Enhance README formatting and emphasis on features
Updated README to emphasize key features and improve clarity.
This commit is contained in:
@@ -14,8 +14,8 @@ digital life — your files, communications, passwords, and websites — all on
|
|||||||
hardware you control, running auditable open-source software you can trust.
|
hardware you control, running auditable open-source software you can trust.
|
||||||
|
|
||||||
Every installation is a private [NixOS](https://nixos.org) desktop with
|
Every installation is a private [NixOS](https://nixos.org) desktop with
|
||||||
[Sparrow Wallet](https://sparrowwallet.com), [Bisq](https://bisq.network), and
|
**[Sparrow Wallet](https://sparrowwallet.com)**, **[Bisq](https://bisq.network)**,
|
||||||
[Bisq 2](https://github.com/bisq-network/bisq2) ready to use. Move beyond
|
and **[Bisq 2](https://github.com/bisq-network/bisq2)** ready to use. Move beyond
|
||||||
custodial exchanges from the first boot, and grow into your own Bitcoin node,
|
custodial exchanges from the first boot, and grow into your own Bitcoin node,
|
||||||
Lightning infrastructure, private cloud, and communications platform when you
|
Lightning infrastructure, private cloud, and communications platform when you
|
||||||
are ready.
|
are ready.
|
||||||
@@ -61,18 +61,18 @@ are ready.
|
|||||||
## Why Sovran_SystemsOS?
|
## Why Sovran_SystemsOS?
|
||||||
|
|
||||||
Bitcoin lets you hold and transfer value without asking a bank, exchange, or
|
Bitcoin lets you hold and transfer value without asking a bank, exchange, or
|
||||||
custodian for permission. But that freedom depends on the software and
|
custodian for permission, but that freedom depends on the software and
|
||||||
infrastructure you choose. Your wider digital life works the same way: files,
|
infrastructure you choose. Your wider digital life works the same way: files,
|
||||||
messages, and passwords kept on someone else's servers are never fully yours.
|
messages, and passwords kept on someone else's servers are never fully yours.
|
||||||
|
|
||||||
Sovran_SystemsOS solves both with one operating system:
|
Sovran_SystemsOS solves both with one operating system:
|
||||||
|
|
||||||
- **Hold your own keys** with Sparrow Wallet. Create and manage wallets,
|
- **Hold your own keys** with **Sparrow Wallet**. Create and manage wallets,
|
||||||
connect hardware signing devices, use multisignature setups, build and
|
connect hardware signing devices, use multisignature setups, build and
|
||||||
inspect transactions, and control UTXOs and coin selection.
|
inspect transactions, and control UTXOs and coin selection.
|
||||||
- **Buy and sell Bitcoin peer-to-peer** with Bisq and Bisq 2. No central
|
- **Buy and sell Bitcoin peer-to-peer** with **Bisq** and **Bisq 2**. No
|
||||||
company holds user funds, and no exchange account stands between buyers and
|
central company holds user funds, and no exchange account stands between
|
||||||
sellers.
|
buyers and sellers.
|
||||||
- **Verify your own Bitcoin** with a full node: [Bitcoin Core](https://bitcoin.org) and
|
- **Verify your own Bitcoin** with a full node: [Bitcoin Core](https://bitcoin.org) and
|
||||||
[Electrs](https://github.com/romanz/electrs), so your wallets connect to
|
[Electrs](https://github.com/romanz/electrs), so your wallets connect to
|
||||||
*your* node instead of a stranger's.
|
*your* node instead of a stranger's.
|
||||||
@@ -90,16 +90,11 @@ Sovran_SystemsOS solves both with one operating system:
|
|||||||
- **Control everything from the Sovran Hub**, on the desktop or from any
|
- **Control everything from the Sovran Hub**, on the desktop or from any
|
||||||
browser on your local network.
|
browser on your local network.
|
||||||
|
|
||||||
No custodian needs to hold your Bitcoin. No outside node needs to tell your
|
Other projects solve one piece of this puzzle: a distribution that runs a
|
||||||
wallet what happened on the network. No third-party cloud needs to control
|
wallet, a node project that runs Bitcoin services, a self-hosting stack that
|
||||||
your data or services.
|
replaces a cloud app. Sovran_SystemsOS brings them together on a reproducible,
|
||||||
|
auditable NixOS foundation: Bitcoin tools from the first boot, one control
|
||||||
Other projects solve one piece of this puzzle: a Linux distribution that can
|
center, and hardware you own.
|
||||||
run a wallet, a node project that runs Bitcoin services, a self-hosting stack
|
|
||||||
that replaces a cloud app. Sovran_SystemsOS brings those worlds together and
|
|
||||||
makes them approachable: Bitcoin tools from the first boot, a complete path
|
|
||||||
from desktop to node to self-hosting, one control center, hardware you own,
|
|
||||||
and a reproducible, auditable NixOS foundation.
