Skip to content

Releases: dasmatus/losos

Now 100% more functional

Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 06 Oct 09:56

What's Changed

  • Fix Nix proxy publishing failure on empty references by @dasmatus with @Copilot in #37
  • fix(security): close the claim-window, loopback, mesh-pod and edge DoS holes by @dasmatus in #38
  • fix(boot): let the installed system find its disk inside a VM by @dasmatus in #44
  • fix: the six code findings from the critical review (wizard claim, admin key, pins, gc, TPM default, change) by @dasmatus in #45
  • ci: simplify devenv update to use nixpkgs devenv by @dasmatus in #46
  • feat(install): seal the disk key to the TPM2 by default; --no-tpm opts out; fix the NUL-stripped keyfile by @dasmatus in #48
  • fix(installer): write a keyfile that survives disko's shell substitution by @dasmatus in #47
  • fix(upgrade): read the box's install-target.nix and overrides.nix under --impure so a remote upgrade keeps them by @dasmatus in #49
  • deps(cargo)(deps): bump the cargo-major group across 2 directories with 2 updates by @dependabot[bot] in #43
  • deps(github-actions)(deps): bump the githubactions-major group across 1 directory with 3 updates by @dependabot[bot] in #41
  • deps(npm)(deps): bump the npm-major group across 2 directories with 5 updates by @dependabot[bot] in #40
  • feat(edge): run the registrar as a Vercel Function for the demo (edge-vercel/) by @dasmatus in #50
  • fix(wizard, install): wait for Nextcloud before the first password; stop the chown errors in nixos-install by @dasmatus in #51
  • Fix the Nextcloud pod crash loop (/run/nextcloud) and surface a dying pod's last log line in the wizard by @dasmatus in #55
  • Survive a claim reply lost in transit: replay the admin key to the same password, retry in the wizard, 10-minute API timeout by @dasmatus in #56
  • deps(cargo): bump the cargo-minor-patch group across 2 directories with 4 updates by @dependabot[bot] in #54
  • deps(npm): bump the npm-minor-patch group across 2 directories with 8 updates by @dependabot[bot] in #53
  • deps(github-actions): bump actions/checkout from 4 to 7 in the githubactions-major group across 1 directory by @dependabot[bot] in #52
  • Build every Rust binary with mold, ccache and sccache by @dasmatus in #59
  • feat(cache): the appliance and installer pull from losos-proxy.dasmat.us by default by @dasmatus in #57
  • deps(npm): bump source-map-js from 1.2.1 to 1.2.2 in /admin-ui/app in the npm-security group across 1 directory by @dependabot[bot] in #58

Full Changelog: v0.1.5...v0.1.6

Installer ISO

losos-installer-v0.1.6.iso — 1.43 GiB

sha256  83a624f70cb842bc445866b394793eb38b5321ac9b095cd341d34a53e3a1da15

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.6/losos-installer-v0.1.6.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.6/losos-installer-v0.1.6.iso
sha256sum -c losos-installer-v0.1.6.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from f2993c3 by this workflow run.

Demo QCOW2

losos-demo-v0.1.6.qcow2 — 5.56 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.6.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74
echo "c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74  losos-demo-v0.1.6.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.6
sha256sum -c losos-demo-v0.1.6.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.6


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

BIOS support

BIOS support Pre-release
Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 03 Oct 04:38

Installer ISO

losos-installer-v0.1.5.iso — 1.43 GiB

sha256  89b7c80ffe124103664bdd814685f8370faaa96284c452bf8bbd29339b1e113b

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.5/losos-installer-v0.1.5.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.5/losos-installer-v0.1.5.iso
sha256sum -c losos-installer-v0.1.5.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from 415d74e by this workflow run.

