Post-install

Just logged in? The ordered walkthrough is After you log in (Unwoke setup, not GNOME Settings). This page is the command dump. Same slot as on secureblue.dev. Overlay steps first, then theirs. Strict apps without a store: ujust install-proton, ujust install-ivpn, ujust install-mullvad, or ujust install-vendor NAME.

After you log in

Unwoke SecureBlue

  1. After the first rebase reboot, a notification (and MOTD) says when the signed image is staged. It repeats every login and every 15 minutes until you reboot. App grid → Unwoke setup → Reboot now.
  2. A first-login window lists the locks. Nothing turns off unless you pick it. Hide it on login, or open Unwoke setup / ujust setup later. ujust why is “this is a lock, not a bug.” Stock leftover (Secure Boot key, kargs, USBGuard) does not change overlay locks. Tutorial buttons open Tutorials.
  3. Confirm the overlay:
ujust setup
ujust why
ujust unwoke-status
ujust audit-unwoke
ujust audit-secureblue

Full toggle table: Features. Restart the house browser after policy changes. If something “broke,” it is usually a default lock — the setup menu maps the usual ones and does not auto-unlock.

Default off (stock has these on): Flathub, Homebrew, Bluetooth, toolbox/distrobox, camera/mic hardware, Fedora countme, connectivity-check, DHCP hostname, file thumbnails. Default on (loosen with off): Flatpak lockdown, Origin/Trivalent policy packs (including no hyperlink ping), Origin Bubblejail, isolation, extra sandbox, Trivalent Network Service Sandbox + referrer flags. Browserless only: host browsers stay blocked until ujust set-allow-browsers on ALLOW.

If this happensRun
Site needs JITujust set-brave-jitless off
Need camera / mic / USB in the browserujust set-brave-devices off
Need passwords / autofillujust set-brave-hardening off
Need extensionsujust set-brave-extensions allow
Need Flathub (stock-like)ujust set-flathub verified
Need unfiltered Flathubujust set-flathub full
Need Steamujust install-steam (asks overlay locks)
Play a game then lock againClick Steam. Close it. Restore is automatic.
Need Bluetoothujust set-bluetooth on
Need toolbox / distroboxujust set-toolbox on
Need Avahi (.local) or a modemujust set-extra-daemons on
Hotel Wi-Fi login page never appearsujust set-connectivity-check on
LAN needs this PC’s hostnameujust set-dhcp-hostname on
Files has no previewsujust set-thumbnails on
Want Fedora countmeujust set-countme on
Want stock deprecation / Flathub-setup noticesujust set-stock-nags on
Flatpaks are brokenujust set-flatpak-lockdown off
Want wallpaper / accent backujust set-unwoke-theme apply
WebGL/WebGPU neededujust set-brave-isolation off
Bubblejail breaks GPU/audio (Origin)ujust set-brave-bubblejail off
Trivalent clears cookies on exitujust set-trivalent-network-sandbox off
Need screen capture / JS optimizerujust set-brave-sandbox off
Need chrome://devtools lockedujust set-brave-devtools lock
Need Homebrewujust set-brew on
Need webcam / micujust set-camera-mic on
Need wheel on the greeterujust set-admin-split off
Create a daily (non-wheel) userujust set-admin-split add NAME
Browserless: install a host browserujust set-allow-browsers on ALLOW

Lock screen / wallpaper gallery: Brand.

Stock secureblue (mirrored)

You still do their post-install: enroll their Secure Boot key if the prompt did not appear, ujust set-kargs-hardening if you rebased instead of installing from their ISO, USBGuard, optional separate wheel account. Full text, updated daily from their repo:

Their post-install (mirrored)

Canonical: https://secureblue.dev/post-install