|
|
||||||
|
|
||||||
> Sovran_SystemsOS provides tools for self-custody and peer-to-peer Bitcoin
|
> Sovran_SystemsOS provides tools for self-custody and peer-to-peer Bitcoin
|
||||||
> use. Users remain responsible for protecting their keys, understanding their
|
> use. Users remain responsible for protecting their keys, understanding their
|
||||||
@@ -110,34 +105,24 @@ and a reproducible, auditable NixOS foundation.
|
|||||||
## Try it first in a virtual machine
|
## Try it first in a virtual machine
|
||||||
|
|
||||||
**Curious, but not ready to replace your current operating system?** Start with
|
**Curious, but not ready to replace your current operating system?** Start with
|
||||||
Sovran_SystemsOS in a virtual machine (VM). A VM runs Sovran_SystemsOS in a
|
Sovran_SystemsOS in a virtual machine (VM): a window on your existing Windows,
|
||||||
window on your existing Windows, macOS, or Linux computer, using a virtual disk
|
macOS, or Linux computer, using a virtual disk file instead of your internal
|
||||||
file instead of your computer's internal drive. You can explore the desktop,
|
drive. Explore the desktop, Sovran Hub, Sparrow, Bisq, and the installation
|
||||||
Sovran Hub, Sparrow, Bisq, and the installation experience before changing how
|
experience before changing how you use any physical machine. Closing or
|
||||||
you use any physical machine.
|
deleting the VM leaves your current operating system untouched, and installing
|
||||||
|
on a dedicated computer later is still open to you.
|
||||||
|
|
||||||
This is a low-commitment way to decide whether Sovran_SystemsOS is right for
|
Use the same ISO with [VirtualBox](https://www.virtualbox.org), VMware,
|
||||||
you:
|
|
||||||
|
|
||||||
- **Keep your current OS.** Closing or deleting the VM leaves the host operating
|
|
||||||
system in place.
|
|
||||||
- **Learn at your own pace.** Familiarize yourself with the desktop and tools
|
|
||||||
without needing to make it your daily computer on day one.
|
|
||||||
- **Choose your next step with confidence.** When you are ready, install it on
|
|
||||||
a dedicated computer, or keep using the VM as a learning environment.
|
|
||||||
|
|
||||||
You can use the same ISO with [VirtualBox](https://www.virtualbox.org), VMware,
|
|
||||||
QEMU/KVM, Proxmox, and similar x86_64 VM software. For a first look, select
|
QEMU/KVM, Proxmox, and similar x86_64 VM software. For a first look, select
|
||||||
**Desktop Only**, allocate at least **8 GB RAM**, and create a **256 GB or
|
**Desktop Only**, allocate at least **8 GB RAM**, and create a **256 GB or
|
||||||
larger dynamically allocated virtual disk**. The full VM setup and installer
|
larger dynamically allocated virtual disk**. Full requirements are in
|
||||||
requirements are in [Installing in a virtual machine](#installing-in-a-virtual-machine-optional).
|
[Installing in a virtual machine](#installing-in-a-virtual-machine-optional).
|
||||||
|
|
||||||
> **A VM is for evaluation and learning, not a substitute for a dedicated,
|
> **A VM is for evaluation and learning, not a substitute for a dedicated,
|
||||||
> hardened setup.** Do not use a trial VM to hold meaningful Bitcoin, recovery
|
> hardened setup.** Do not hold meaningful Bitcoin, recovery phrases,
|
||||||
> phrases, passwords, or other sensitive data. Avoid attaching physical drives
|
> passwords, or other sensitive data in a trial VM. Avoid attaching physical
|
||||||
> to the VM, and be deliberate about shared folders, clipboard sharing, and
|
> drives, and be deliberate about shared folders, clipboard sharing, and
|
||||||
> network settings. The installer only changes the disk you select, but you
|
> network settings. Review VM disk selections before confirming an install.
|
||||||
> should always review VM disk selections before confirming an install.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -201,24 +186,27 @@ Bitcoin and self-hosting infrastructure runs on the machine.