Demo QCOW2

losos-demo-v0.1.5.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  73424148a054e34b37e238a7fae76fd32b90e81d4548e685f40bf76e9cb48239

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.5.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:73424148a054e34b37e238a7fae76fd32b90e81d4548e685f40bf76e9cb48239
echo "73424148a054e34b37e238a7fae76fd32b90e81d4548e685f40bf76e9cb48239  losos-demo-v0.1.5.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.5
sha256sum -c losos-demo-v0.1.5.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.5


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

You can now get paid for sharing your storage and compute (for real this time)

Choose a tag to compare

@dasmatus dasmatus released this 02 Oct 17:41

Installer ISO

losos-installer-v0.1.4.1.2.iso — 1.43 GiB

sha256  a7b97fcd4c901092b0bbfd81be9b8f588b2afff45f73b9c6aa48421d9342f99d

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1.2/losos-installer-v0.1.4.1.2.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1.2/losos-installer-v0.1.4.1.2.iso
sha256sum -c losos-installer-v0.1.4.1.2.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from 9de1fba by this workflow run.

Demo QCOW2

losos-demo-v0.1.4.1.2.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  d85d028ec5b04df2d159cf24902c8cda595d656adeda6101394b7e103c88678d

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.4.1.2.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:d85d028ec5b04df2d159cf24902c8cda595d656adeda6101394b7e103c88678d
echo "d85d028ec5b04df2d159cf24902c8cda595d656adeda6101394b7e103c88678d  losos-demo-v0.1.4.1.2.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.4.1.2
sha256sum -c losos-demo-v0.1.4.1.2.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.4.1.2


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

Get paid for sharing your storage

Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 02 Oct 15:45

Installer ISO

losos-installer-v0.1.4.1.iso — 1.43 GiB

sha256  bf38a6c323372bccc796bf72c0403e7ee90df610b695b5af1f73244033cd1393

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1/losos-installer-v0.1.4.1.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1/losos-installer-v0.1.4.1.iso
sha256sum -c losos-installer-v0.1.4.1.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from 4f977d6 by this workflow run.

Demo QCOW2

losos-demo-v0.1.4.1.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  2d0acf29f2b3a422e368905d82ff77377bc3ec5bd19f811a74c4aa34bbda78de

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.4.1.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:2d0acf29f2b3a422e368905d82ff77377bc3ec5bd19f811a74c4aa34bbda78de
echo "2d0acf29f2b3a422e368905d82ff77377bc3ec5bd19f811a74c4aa34bbda78de  losos-demo-v0.1.4.1.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.4.1
sha256sum -c losos-demo-v0.1.4.1.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.4.1


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

Visual consistency, yay!

Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 02 Oct 14:18

Installer ISO

losos-installer-v0.1.4.iso — 1.43 GiB

sha256  d652ae9d6751d86bc16382e3566ea468d54417795c8e902636b92f7b0fded6ca

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4/losos-installer-v0.1.4.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4/losos-installer-v0.1.4.iso
sha256sum -c losos-installer-v0.1.4.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from ed7dbd5 by this workflow run.

Demo QCOW2

losos-demo-v0.1.4.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  4071b7a94df5b1f9e6aa52c22d3e4c41a193eb1e70f0d03b68770752b3c5e2fd

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.4.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:4071b7a94df5b1f9e6aa52c22d3e4c41a193eb1e70f0d03b68770752b3c5e2fd
echo "4071b7a94df5b1f9e6aa52c22d3e4c41a193eb1e70f0d03b68770752b3c5e2fd  losos-demo-v0.1.4.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.4
sha256sum -c losos-demo-v0.1.4.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.4


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

Now that we have our own cache...

Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 01 Oct 09:46

Installer ISO

losos-installer-v0.1.3.iso — 1.43 GiB

sha256  1d2e28dd90578374a8e40b5953a16110cfeeccfa8a1240a49eb91372b9e9b3a2

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.3/losos-installer-v0.1.3.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.3/losos-installer-v0.1.3.iso
sha256sum -c losos-installer-v0.1.3.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from 9b44916 by this workflow run.

