Repository navigation
Releases: dasmatus/losos
Release list
Now 100% more functional
What's Changed
- Fix Nix proxy publishing failure on empty references by @dasmatus with @Copilot in #37
- fix(security): close the claim-window, loopback, mesh-pod and edge DoS holes by @dasmatus in #38
- fix(boot): let the installed system find its disk inside a VM by @dasmatus in #44
- fix: the six code findings from the critical review (wizard claim, admin key, pins, gc, TPM default, change) by @dasmatus in #45
- ci: simplify devenv update to use nixpkgs devenv by @dasmatus in #46
- feat(install): seal the disk key to the TPM2 by default; --no-tpm opts out; fix the NUL-stripped keyfile by @dasmatus in #48
- fix(installer): write a keyfile that survives disko's shell substitution by @dasmatus in #47
- fix(upgrade): read the box's install-target.nix and overrides.nix under --impure so a remote upgrade keeps them by @dasmatus in #49
- deps(cargo)(deps): bump the cargo-major group across 2 directories with 2 updates by @dependabot[bot] in #43
- deps(github-actions)(deps): bump the githubactions-major group across 1 directory with 3 updates by @dependabot[bot] in #41
- deps(npm)(deps): bump the npm-major group across 2 directories with 5 updates by @dependabot[bot] in #40
- feat(edge): run the registrar as a Vercel Function for the demo (edge-vercel/) by @dasmatus in #50
- fix(wizard, install): wait for Nextcloud before the first password; stop the chown errors in nixos-install by @dasmatus in #51
- Fix the Nextcloud pod crash loop (/run/nextcloud) and surface a dying pod's last log line in the wizard by @dasmatus in #55
- Survive a claim reply lost in transit: replay the admin key to the same password, retry in the wizard, 10-minute API timeout by @dasmatus in #56
- deps(cargo): bump the cargo-minor-patch group across 2 directories with 4 updates by @dependabot[bot] in #54
- deps(npm): bump the npm-minor-patch group across 2 directories with 8 updates by @dependabot[bot] in #53
- deps(github-actions): bump actions/checkout from 4 to 7 in the githubactions-major group across 1 directory by @dependabot[bot] in #52
- Build every Rust binary with mold, ccache and sccache by @dasmatus in #59
- feat(cache): the appliance and installer pull from losos-proxy.dasmat.us by default by @dasmatus in #57
- deps(npm): bump source-map-js from 1.2.1 to 1.2.2 in /admin-ui/app in the npm-security group across 1 directory by @dependabot[bot] in #58
Full Changelog: v0.1.5...v0.1.6
Installer ISO
losos-installer-v0.1.6.iso — 1.43 GiB
sha256 83a624f70cb842bc445866b394793eb38b5321ac9b095cd341d34a53e3a1da15
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.6/losos-installer-v0.1.6.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.6/losos-installer-v0.1.6.iso
sha256sum -c losos-installer-v0.1.6.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from f2993c3 by this workflow run.
Demo QCOW2
losos-demo-v0.1.6.qcow2 — 5.56 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.6.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74
echo "c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74 losos-demo-v0.1.6.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.6
sha256sum -c losos-demo-v0.1.6.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.6
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2BIOS support
Installer ISO
losos-installer-v0.1.5.iso — 1.43 GiB
sha256 89b7c80ffe124103664bdd814685f8370faaa96284c452bf8bbd29339b1e113b
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.5/losos-installer-v0.1.5.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.5/losos-installer-v0.1.5.iso
sha256sum -c losos-installer-v0.1.5.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from 415d74e by this workflow run.