|
|||||||
| Mode | Best for | What you get |
|
| Mode | Best for | What you get |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| **Desktop** | Everyday users and computers with modest hardware | Sparrow, Bisq, and Bisq 2 for self-custody and peer-to-peer Bitcoin use |
|
| **Desktop** | Everyday users and computers with modest hardware | Sparrow, Bisq, and Bisq 2 for self-custody and peer-to-peer Bitcoin use |
|
||||||
| **Node** | People ready to verify and operate their own Bitcoin infrastructure | Everything in Desktop, plus the full Bitcoin stack: Bitcoin Core, Electrs, LND, Ride The Lightning, BTCPay Server, and wallet-to-node connections |
|
| **Node** | People ready to verify and operate their own Bitcoin infrastructure | Everything in Desktop, plus the full Bitcoin stack: Bitcoin Core, Electrs, LND, Ride The Lightning, BTCPay Server, and wallet-to-node connections. **Publishes nothing unless you enable *Put BTCPay Server Online* or *Lightning Wallet Connections*:** [read this first](#server--desktop-and-your-home-ip-address) |
|
||||||
| **Server + Desktop** | Bitcoiners who want the same sovereignty over their communications, cloud, passwords, and web services | The complete Node stack, plus the private self-hosted services. **Makes your home IP address public:** [read this first](#server--desktop-and-your-home-ip-address) |
|
| **Server + Desktop** | Bitcoiners who want the same sovereignty over their communications, cloud, passwords, and web services | The complete Node stack, plus the private self-hosted services. **Makes your home IP address public:** [read this first](#server--desktop-and-your-home-ip-address) |
|
||||||
|
|
||||||
**Desktop: start with your keys.** Desktop is not a reduced or Bitcoin-free
|
**Desktop: start with your keys.** Desktop is not a reduced or Bitcoin-free
|
||||||
edition. It is a complete, private everyday computer with a clean GNOME
|
edition: it is a complete, private everyday computer with a clean GNOME
|
||||||
desktop, Tor, and the Sovran Hub, giving you a lower-hardware path to
|
desktop, Tor, and the Sovran Hub, and a lower-hardware path to self-custody and
|
||||||
self-custody and non-KYC Bitcoin tools from the first boot. You do not need a
|
non-KYC Bitcoin tools from the first boot. Move to Node mode when your
|
||||||
fully synchronized node to begin; move to Node mode when your hardware,
|
hardware, storage, and needs are ready.
|
||||||
storage, and needs are ready.
|
|
||||||
|
|
||||||
**Node: verify your own money.** Instead of asking someone else's server
|
**Node: verify your own money.** You operate the infrastructure that performs
|
||||||
about your wallet and transactions, you operate the infrastructure that
|
the verification instead of asking someone else's server: your node verifies,
|
||||||
performs the verification. Your node verifies. Your wallet connects to it.
|
your wallet connects to it, your keys stay yours.
|
||||||
Your keys remain yours.
|
|
||||||
|
|
||||||
**Server + Desktop: sovereignty beyond money.** Bitcoin sovereignty is the
|
Node publishes nothing by default. Two Node features need a public domain and
|
||||||
foundation. Server + Desktop applies the same principle to your data,
|
make your home IP address public when enabled: **Put BTCPay Server Online** and
|
||||||
communications, identity, and services.
|
**Lightning Wallet Connections**. Everything else, Mempool and Ride The
|
||||||
|
Lightning included, stays on your home network or reaches you through Tor — see
|
||||||
|
[Server + Desktop and your home IP address](#server--desktop-and-your-home-ip-address).
|
||||||
|
|
||||||
|
**Server + Desktop: sovereignty beyond money.** The same principle, applied
|
||||||
|
to your data, communications, identity, and services.
|
||||||
|
|
||||||
### Recommended hardware
|
### Recommended hardware
|
||||||
|
|
||||||
@@ -234,13 +222,7 @@ communications, identity, and services.
|
|||||||
> the public internet, which means opening specific ports on your home network.
|
> the public internet, which means opening specific ports on your home network.
|
||||||
> Before you start, confirm three things: you can log in to your router's admin
|
> Before you start, confirm three things: you can log in to your router's admin
|
||||||
> panel, the panel includes a port-forwarding section, and your internet
|
> panel, the panel includes a port-forwarding section, and your internet
|
||||||
> provider allows port forwarding. Most home routers and providers already
|
> provider allows port forwarding.
|
||||||
> support this. If you are unsure, a quick search for your router model and
|
|
||||||
> "port forwarding" will usually turn up a step-by-step guide.
|
|
||||||
>
|
|
||||||
> **This mode also makes your home IP address public.** Read
|
|
||||||
> [what that means](#server--desktop-and-your-home-ip-address) before you
|
|
||||||
> choose it.
|
|
||||||
|
|
||||||
### Server + Desktop and your home IP address
|
### Server + Desktop and your home IP address
|
||||||
|
|
||||||
@@ -251,50 +233,42 @@ communications, identity, and services.
|
|||||||
> [Njal.la](https://njal.la) and keeps it up to date, and you forward ports 80
|
> [Njal.la](https://njal.la) and keeps it up to date, and you forward ports 80
|
||||||
> and 443 on your router to this computer. From then on:
|
> and 443 on your router to this computer. From then on:
|
||||||
>
|
>
|
||||||
> - **Anyone can look up your domain and see your home IP address.** An IP
|
> - **Anyone can look up your domain and see your home IP address,** which
|
||||||
> address typically reveals your internet provider and your approximate
|
> reveals your internet provider and approximate location and ties everything
|
||||||
> location, and it ties everything you publish on that domain to your home
|
> you publish on that domain to your home connection. Domain privacy does not
|
||||||
> connection.
