First session

After you log in

The desktop will feel quiet. No store. No Bluetooth. Sites may look “broken.” That is the healthy state, not a failed install. Walk this list once, in order. Then live with the defaults.

About 20 minutes Keep the locks Settings is not setup

The one sentence. Do not open GNOME Software, Discover, or Settings → Apps. Open Unwoke setup in the app grid (also ujust setup). Nothing turns off until you pick it.

Where to click

Three places. Most first-day mistakes are using the wrong one.

Use this

Unwoke setup

Pinned on the GNOME dash, first login, or ujust setup. Locks, leftover stock, daily user, Steam, Whonix, “this looks broken.” This is first-time setup.

Later, maybe

GNOME / KDE Settings

Wi-Fi network name, display scale, keyboard, night light. Not software. Not Bluetooth. Not “privacy” checkboxes. We already set those.

There isn’t one

A software store

Bazaar, GNOME Software, and Discover are gone on purpose. Searching Settings for “Software” is a dead end. Apps: Install an app.

Do this / not that

Do

Keep defaults for a day

Create the daily user if asked. Reboot if a signed update is staged. Enroll their Secure Boot key. USBGuard with the devices you actually use. Then stop.

Do not

Make it “feel like Fedora”

Do not enable Bluetooth, Flathub, brew, toolbox, and every browser pack in the first hour “to test.” Each one is a named need, later. ujust why if something looks broken.

Before the login window

On a USB install (and on first boot of a new image) you may see an installer-style screen on tty1 before GNOME or KDE starts. It asks for a daily username. The greeter waits. That is not a hung install.

  1. If the screen appears

    Create a daily (non-wheel) user

    Pick a normal name and password. That account is for the graphical session. Wheel stays for TTY and run0. Empty name, Cancel, or a 5-minute skip leaves this pending — then Unwoke setup → Daily user. Do not log into GNOME/KDE as wheel if you can avoid it.

First graphical login, in order

  1. Login

    Sign in as the daily user

    The navy wallpaper and blue accent are the theme, not a second setup wizard. If the greeter refuses wheel, that is admin-split working. Use the daily account. Need privilege later: run0, not sudo.

  2. If you see a reboot nag

    Reboot onto the signed image first

    The first rebase cannot check our stamp yet. After that boot, a service stages ostree-image-signed. If nobody is logged in, we reboot onto it once. If you are already in a session, a notification repeats until you reboot (Reboot button). Unwoke setup → Start → Reboot now.

    rpm-ostree status

    You want a staged signed deployment, then one reboot. Until then, updates are not locked to our cosign.pub. No staged row? Network, or the command on Install.

  3. The window that opens

    Stay in Unwoke setup

    It autostarts on first login. App grid → Unwoke setup if you closed it. Same stamps as ujust setup. On Start: Keep all defaults (recommended). You can hide it on login after this session. Open it again any time. Tutorial buttons in the window open these pages offline if the image has help files.

  4. Stock leftover tab

    Their steps, not ours

    Overlay locks stay on. Do these on confirm:

    • Enroll the secureblue Secure Boot key if the installer prompt did not run. BIOS password is secureblue. The kernel is still theirs.
    • ujust set-kargs-hardening if you rebased instead of installing from a secureblue/Unwoke ISO.
    • USBGuard: Unwoke setup → USBGuard (default No) after you are in GNOME/KDE. Plug in the keyboard/mouse you trust first if you say Yes. We do not block the login screen on tty1. Detail: USB.

    Full stock text: their post-install.

  5. Daily user tab

    Only if you skipped tty1

    Create the non-wheel account here. Then log out and into that user. Do not make a second wheel account and call it daily.

  6. Stop

    Do not “turn everything on”

    Flathub, Bluetooth, brew, toolbox, camera, JIT, WebGL: all intentional defaults. Live a day. When a headset or a site is a real task, open that tutorial — one lock. Extra browser packs make you rarer than stock Trivalent; that is the security default. Read Fingerprinting vs locks before loosening JIT or WebGL “to look normal.”

  7. Trust

    Confirm the box is what we shipped

    Unwoke setup → Start → Test everything Unwoke added, or:

    ujust unwoke-test
    ujust audit-secureblue

    PASS = that lock is on this disk. LOOSE = you turned it off. FAIL = the image is missing what this flavor ships. Each line has a proof: path. Do not trust the script: see each lock yourself. Stock kernel/USBGuard/malloc is the second command. Longer version: Check health.

  8. Now Settings is fine

    Wi-Fi, display, keyboard — not apps

    GNOME Settings or KDE System Settings: join a Wi-Fi network, set scale, night light, input. Do not look there for a store, Bluetooth enable (the service is masked until Unwoke setup → Turn on), or Users as a way around admin-split. Wallpaper is already Unwoke; change it in Settings if you want, or ujust set-unwoke-theme apply to put it back.

How to read Unwoke setup

Tabs. Nothing auto-unlocks. The TUI (ujust setup) is the same list if GTK is missing.

Start

Keep defaults, reboot, hide

Recommended button. Status. Reboot now if a signed image is staged. “Don’t show on login” after you have done this once.

Turn on

Named needs only

Flathub verified, Bluetooth, camera, NFS/CIFS, toolbox, brew. Each line is optional. Wi-Fi is already on.

Looks broken

It is probably a lock

JIT, WebGL, browser camera, Flatpaks, no store, Flatpak mic, NAS. Maps the symptom. Still your click. Same as ujust why.

Stock leftover

Their post-install

Secure Boot key, hardening kargs, USBGuard, stock audit. Overlay locks unchanged.

Daily user

Non-wheel on the greeter

If tty1 was skipped. Graphical session as a normal account. run0 when you need wheel.

You loosened

Put a lock back

Only what you turned off. Restoring one does not unlock the rest.

Strict apps

No store. Wizards later.

Proton.me, IVPN, Mullvad: web or WireGuard first. Official RPM only after a checksum and an asked extra origin. Not day-one work unless that is why you installed.

GNOME / KDE Settings vs Unwoke

Settings is a settings app. It is not the security control panel.

You wantGo here
Join Wi-Fi, pick a display, keyboard layout GNOME Settings / KDE System Settings
Bluetooth headphones Unwoke setup → Turn on, then Settings. Service is masked until then. Bluetooth
Install an app Not Settings. Verified Flathub then Flatpak, or a vendor wizard. Install an app
Webcam / mic for a call Kernel lock and browser policy are two doors. Camera and mic
A site looks broken Unwoke setup → Looks broken (usually JIT or WebGL). Sites
Users / “admin on the login screen” Unwoke Daily user. Not Settings → Users as wheel
Privacy checkboxes, telemetry, connectivity Already off. Do not turn Fedora countme or connectivity-check on to “fix” hotel Wi-Fi until you need that one lock. Privacy

After this session

You are done with first-time setup when: daily user exists, signed reboot happened, their key/USBGuard are done, and you have not loosened a pile of locks. Command dump for later: Post-install. Everyday tasks: Tutorials.

Tutorials Post-install table Health check

If it still feels broken. App grid → Unwoke setup → Looks broken, or ujust why. That menu names the lock. It does not auto-unlock. Workarounds for stock bugs that hit this overlay: Workarounds.