Demo QCOW2
losos-demo-v0.1.5.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 73424148a054e34b37e238a7fae76fd32b90e81d4548e685f40bf76e9cb48239
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.5.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:73424148a054e34b37e238a7fae76fd32b90e81d4548e685f40bf76e9cb48239
echo "73424148a054e34b37e238a7fae76fd32b90e81d4548e685f40bf76e9cb48239 losos-demo-v0.1.5.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.5
sha256sum -c losos-demo-v0.1.5.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.5
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2You can now get paid for sharing your storage and compute (for real this time)
Installer ISO
losos-installer-v0.1.4.1.2.iso — 1.43 GiB
sha256 a7b97fcd4c901092b0bbfd81be9b8f588b2afff45f73b9c6aa48421d9342f99d
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1.2/losos-installer-v0.1.4.1.2.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1.2/losos-installer-v0.1.4.1.2.iso
sha256sum -c losos-installer-v0.1.4.1.2.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from 9de1fba by this workflow run.
Demo QCOW2
losos-demo-v0.1.4.1.2.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 d85d028ec5b04df2d159cf24902c8cda595d656adeda6101394b7e103c88678d
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.4.1.2.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:d85d028ec5b04df2d159cf24902c8cda595d656adeda6101394b7e103c88678d
echo "d85d028ec5b04df2d159cf24902c8cda595d656adeda6101394b7e103c88678d losos-demo-v0.1.4.1.2.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.4.1.2
sha256sum -c losos-demo-v0.1.4.1.2.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.4.1.2
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2Get paid for sharing your storage
Installer ISO
losos-installer-v0.1.4.1.iso — 1.43 GiB
sha256 bf38a6c323372bccc796bf72c0403e7ee90df610b695b5af1f73244033cd1393
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1/losos-installer-v0.1.4.1.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4.1/losos-installer-v0.1.4.1.iso
sha256sum -c losos-installer-v0.1.4.1.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from 4f977d6 by this workflow run.
Demo QCOW2
losos-demo-v0.1.4.1.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 2d0acf29f2b3a422e368905d82ff77377bc3ec5bd19f811a74c4aa34bbda78de
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.4.1.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:2d0acf29f2b3a422e368905d82ff77377bc3ec5bd19f811a74c4aa34bbda78de
echo "2d0acf29f2b3a422e368905d82ff77377bc3ec5bd19f811a74c4aa34bbda78de losos-demo-v0.1.4.1.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.4.1
sha256sum -c losos-demo-v0.1.4.1.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.4.1
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2Visual consistency, yay!
Installer ISO
losos-installer-v0.1.4.iso — 1.43 GiB
sha256 d652ae9d6751d86bc16382e3566ea468d54417795c8e902636b92f7b0fded6ca
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4/losos-installer-v0.1.4.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.4/losos-installer-v0.1.4.iso
sha256sum -c losos-installer-v0.1.4.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from ed7dbd5 by this workflow run.
Demo QCOW2
losos-demo-v0.1.4.qcow2 — 4.78 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 4071b7a94df5b1f9e6aa52c22d3e4c41a193eb1e70f0d03b68770752b3c5e2fd
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.4.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:4071b7a94df5b1f9e6aa52c22d3e4c41a193eb1e70f0d03b68770752b3c5e2fd
echo "4071b7a94df5b1f9e6aa52c22d3e4c41a193eb1e70f0d03b68770752b3c5e2fd losos-demo-v0.1.4.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.4
sha256sum -c losos-demo-v0.1.4.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.4
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2Now that we have our own cache...
Installer ISO
losos-installer-v0.1.3.iso — 1.43 GiB
sha256 1d2e28dd90578374a8e40b5953a16110cfeeccfa8a1240a49eb91372b9e9b3a2
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.3/losos-installer-v0.1.3.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.3/losos-installer-v0.1.3.iso
sha256sum -c losos-installer-v0.1.3.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from 9b44916 by this workflow run.
Demo QCOW2
losos-demo-v0.1.3.qcow2 — 4.55 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 95857c6af1a73b51be87152d2b2896c9d633c0b3c271343b9999900c0581b9af
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.3.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:95857c6af1a73b51be87152d2b2896c9d633c0b3c271343b9999900c0581b9af
echo "95857c6af1a73b51be87152d2b2896c9d633c0b3c271343b9999900c0581b9af losos-demo-v0.1.3.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.3
sha256sum -c losos-demo-v0.1.3.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.3
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2It should now wait for network
Installer ISO
losos-installer-v0.1.2.iso — 1.43 GiB
sha256 7a1fa33afc1f29881f64e9db8d4e32599744ee8cb1ea1887de0edc5392ce0006
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.2/losos-installer-v0.1.2.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.2/losos-installer-v0.1.2.iso
sha256sum -c losos-installer-v0.1.2.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Built from 1f826d5 by this workflow run.