|
> hide it: registrar privacy protects the registrant's identity, not the IP
|
||||||
> - **Domain privacy does not hide it.** Registrar privacy protects the
|
> address in your DNS records.
|
||||||
> registrant's identity, not the IP address in your DNS records.
|
|
||||||
> - **Your connection is open to the whole internet on those ports.** Scanners
|
> - **Your connection is open to the whole internet on those ports.** Scanners
|
||||||
> and bots constantly probe public IP addresses, so expect automated probing
|
> and bots constantly probe public IP addresses, so expect automated probing
|
||||||
> and login attempts against every service you publish.
|
> and login attempts against every service you publish.
|
||||||
> - **Your service names are discoverable.** Public HTTPS certificates are
|
> - **Your service names are discoverable.** Public HTTPS certificates are
|
||||||
> listed in public Certificate Transparency logs, so hostnames such as
|
> listed in Certificate Transparency logs, so hostnames such as
|
||||||
> `vault.yourdomain.com` can be found, and then resolved to your IP address,
|
> `vault.yourdomain.com` can be found and resolved to your IP address, even
|
||||||
> even if you never share them.
|
> if you never share them.
|
||||||
|
|
||||||
Nothing is published until you finish domain setup and port forwarding, but that
|
**Desktop** publishes nothing. **Node** publishes nothing unless you enable
|
||||||
setup is the point of this mode, so assume your IP address will be public.
|
*Put BTCPay Server Online* or *Lightning Wallet Connections* — see
|
||||||
**Desktop** publishes nothing. **Node** publishes nothing unless you turn on a
|
[Three modes](#three-modes).
|
||||||
feature that needs a domain: *Put BTCPay Server Online* or *Lightning Wallet
|
|
||||||
Connections*.
|
|
||||||
|
|
||||||
**If you do not want your home IP address to be public,** choose Desktop or
|
**If you do not want your home IP address to be public,** choose Desktop or
|
||||||
Node. Advanced users can put a VPS, reverse proxy, or tunnel in front of their
|
Node. Advanced users can put a VPS, reverse proxy, or tunnel in front of their
|
||||||
services so DNS points there instead of at their home. Sovran_SystemsOS does not
|
services so DNS points there instead of at their home; Sovran_SystemsOS does
|
||||||
set this up for you, and the Hub's domain checks currently expect DNS to point
|
not set that up, and the Hub's domain checks expect DNS to point at your home
|
||||||
at your home IP address.
|
IP address.
|
||||||
|
|
||||||
<details>
|
<details>
|
||||||
<summary><strong>What happens technically</strong></summary>
|
<summary><strong>What happens technically</strong></summary>
|
||||||
|
|
||||||
- You create a **Dynamic** DNS record at Njal.la and paste its update command
|
- You create a **Dynamic** DNS record at Njal.la and paste its update command
|
||||||
into the Hub. The Hub only accepts `njal.la` update URLs.
|
into the Hub, which only accepts `njal.la` update URLs.
|
||||||
- The `sovran-ddns-update` timer asks Njal.la to point your record at the
|
- The `sovran-ddns-update` timer points your record at the address the request
|
||||||
address the request came from. It does this right after you save a domain,
|
came from: after you save a domain, two minutes after boot, then every 15
|
||||||
two minutes after boot, and then every 15 minutes.
|
minutes. Element calling and the Hub use that same address. See
|
||||||
- Njal.la reports that address back, and Sovran_SystemsOS keeps it for Element
|
|
||||||
calling and the Hub. Nothing else looks up your public IP address: no STUN
|
|
||||||
server, public DNS resolver, or "what is my IP" service is involved. See
|
|
||||||
`modules/core/njalla.nix`.
|
`modules/core/njalla.nix`.
|
||||||
- Once a service that needs a domain is turned on, the firewall opens TCP and
|
- Once a service that needs a domain is on, the firewall opens TCP and UDP
|
||||||
UDP ports 80 and 443 for Caddy, which requests public HTTPS certificates for
|
ports 80 and 443 for Caddy, which requests public HTTPS certificates for the
|
||||||
the domains you configure. See `modules/core/caddy.nix`.
|
domains you configure. The Hub lists any additional ports a feature needs.
|
||||||
- Optional features can need more ports. Element calling, for example, needs
|
See `modules/core/caddy.nix`.
|
||||||
TCP 7881 and UDP 3478, 7882, and 40000–40099. The Hub lists the ports each
|
|
||||||
feature needs.
|
|
||||||
|
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
@@ -317,10 +291,7 @@ Prefer to keep using Windows, macOS, Linux, Android, or iOS? Install
|
|||||||
Sovran_SystemsOS on a separate computer and let it run quietly on your local
|
Sovran_SystemsOS on a separate computer and let it run quietly on your local
|
||||||
network, with or without a monitor. From any other device on the same network,
|
network, with or without a monitor. From any other device on the same network,
|
||||||
open a browser, visit `http://sovransystemsos.local:8937`, and manage
|
open a browser, visit `http://sovransystemsos.local:8937`, and manage
|
||||||
everything from [The Sovran Hub](#the-sovran-hub).
