Stay current

Updates and rollback

Keep locked After the signed reboot, the PC follows ghcr.io/sergi270710267/… and checks our cosign.pub. Do not switch back to an unverified origin to “fix” an update.

  1. Let it update

    Stock automatic updates stay. We rebuild overlay images twice a day. You do not click a store. A staged deployment needs a reboot to become the booted one.

  2. See what is coming

    rpm-ostree status

    Look for a staged deployment and whether the origin is ostree-image-signed. If the first boot never staged signed (no network), use the command on Install.

  3. Reboot when it is staged

    Same as the first hour. Notification Reboot button, Setup → Reboot now, or:

    systemctl reboot
  4. Roll back a bad bake

    Atomic desktops keep the previous deployment. This is the standard recovery, not a reinstall.

    rpm-ostree rollback
    systemctl reboot

    Pin a known-good deployment if you need it to survive the next update (stock ostree admin pin / their docs). Do not rpm-ostree rebase onto random unsigned tags.

Factory canary + inspect run on GitHub, not on your laptop. If you care that this disk matches what we published: check health.