Demo QCOW2

losos-demo-v0.1.3.qcow2 — 4.55 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  95857c6af1a73b51be87152d2b2896c9d633c0b3c271343b9999900c0581b9af

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.3.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:95857c6af1a73b51be87152d2b2896c9d633c0b3c271343b9999900c0581b9af
echo "95857c6af1a73b51be87152d2b2896c9d633c0b3c271343b9999900c0581b9af  losos-demo-v0.1.3.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.3
sha256sum -c losos-demo-v0.1.3.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.3


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

It should now wait for network

Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 01 Oct 08:40

Installer ISO

losos-installer-v0.1.2.iso — 1.43 GiB

sha256  7a1fa33afc1f29881f64e9db8d4e32599744ee8cb1ea1887de0edc5392ce0006

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.2/losos-installer-v0.1.2.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.2/losos-installer-v0.1.2.iso
sha256sum -c losos-installer-v0.1.2.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from 1f826d5 by this workflow run.

Demo QCOW2

losos-demo-v0.1.2.qcow2 — 4.55 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  a14e4d7de21982266452ff84610f48121ea58516c1c0a481314880fd0a30ea33

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.2.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:a14e4d7de21982266452ff84610f48121ea58516c1c0a481314880fd0a30ea33
echo "a14e4d7de21982266452ff84610f48121ea58516c1c0a481314880fd0a30ea33  losos-demo-v0.1.2.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.2
sha256sum -c losos-demo-v0.1.2.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.2


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

Or substitute the already-built store paths recorded in release.json
from the project cache:

nix copy --from https://losos.cachix.org /nix/store/138xnh7sj5ks0nc8f436fnyp8czdysxy-nixos-minimal-26.11.20260916.b1b8759-x86_64-linux.iso
nix copy --from https://losos.cachix.org /nix/store/nifgn9af5bsf737fwk9gh977c9klfmkg-losos-disk-qcow2

These beautiful things that I got

Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 30 Sep 17:53

Installer ISO

losos-installer-v0.1.1.iso — 1.43 GiB

sha256  912981956bed9d299b7cb6fed884ed08e158692bcc77e0fc8f81078ecc9e7105

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.1/losos-installer-v0.1.1.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.1/losos-installer-v0.1.1.iso
sha256sum -c losos-installer-v0.1.1.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Demo QCOW2

losos-demo-v0.1.1.qcow2 — 4.55 GiB, too large for a GitHub release asset.
Pull it from GHCR with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.1
sha256sum -c losos-demo-v0.1.1.qcow2.sha256
sha256  207232ec9801a428eedc695672aa556883fb14e56c90437a0f6f028092a36de3

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too: oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.1


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2

Or substitute the already-built store paths recorded in release.json
from the project cache:

nix copy --from https://losos.cachix.org /nix/store/hadyyz33jqandgg3m7z9gaa2vp23dhnv-nixos-minimal-26.11.20260916.b1b8759-x86_64-linux.iso
nix copy --from https://losos.cachix.org /nix/store/8h162q6f6irz23nvqdpfia84md4z4fxl-losos-disk-qcow2

Initial release

Initial release Pre-release
Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 23 Sep 09:08

What's Changed

  • ci: add a GitHub Actions lane beside the Forgejo one by @dasmatus in #1
  • fix(ci): import the sibling job's store export by path, not with --all by @dasmatus in #3
  • Publish ISO and QCOW2 via Codeberg generic registry by @dasmatus with @Copilot in #2
  • build(deps): bump disko from ff8702b to 4084b6c by @dependabot[bot] in #5
  • build(deps): bump nixpkgs from f13ff45 to b1b8759 by @dependabot[bot] in #4
  • Classify code scanning alerts #1–#19 as false positives by @dasmatus with @Copilot in #6
  • Add weekly lockfile refresh workflow by @dasmatus with @Copilot in #7
  • Pin lockfile refresh to the locked devenv revision by @dasmatus with @Copilot in #8
  • fix(nix): bump admin-ui playwright pin to nixpkgs 1.63.0 and refresh npmDepsHash by @dasmatus in #17

New Contributors

Full Changelog: https://github.com/dasmatus/losos/commits/v0.1.0