|
everything from [the Hub](#the-hub).
|
||||||
|
|
||||||
Your existing devices stay familiar. Sovran_SystemsOS provides the independent
|
|
||||||
infrastructure behind them.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -328,16 +299,15 @@ infrastructure behind them.
|
|||||||
|
|
||||||
### Your private infrastructure, controlled from any screen.
|
### Your private infrastructure, controlled from any screen.
|
||||||
|
|
||||||
The Hub is the command center built into Sovran_SystemsOS. It is both a
|
The Hub is the command center built into Sovran_SystemsOS: a local desktop
|
||||||
local desktop application and a private web interface served directly by your
|
application and a private web interface served by your Sovran_SystemsOS
|
||||||
Sovran_SystemsOS machine. Nothing needs to be installed on the device opening
|
machine. The device opening it needs only a modern browser and access to the
|
||||||
the Hub: you only need a modern browser and access to the same local network.
|
same local network.
|
||||||
|
|
||||||
From one place, the Hub helps you:
|
From one place, the Hub lets you:
|
||||||
|
|
||||||
- Open, monitor, start, and stop your services
|
- Open, monitor, start, and stop your services
|
||||||
- See what is running and configure system features
|
- Configure system features and manage service domains and credentials
|
||||||
- Manage service domains and credentials
|
|
||||||
- Reach your Bitcoin tools, private cloud, and communications
|
- Reach your Bitcoin tools, private cloud, and communications
|
||||||
- Perform supported system operations without everyday terminal commands
|
- Perform supported system operations without everyday terminal commands
|
||||||
|
|
||||||
@@ -372,22 +342,36 @@ From one place, the Hub helps you:
|
|||||||
└──────────────────────────┘
|
└──────────────────────────┘
|
||||||
```
|
```
|
||||||
|
|
||||||
Keep using the devices you already own. Sovran_SystemsOS becomes the private
|
|
||||||
Bitcoin and digital infrastructure behind them.
|
|
||||||
|
|
||||||
> **Local access:** the Hub is available at
|
> **Local access:** the Hub is available at
|
||||||
> `http://sovransystemsos.local:8937` to devices connected to the same local
|
> `http://sovransystemsos.local:8937` to devices connected to the same local
|
||||||
> network (not on Desktop, which publishes nothing). It is protected by
|
> network (not on Desktop, which publishes nothing). It is protected by
|
||||||
> authentication, answers only your local network, and is not automatically
|
> authentication and answers only your local network.
|
||||||
> exposed to the public internet.
|
|
||||||
|
### Tech Support
|
||||||
|
|
||||||
|
The Hub can give a Sovran Systems technician temporary access to your machine.
|
||||||
|
Support runs over SSH, and **Tech Support requires SSH Remote Access, which is
|
||||||
|
off by default.**
|
||||||
|
|
||||||
|
Turning SSH on makes the machine listen on all interfaces and opens **TCP port
|
||||||
|
22** in the firewall. Letting support in from outside your home means
|
||||||
|
forwarding port 22 on your router, which puts SSH on the public internet where
|
||||||
|
scanners and brute-force attempts will find it. Turn SSH off when the session
|
||||||
|
ends; the Hub prompts you to.
|
||||||
|
|
||||||
|
Support signs in as the restricted `sovran-support` account, not as root, with
|
||||||
|
one key that expires after 24 hours. Wallet paths stay locked unless you unlock
|
||||||
|
them for a limited time, and every session event is written to
|
||||||
|
`/var/log/sovran-support-audit.log`. See
|
||||||
|
[Restricted support access](SECURITY.md#restricted-support-access).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Install Sovran_SystemsOS
|
## Install Sovran_SystemsOS
|
||||||
|
|
||||||
Sovran_SystemsOS is free and open source. You can download the installer,
|
Sovran_SystemsOS is free and open source: download the installer, verify it,
|
||||||
verify it, write it to a USB drive, and install it yourself, staying in
|
write it to a USB drive, and install it yourself, in control from the first
|
||||||
control from the very first step.
|
step.
|
||||||
|
|
||||||
An ISO is a complete installation image containing the operating system and
|
An ISO is a complete installation image containing the operating system and
|
||||||
installer. It is not copied to a USB drive like a document; it must be written
|
installer. It is not copied to a USB drive like a document; it must be written
|
||||||
@@ -414,10 +398,9 @@ verifying it, and keep both files in the same folder.
|
|||||||
|
|
||||||
### 2. Verify the checksum
|
### 2. Verify the checksum
|
||||||
|
|
||||||
A checksum is a digital fingerprint of a file. Verifying it confirms that the
|
A checksum is a digital fingerprint of a file. Verifying it confirms the ISO
|
||||||
ISO downloaded completely, was not accidentally corrupted, and matches the
|
downloaded completely and without corruption. The checksum produced from your
|
||||||
published image. The checksum produced from your ISO must match the published
|
ISO must match the published one exactly.
