Tutorials

Common things on this desktop, secure path first. Vendor apps below are generated from vendor-installers.json at Pages deploy so the hub cannot drift.

How to use these. The recommended step keeps the lock. Nothing auto-unlocks Flathub, Bluetooth, the webcam, JIT, or a store (there is no store).

Install: Install. First session: After you log in. Checklist: Post-install. Vs stock: Compared.

First days

Start

After you log in

Unwoke setup, not GNOME Settings. Daily user, signed reboot, leftover stock. Keep the locks.

Stay current

Updates and rollback

Updates are automatic and signed. Check status, reboot, roll back if a bake is bad.

Trust

Check the box is what we shipped

ujust unwoke-test: PASS/LOOSE/FAIL with proof for every overlay lock. Then stock audit and cosign.

Trust

See each lock yourself

Do not trust our script. Type these read-only commands and look at the files. Same proofs, one at a time.

Accounts

Daily user vs wheel

Graphical session as a non-admin. run0 when you need privilege. That is the standard.

Apps and files

Software

Install an app

No GUI store. Verified Flathub, then Flatpak. Lockdown stays; grant in Flatseal.

Games

Steam

Same stock Flatpak. Overlay locks that would break games are asked first. Nothing silent.

Games

Play window

GameMode while you play. Close the game, full locks. No CachyOS kernel swap.

Software

Stock installers

install-steam, install-vpn, install-docker, enable-dangerzone, distrobox-assemble, unfiltered Flathub — intercepted. Asked, not silent.

Anonymity

Whonix KVM

Official images, OpenPGP, clipboard/USB/mic off. Gateway then Workstation. Not Qubes, not Tails.

Anonymity

Stay unnamed

Host is not Tor. Whonix for IP. TCP timestamps off. Do not mix accounts.

Peripherals

USB sticks and gadgets

USBGuard: allow what is plugged in now, block the rest. Do this once, on purpose.

Hardware people expect to “just work”

Radio

Bluetooth headphones

Off on purpose. Wi-Fi is already on. Turn BT on only if you need it.

Calls

Webcam and microphone

Kernel lock and browser policy are two different doors. Open the smallest one.

NAS

Network shares (NFS/CIFS)

Clients are locked. Stock only masks the NFS server. Turn on only if you mount a NAS.

Meetings

Screen share

Extra sandbox blocks capture. Loosen that pack, not the whole browser.

Browser and network

Web

A site looks broken

Usually JIT-less or WebGL. That is a lock. Do not flatten every policy for one page.

Web

Fingerprinting vs locks

Security first. Extra browser packs make you rarer than stock Trivalent. Phone-home off does not. Blend only if you choose.

Network

VPN without DNS leaks

Keep system DNS on the VPN’s resolver. Skip Trivalent DoH if you tunnel.

Power tools

Containers

toolbox / distrobox

Off. Prefer Flatpak. Turn the wrappers back into real bins only when you need a pet container.

Strict apps (from the vendor list)

Proton.me

Mail, Pass, VPN

Wizard, not a store. Trivalent/WireGuard first. SHA512 on official RPMs.

IVPN

WireGuard, then official app

VPN + AntiTracker in their client. Import first. No Snap.

Mullvad

VPN, WireGuard first

Same vendor list. Official app only if you accept their repo.

Vpn Dns

Tailscale official Fedora repo

Watched and healed. Strictest keys first. No store.

Whonix

Whonix KVM

Watched and healed. Strictest keys first. No store.