Use this
Unwoke setup
Pinned on the GNOME dash, first login, or ujust setup. Locks, leftover stock, daily user, Steam, Whonix, “this looks broken.” This is first-time setup.
First session
The desktop will feel quiet. No store. No Bluetooth. Sites may look “broken.” That is the healthy state, not a failed install. Walk this list once, in order. Then live with the defaults.
The one sentence. Do not open GNOME Software, Discover, or Settings → Apps. Open Unwoke setup in the app grid (also ujust setup). Nothing turns off until you pick it.
Three places. Most first-day mistakes are using the wrong one.
Use this
Pinned on the GNOME dash, first login, or ujust setup. Locks, leftover stock, daily user, Steam, Whonix, “this looks broken.” This is first-time setup.
Later, maybe
Wi-Fi network name, display scale, keyboard, night light. Not software. Not Bluetooth. Not “privacy” checkboxes. We already set those.
There isn’t one
Bazaar, GNOME Software, and Discover are gone on purpose. Searching Settings for “Software” is a dead end. Apps: Install an app.
Do
Create the daily user if asked. Reboot if a signed update is staged. Enroll their Secure Boot key. USBGuard with the devices you actually use. Then stop.
Do not
Do not enable Bluetooth, Flathub, brew, toolbox, and every browser pack in the first hour “to test.” Each one is a named need, later. ujust why if something looks broken.
On a USB install (and on first boot of a new image) you may see an installer-style screen on tty1 before GNOME or KDE starts. It asks for a daily username. The greeter waits. That is not a hung install.
If the screen appears
Pick a normal name and password. That account is for the graphical session. Wheel stays for TTY and run0. Empty name, Cancel, or a 5-minute skip leaves this pending — then Unwoke setup → Daily user. Do not log into GNOME/KDE as wheel if you can avoid it.
Login
The navy wallpaper and blue accent are the theme, not a second setup wizard. If the greeter refuses wheel, that is admin-split working. Use the daily account. Need privilege later: run0, not sudo.
If you see a reboot nag
The first rebase cannot check our stamp yet. After that boot, a service stages ostree-image-signed. If nobody is logged in, we reboot onto it once. If you are already in a session, a notification repeats until you reboot (Reboot button). Unwoke setup → Start → Reboot now.
rpm-ostree status
You want a staged signed deployment, then one reboot. Until then, updates are not locked to our cosign.pub. No staged row? Network, or the command on Install.
The window that opens
It autostarts on first login. App grid → Unwoke setup if you closed it. Same stamps as ujust setup. On Start: Keep all defaults (recommended). You can hide it on login after this session. Open it again any time. Tutorial buttons in the window open these pages offline if the image has help files.
Stock leftover tab
Overlay locks stay on. Do these on confirm:
secureblue. The kernel is still theirs.ujust set-kargs-hardening if you rebased instead of installing from a secureblue/Unwoke ISO.Full stock text: their post-install.
Daily user tab
Create the non-wheel account here. Then log out and into that user. Do not make a second wheel account and call it daily.
Stop
Flathub, Bluetooth, brew, toolbox, camera, JIT, WebGL: all intentional defaults. Live a day. When a headset or a site is a real task, open that tutorial — one lock. Extra browser packs make you rarer than stock Trivalent; that is the security default. Read Fingerprinting vs locks before loosening JIT or WebGL “to look normal.”
Trust
Unwoke setup → Start → Test everything Unwoke added, or:
ujust unwoke-test
ujust audit-secureblue
PASS = that lock is on this disk. LOOSE = you turned it off. FAIL = the image is missing what this flavor ships. Each line has a proof: path. Do not trust the script: see each lock yourself. Stock kernel/USBGuard/malloc is the second command. Longer version: Check health.
Now Settings is fine
GNOME Settings or KDE System Settings: join a Wi-Fi network, set scale, night light, input. Do not look there for a store, Bluetooth enable (the service is masked until Unwoke setup → Turn on), or Users as a way around admin-split. Wallpaper is already Unwoke; change it in Settings if you want, or ujust set-unwoke-theme apply to put it back.
Tabs. Nothing auto-unlocks. The TUI (ujust setup) is the same list if GTK is missing.
Start
Recommended button. Status. Reboot now if a signed image is staged. “Don’t show on login” after you have done this once.
Turn on
Flathub verified, Bluetooth, camera, NFS/CIFS, toolbox, brew. Each line is optional. Wi-Fi is already on.
Looks broken
JIT, WebGL, browser camera, Flatpaks, no store, Flatpak mic, NAS. Maps the symptom. Still your click. Same as ujust why.
Stock leftover
Secure Boot key, hardening kargs, USBGuard, stock audit. Overlay locks unchanged.
Daily user
If tty1 was skipped. Graphical session as a normal account. run0 when you need wheel.
You loosened
Only what you turned off. Restoring one does not unlock the rest.
Strict apps
Proton.me, IVPN, Mullvad: web or WireGuard first. Official RPM only after a checksum and an asked extra origin. Not day-one work unless that is why you installed.
Settings is a settings app. It is not the security control panel.
| You want | Go here |
|---|---|
| Join Wi-Fi, pick a display, keyboard layout | GNOME Settings / KDE System Settings |
| Bluetooth headphones | Unwoke setup → Turn on, then Settings. Service is masked until then. Bluetooth |
| Install an app | Not Settings. Verified Flathub then Flatpak, or a vendor wizard. Install an app |
| Webcam / mic for a call | Kernel lock and browser policy are two doors. Camera and mic |
| A site looks broken | Unwoke setup → Looks broken (usually JIT or WebGL). Sites |
| Users / “admin on the login screen” | Unwoke Daily user. Not Settings → Users as wheel |
| Privacy checkboxes, telemetry, connectivity | Already off. Do not turn Fedora countme or connectivity-check on to “fix” hotel Wi-Fi until you need that one lock. Privacy |
You are done with first-time setup when: daily user exists, signed reboot happened, their key/USBGuard are done, and you have not loosened a pile of locks. Command dump for later: Post-install. Everyday tasks: Tutorials.
If it still feels broken. App grid → Unwoke setup → Looks broken, or ujust why. That menu names the lock. It does not auto-unlock. Workarounds for stock bugs that hit this overlay: Workarounds.