|
||||||
checksum exactly.
|
|
||||||
|
|
||||||
<details>
|
<details>
|
||||||
<summary><strong>Linux</strong></summary>
|
<summary><strong>Linux</strong></summary>
|
||||||
@@ -434,9 +417,6 @@ A successful comparison reports:
|
|||||||
Sovran_SystemsOS-1.2.0.iso: OK
|
Sovran_SystemsOS-1.2.0.iso: OK
|
||||||
```
|
```
|
||||||
|
|
||||||
You can also run `sha256sum Sovran_SystemsOS-1.2.0.iso` and compare the output
|
|
||||||
against the checksum file manually.
|
|
||||||
|
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
<details>
|
<details>
|
||||||
@@ -509,14 +489,14 @@ similar x86_64 virtual machines. Use production-like resources where possible:
|
|||||||
allocated disks are fine; they do not consume the full size immediately.
|
allocated disks are fine; they do not consume the full size immediately.
|
||||||
- Use NAT or bridged networking with internet access before opening the
|
- Use NAT or bridged networking with internet access before opening the
|
||||||
installer.
|
installer.
|
||||||
- UEFI/EFI firmware is preferred. In UEFI VMs, the installer avoids depending
|
- UEFI/EFI firmware is preferred: in UEFI VMs the installer avoids depending
|
||||||
on VM NVRAM boot-entry writes. If a VM boots the ISO in legacy BIOS mode,
|
on VM NVRAM boot-entry writes, and a VM that boots the ISO in legacy BIOS
|
||||||
the installer automatically switches the installed system to GRUB.
|
mode automatically installs GRUB instead.
|
||||||
- For Node or Server + Desktop, attach a **second 2 TB virtual data disk**.
|
- For Node or Server + Desktop, attach a **second 2 TB virtual data disk**.
|
||||||
If you only attach one disk, choose **Desktop Only**.
|
If you only attach one disk, choose **Desktop Only**.
|
||||||
- Present the install target as a normal virtual disk such as VirtIO, SATA,
|
- Present the install target as a normal virtual disk such as VirtIO, SATA,
|
||||||
SCSI, or NVMe. USB-attached target disks are intentionally hidden by the
|
SCSI, or NVMe. USB-attached disks are hidden by the installer so you cannot
|
||||||
installer to avoid erasing the installer USB by mistake.
|
erase the installer USB by mistake.
|
||||||
|
|
||||||
### 5. Install
|
### 5. Install
|
||||||
|
|
||||||
@@ -557,10 +537,6 @@ on the network, so in that mode open it from the desktop.
|
|||||||
access.
|
access.
|
||||||
5. Try another browser or device on the same network.
|
5. Try another browser or device on the same network.
|
||||||
|
|
||||||
Some networks or devices may not support `.local` address discovery correctly.
|
|
||||||
Network isolation, custom DNS settings, VPNs, and some routers can interfere
|
|
||||||
with local-device discovery.
|
|
||||||
|
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
### Prefer guided help?
|
### Prefer guided help?
|
||||||
@@ -762,9 +738,8 @@ rebuilds the machine into the selected declarative state.
|
|||||||
| Nextcloud, Vaultwarden, WordPress | `modules/nextcloud.nix`, `modules/vaultwarden.nix`, `modules/wordpress.nix`, `modules/php.nix` |
|
| Nextcloud, Vaultwarden, WordPress | `modules/nextcloud.nix`, `modules/vaultwarden.nix`, `modules/wordpress.nix`, `modules/php.nix` |
|
||||||
| Optional remote desktop and public SSH | `modules/rdp.nix`, `modules/sshd.nix` |
|
| Optional remote desktop and public SSH | `modules/rdp.nix`, `modules/sshd.nix` |
|
||||||
|
|
||||||
Feature availability and defaults may change as Sovran_SystemsOS develops.
|
Feature availability and defaults may change as Sovran_SystemsOS develops:
|
||||||
Review the relevant Nix module before relying on a specific default in a
|
review the relevant Nix module before relying on a default in production.
|
||||||
production environment.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -774,11 +749,11 @@ Wallet recovery words control the funds. Never share them with a website,
|
|||||||
support technician, cloud service, or chat application.
|
support technician, cloud service, or chat application.
|
||||||
|
|
||||||
For meaningful balances, prefer a well-reviewed hardware signer and follow its
|
For meaningful balances, prefer a well-reviewed hardware signer and follow its
|
||||||
verified backup process. A BIP39 passphrase is optional, advanced protection;
|
verified backup process. A BIP39 passphrase is optional, advanced protection,
|
||||||
it is not a replacement for the recovery words. If you use one, back it up
|
not a replacement for recovery words: back it up separately, because losing
|
||||||
separately—losing either item can make the wallet unrecoverable.
|
either item can make the wallet unrecoverable.
|
||||||
|
|
||||||
Keep durable offline backups in separate secure locations. Test recovery before
|
Keep durable offline backups in separate secure locations, test recovery before
|
||||||
relying on a wallet, and begin with a small amount.
|
relying on a wallet, and begin with a small amount.
