hardened Fedora KDE; primary on Forgejo
Find a file
s8n deedb6cf37 feat(installer): pre-stage gum-based UX assets for v0.5.1
Drops in branded assets the v0.5.1 installer rewrite (whiptail -> gum)
will consume: ASCII banner, sourceable GUM_* env-var palette matching
the veilor-black KDE color scheme, and an INSTALLER.md walkthrough.

The existing v0.5.0 veilor-installer script is intentionally untouched
so the swap can land in a separate, focused PR.
2026-05-02 03:39:55 +01:00
.github ci: patch livecd-creator __get_efi_image_stanza LABEL → CDLABEL 2026-05-01 21:26:34 +01:00
assets feat(installer): pre-stage gum-based UX assets for v0.5.1 2026-05-02 03:39:55 +01:00
build ci: switch refs from veilorveilor-org (GH org slug); domain veilor.org 2026-04-30 13:59:20 +01:00
docs feat(installer): pre-stage gum-based UX assets for v0.5.1 2026-05-02 03:39:55 +01:00
kickstart v0.5.0-alpha: TTY1 installer (omarchy/archinstall-style) 2026-05-02 03:20:42 +01:00
overlay v0.5.0-alpha: TTY1 installer (omarchy/archinstall-style) 2026-05-02 03:20:42 +01:00
scripts v0.2.3: os-release branding + admin user creation in %post 2026-05-01 18:25:57 +01:00
test test: add VM runner — qemu+OVMF wrapper for fast iso iteration loop 2026-04-30 04:06:19 +01:00
upstream v0.3 theme: match onyx exactly — solid black wallpaper, Linux Konsole scheme, Breeze_Light cursor 2026-04-30 17:18:14 +01:00
.gitignore chore: gitignore agent worktrees + un-track accidental embedded repos 2026-05-02 01:08:14 +01:00
CONTRIBUTING.md ci: switch refs from veilorveilor-org (GH org slug); domain veilor.org 2026-04-30 13:59:20 +01:00
LICENSE veilor-os v0.1 scaffold — kickstart + hardening + 3-mode power + DuckSans-ready KDE black theme 2026-04-30 03:43:33 +01:00
README.md fonts: swap DuckSans → Fira Code (Fedora fira-code-fonts, SIL OFL 1.1) 2026-04-30 03:57:17 +01:00

veilor-os

Hardened minimal Fedora KDE remix. Black-on-black. Locked down by default.

veilor-os is a Fedora 43 KDE spin built for operators who want a clean, fast, opinionated desktop with serious hardening already in place. No prompts at install beyond the LUKS passphrase. Boot, set admin password, work.

Highlights

  • Single-prompt install — only LUKS passphrase. No account wizard, no initial-setup screen. admin account is created automatically; password is set on first boot.
  • Hardened by default — SELinux enforcing, USBGuard, fail2ban, firewalld drop zone, kernel sysctl lockdown, NTS-authenticated NTP, DNS-over-TLS.
  • 3-mode power managementveilor-power save | mid | perf, with AC/battery auto-switching via udev. Backed by tuned profiles.
  • Fira Code system font — programming ligatures, monospace consistency across UI + terminal. (DuckSans planned for v0.3.)
  • Pure-black KDE color schemeveilor-black theme system-wide.
  • LUKS2 + Secure Boot — argon2id, aes-xts, btrfs subvolumes, zram swap (no disk swap, no cold-boot leak).
  • Reproducible build — kickstart + podman + livemedia-creator. ISO output is deterministic given pinned base.

Repo layout

kickstart/   veilor-os.ks                full kickstart definition
build/       Containerfile + build-iso.sh   reproducible ISO builder
overlay/     files dropped into installed root via %post
scripts/     hardening, SELinux policy, theme apply, firstboot
assets/      fonts, KDE color scheme, branding, plymouth theme
docs/        HARDENING / POWER / BUILD / INSTALL
test/        boot-checklist + findings log

See docs/BUILD.md for build instructions, docs/INSTALL.md for install, docs/HARDENING.md for what's locked down and why.

Status

Pre-release. v0.x. Repo private until first green ISO boots clean on test hardware.

License

MIT — see LICENSE. Fira Code ships from Fedora's fira-code-fonts package under SIL OFL 1.1.