
ujust set-brave-jitless on|off # no JS JIT; breaks some sites (default on)
ujust set-brave-extensions block|allow
ujust set-brave-isolation on|off # no WebGL/WebGPU; SitePerProcess (default on)
ujust set-brave-sandbox on|off # audio sandbox, no screen capture, no JS optimizer
ujust set-brave-devtools lock|allow # default allow (opt-in)
ujust set-brave-bubblejail on|off # Origin only; default on; GPU may break
ujust set-trivalent-network-sandbox on|off # Trivalent only; may clear cookies
ujust set-trivalent-referrers on|off # Trivalent only; punycode + strip referrers
# All flavors
ujust set-flathub verified|full|off # default off; verified = stock
ujust set-bluetooth on|off # default off; Wi-Fi stays
ujust set-toolbox on|off # default off; /usr/bin/toolbox is a wrapper
ujust set-extra-daemons on|off # default off (Avahi + ModemManager)
ujust set-stock-nags on|off # default off
ujust set-flatpak-lockdown on|off # default on
ujust set-brew on|off # default off
ujust set-camera-mic on|off # default locked
ujust set-admin-split on|off|add NAME
ujust set-unwoke-theme apply
# Browserless only
ujust set-allow-browsers on ALLOW
ujust set-allow-browsers offTwelve images (rebuilt 08:00 and 20:00 UTC)
| Image | Desktop | GPU | Browser |
|---|---|---|---|
unwoke-silverblue |
GNOME | Nouveau | Brave Origin |
unwoke-silverblue-nvidia-open |
GNOME | NVIDIA open (GTX 16xx / RTX+) | Brave Origin |
unwoke-kinoite |
KDE Plasma | Nouveau | Brave Origin |
unwoke-kinoite-nvidia-open |
KDE Plasma | NVIDIA open | Brave Origin |
unwoke-silverblue-trivalent |
GNOME | Nouveau | Trivalent |
unwoke-silverblue-nvidia-open-trivalent |
GNOME | NVIDIA open | Trivalent |
unwoke-kinoite-trivalent |
KDE Plasma | Nouveau | Trivalent |
unwoke-kinoite-nvidia-open-trivalent |
KDE Plasma | NVIDIA open | Trivalent |
unwoke-silverblue-browserless |
GNOME | Nouveau | none |
unwoke-silverblue-nvidia-open-browserless |
GNOME | NVIDIA open | none |
unwoke-kinoite-browserless |
KDE Plasma | Nouveau | none |
unwoke-kinoite-nvidia-open-browserless |
KDE Plasma | NVIDIA open | none |
The OS is the GHCR image. A flashable ISO wraps that image.
- After each green overlay bake: the two recommended Trivalent sticks (
unwoke-silverblue-trivalent,unwoke-kinoite-trivalent) toghcr.io/sergi270710267/<name>-iso:latest. Stillcosign verifyof our:latest. - On demand: Actions → iso → pick the image → artifact (90 days, GitHub login).
- Weekly (Sunday 10:00 UTC): all 12 flavors. Origin and the other ten stay weekly so it does not wrap eight Origin sticks a day.
- GitHub will not host a 3 GB ISO as a normal release. Not Ventoy. Enroll your Secure Boot key. Watch
factory-alarm/iso-alarmissues if you are away. Map: Factory.
Stock-ISO-then-rebase still works.
Not a git fork of secureblue/secureblue. Forks rot. We pull their already-built, already-signed images.
base-image: ghcr.io/secureblue/silverblue-main-hardened
image-version: latestTrust chain and factory
- secureblue builds and cosign-signs
ghcr.io/secureblue/…-hardened. - Our CI checks their public key still matches
keys/secureblue.pub,cosign verifys the base, then pins that digest. A canary inspects that signed base with crane export (does not run it, does not docker-pull it) and fails the overlay if the stock image names this repo, our GHCR, or/usr/share/unwoke. After rebase, your PC follows our GHCR, not theirs. - We drop Bazaar + GUI stores. Origin also drops Trivalent and layers Brave Origin +
brave_t.-trivalentkeeps stock Trivalent and adds extra policies. Browserless drops Trivalent and skips Origin. Then we cosign-sign our image withcosign.pubin this repo. - Your PC pulls
ghcr.io/sergi270710267/unwoke-…and, after the signed rebase, verifies our signature.
We do not rebuild their kernel or re-run their SLSA pipeline.
Factory extras (this repo, not the desktop): Harden-Runner; Actions pinned to SHAs; SLSA-style provenance; checksum-pinned crane v0.20.3; inspect after each bake and twice daily; one reused issue per alarm label; pr-gate + ruleset main-strict; stock ujust harden-flatpak is a trampoline to Unwoke’s script. Living map: Factory.
We do not use a hardware signing key. cosign.key lives only as the GitHub secret SIGNING_SECRET.
| Change | File |
|---|---|
| Packages | recipes/common.yml; remove-trivalent.sh on Origin/browserless |
| Browser / first-boot | files/scripts/apply-{unwoke,brave,trivalent,browserless}.sh |
| Brave SELinux / userns | files/scripts/install-brave-selinux.sh (Origin only) |
| ujust extras | files/justfiles/unwoke.just, files/system/usr/libexec/unwoke/toggles.sh |
| GNOME favorites | files/gschema-overrides/zz2-unwoke*.gschema.override |
Stock FAQ/features/install are mirrored daily under the site /secureblue/ (Apache-2.0, not affiliated). Pickup file for this repo: PROGRESS.md.
Overlay files: MIT. Fedora, secureblue, BlueBuild, Brave, Trivalent: their licenses. Unaffiliated with secureblue.