Demo QCOW2
losos-demo-v0.1.2.qcow2 — 4.55 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.
sha256 a14e4d7de21982266452ff84610f48121ea58516c1c0a481314880fd0a30ea33
Download the layer directly with curl (the token is anonymous):
token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.2.qcow2 \
https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:a14e4d7de21982266452ff84610f48121ea58516c1c0a481314880fd0a30ea33
echo "a14e4d7de21982266452ff84610f48121ea58516c1c0a481314880fd0a30ea33 losos-demo-v0.1.2.qcow2" | sha256sum -cOr pull it with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.2
sha256sum -c losos-demo-v0.1.2.qcow2.sha256This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.2
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2Or substitute the already-built store paths recorded in release.json
from the project cache:
nix copy --from https://losos.cachix.org /nix/store/138xnh7sj5ks0nc8f436fnyp8czdysxy-nixos-minimal-26.11.20260916.b1b8759-x86_64-linux.iso
nix copy --from https://losos.cachix.org /nix/store/nifgn9af5bsf737fwk9gh977c9klfmkg-losos-disk-qcow2These beautiful things that I got
Installer ISO
losos-installer-v0.1.1.iso — 1.43 GiB
sha256 912981956bed9d299b7cb6fed884ed08e158692bcc77e0fc8f81078ecc9e7105
Verify it with:
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.1/losos-installer-v0.1.1.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.1/losos-installer-v0.1.1.iso
sha256sum -c losos-installer-v0.1.1.iso.sha256Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.
Demo QCOW2
losos-demo-v0.1.1.qcow2 — 4.55 GiB, too large for a GitHub release asset.
Pull it from GHCR with oras, which fetches the
.sha256 beside it:
oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.1
sha256sum -c losos-demo-v0.1.1.qcow2.sha256sha256 207232ec9801a428eedc695672aa556883fb14e56c90437a0f6f028092a36de3
This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.
The installer ISO is on GHCR too: oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.1
Build the installer ISO from this tag instead:
nix build .#nixosConfigurations.iso.config.system.build.isoImageBuild the demo QCOW2 instead:
nix build .#losos-disk-qcow2Or substitute the already-built store paths recorded in release.json
from the project cache:
nix copy --from https://losos.cachix.org /nix/store/hadyyz33jqandgg3m7z9gaa2vp23dhnv-nixos-minimal-26.11.20260916.b1b8759-x86_64-linux.iso
nix copy --from https://losos.cachix.org /nix/store/8h162q6f6irz23nvqdpfia84md4z4fxl-losos-disk-qcow2Initial release
What's Changed
- ci: add a GitHub Actions lane beside the Forgejo one by @dasmatus in #1
- fix(ci): import the sibling job's store export by path, not with --all by @dasmatus in #3
- Publish ISO and QCOW2 via Codeberg generic registry by @dasmatus with @Copilot in #2
- build(deps): bump disko from
ff8702bto4084b6cby @dependabot[bot] in #5 - build(deps): bump nixpkgs from
f13ff45tob1b8759by @dependabot[bot] in #4 - Classify code scanning alerts #1–#19 as false positives by @dasmatus with @Copilot in #6
- Add weekly lockfile refresh workflow by @dasmatus with @Copilot in #7
- Pin lockfile refresh to the locked
devenvrevision by @dasmatus with @Copilot in #8 - fix(nix): bump admin-ui playwright pin to nixpkgs 1.63.0 and refresh npmDepsHash by @dasmatus in #17
New Contributors
- @dasmatus made their first contribution in #1
- @dasmatus with @Copilot made their first contribution in #2
- @dependabot[bot] made their first contribution in #5
Full Changelog: https://github.com/dasmatus/losos/commits/v0.1.0