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -789,7 +764,8 @@ Sovran_SystemsOS uses layered controls:
|
|||||||
|
|
||||||
- Pinned flake inputs and hash-pinned source archives
|
- Pinned flake inputs and hash-pinned source archives
|
||||||
- Bitcoin and Lightning modules maintained in this repository
|
- Bitcoin and Lightning modules maintained in this repository
|
||||||
- Firewall enabled; public SSH and remote desktop disabled by default
|
- Firewall enabled; SSH Remote Access and remote desktop disabled by default.
|
||||||
|
Enabling SSH opens TCP port 22 and the Hub then asks you to forward it
|
||||||
- Separate service users, systemd sandboxing, and loopback bindings where practical
|
- Separate service users, systemd sandboxing, and loopback bindings where practical
|
||||||
- Tor enforcement for supported Bitcoin services
|
- Tor enforcement for supported Bitcoin services
|
||||||
- Restricted, time-limited support access with scoped `sudo`
|
- Restricted, time-limited support access with scoped `sudo`
|
||||||
@@ -798,9 +774,7 @@ Sovran_SystemsOS uses layered controls:
|
|||||||
once you set up a domain)
|
once you set up a domain)
|
||||||
|
|
||||||
See [`SECURITY.md`](SECURITY.md) for the threat model, limitations, reporting,
|
See [`SECURITY.md`](SECURITY.md) for the threat model, limitations, reporting,
|
||||||
and operator guidance. No operating system can protect funds after recovery
|
and operator guidance.
|
||||||
words, administrator credentials, or the root account are compromised. Apply
|
|
||||||
updates and keep tested offline backups.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -810,11 +784,9 @@ Sovran_SystemsOS stands on the work of exceptional free and open-source projects
|
|||||||
|
|
||||||
### NixOS
|
### NixOS
|
||||||
|
|
||||||
Deep gratitude goes to the [NixOS](https://nixos.org) team, the [Nixpkgs](https://github.com/NixOS/nixpkgs) maintainers, and the broader [Nix community](https://github.com/nix-community).
|
Gratitude to the [NixOS](https://nixos.org) team, the [Nixpkgs](https://github.com/NixOS/nixpkgs) maintainers, and the broader [Nix community](https://github.com/nix-community).
|
||||||
|
|
||||||
NixOS provides the reproducible, declarative foundation that makes Sovran_SystemsOS possible. Its module system, package ecosystem, [flakes](https://nixos.wiki/wiki/Flakes), and generation-based system management allow an entire Bitcoin operating system to be described, audited, rebuilt, upgraded, and rolled back from source.
|
NixOS provides the reproducible, declarative foundation that makes Sovran_SystemsOS possible: its module system, package ecosystem, [flakes](https://nixos.wiki/wiki/Flakes), and generation-based system management allow an entire Bitcoin operating system to be described, audited, rebuilt, upgraded, and rolled back from source.
|
||||||
|
|
||||||
Sovran_SystemsOS would not have the same reliability, transparency, or reproducibility without their years of work.
|
|
||||||
|
|
||||||
### nix-bitcoin
|
### nix-bitcoin
|
||||||
|
|
||||||
@@ -822,24 +794,17 @@ The in-repository Bitcoin stack began with code adapted from
|
|||||||
[nix-bitcoin](https://github.com/fort-nix/nix-bitcoin), primarily from commit
|
[nix-bitcoin](https://github.com/fort-nix/nix-bitcoin), primarily from commit
|
||||||
[`360e30f`](https://github.com/fort-nix/nix-bitcoin/commit/360e30fee5ba32f9fecc89bc35628195d9d2dbbe).
|
[`360e30f`](https://github.com/fort-nix/nix-bitcoin/commit/360e30fee5ba32f9fecc89bc35628195d9d2dbbe).
|
||||||
It has since been narrowed to Sovran's supported services and is maintained in
|
It has since been narrowed to Sovran's supported services and is maintained in
|
||||||
this repository. nix-bitcoin is no longer a flake input or build dependency.
|
this repository; nix-bitcoin is no longer a flake input or build dependency.
|
||||||
|
Its MIT notice is retained in [`THIRD_PARTY_NOTICES.md`](THIRD_PARTY_NOTICES.md).
|
||||||
We remain grateful to the nix-bitcoin contributors for the declarative and
|
|
||||||
security-focused foundation. Its MIT notice is retained in
|
|
||||||
[`THIRD_PARTY_NOTICES.md`](THIRD_PARTY_NOTICES.md).
|
|
||||||
|
|
||||||
### Emmanuel Rosa and btc-clients-nix
|
### Emmanuel Rosa and btc-clients-nix
|
||||||
|
|
||||||
Special thanks go to [Emmanuel Rosa](https://github.com/emmanuelrosa) for [btc-clients-nix](https://github.com/emmanuelrosa/btc-clients-nix).
|
Thanks to [Emmanuel Rosa](https://github.com/emmanuelrosa) for [btc-clients-nix](https://github.com/emmanuelrosa/btc-clients-nix), which packages the Bitcoin desktop software included in every installation:
|
||||||
|
|
||||||
The project provides Nix packages for the Bitcoin desktop software central to the Sovran_SystemsOS experience:
|
|
||||||
|
|
||||||
- [Sparrow Wallet](https://github.com/sparrowwallet/sparrow)
|
- [Sparrow Wallet](https://github.com/sparrowwallet/sparrow)
|
||||||
- [Bisq](https://github.com/bisq-network/bisq)
|
- [Bisq](https://github.com/bisq-network/bisq)
|
||||||
- [Bisq 2](https://github.com/bisq-network/bisq2)
|
- [Bisq 2](https://github.com/bisq-network/bisq2)
|
||||||
|
|
||||||
This work helps make it possible for Sovran_SystemsOS to deliver self-custody and peer-to-peer Bitcoin tools as part of every installation.
|
|
||||||
|
|
||||||
### The upstream Bitcoin ecosystem
|
### The upstream Bitcoin ecosystem
|
||||||
|
|
||||||
Sovran_SystemsOS also depends on the work of the developers and communities behind:
|
Sovran_SystemsOS also depends on the work of the developers and communities behind:
|
||||||
@@ -867,27 +832,16 @@ Sovran_SystemsOS also depends on the work of the developers and communities behi
|
|||||||
- [WordPress](https://github.com/WordPress/WordPress)
|
- [WordPress](https://github.com/WordPress/WordPress)
|
||||||
- Every other upstream project included in the system
|
- Every other upstream project included in the system
|
||||||
|
|
||||||
Sovran Systems did not create these foundations. Our work is to bring them together into a cohesive operating system that helps more people use Bitcoin privately, independently, and with confidence.
|
Sovran Systems did not create these foundations; our work is to bring them together into one operating system that helps more people use Bitcoin privately and independently. Thank you to every developer, maintainer, reviewer, tester, documentarian, and user who keeps this ecosystem alive.
|
||||||
|
|
||||||
Thank you to every developer, maintainer, reviewer, tester, documentarian, and user who keeps this ecosystem alive.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|
||||||
Sovran_SystemsOS is free and open-source software licensed under the
|
Sovran_SystemsOS is free and open-source software licensed under the
|
||||||
[GNU Affero General Public License v3.0](LICENSE).
|
[GNU Affero General Public License v3.0](LICENSE). You may use, study, modify,
|
||||||
|
share, and self-host it; if you distribute a modified version, you must make
|
||||||
The AGPL-3.0 protects your freedom to:
|
its corresponding source code available under the same license.
|
||||||
|
|
||||||
- Use Sovran_SystemsOS
|
|
||||||
- Study how the system works
|
|
||||||
- Modify the source code
|
|
||||||
- Share original or modified versions
|
|
||||||
- Build and operate the system on your own hardware
|
|
||||||
|
|
||||||
If you distribute a modified version, you must make its corresponding source
|
|
||||||
code available under the same license.
|
|
||||||
|
|
||||||
Because Sovran_SystemsOS includes the browser-based Sovran Hub, operators who
|
Because Sovran_SystemsOS includes the browser-based Sovran Hub, operators who
|
||||||
modify the covered software and make that modified version available for users
|
modify the covered software and make that modified version available for users
|
||||||
@@ -895,14 +849,9 @@ to interact with over a network must offer those users access to its
|
|||||||
corresponding source code, as required by the AGPL-3.0.
|
corresponding source code, as required by the AGPL-3.0.
|
||||||
|
|
||||||
Sovran_SystemsOS is provided **without warranty**, as described in the full
|
Sovran_SystemsOS is provided **without warranty**, as described in the full
|
||||||
license.
|
license. Individual upstream applications, packages, artwork, fonts, and other
|
||||||
|
components may have their own licenses and copyright holders, which the
|
||||||
> Individual upstream applications, packages, artwork, fonts, and other
|
AGPL-3.0 does not replace. Read [`LICENSE`](LICENSE) and
|
||||||
> components included with or built by Sovran_SystemsOS may have their own
|
|
||||||
> licenses and copyright holders. The AGPL-3.0 license for this repository does
|
|
||||||
> not replace those licenses.
|
|
||||||
|
|
||||||
Read [`LICENSE`](LICENSE) and
|
|
||||||
[`THIRD_PARTY_NOTICES.md`](THIRD_PARTY_NOTICES.md).
|
[`THIRD_PARTY_NOTICES.md`](THIRD_PARTY_NOTICES.md).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
Reference in New Issue
Block a user