diff --git a/README.md b/README.md index 3c3d17e..0c8af26 100644 --- a/README.md +++ b/README.md @@ -6,15 +6,17 @@ ### Your Bitcoin life. Your keys. Your node. Your machine. -Sovran_SystemsOS is a free and open-source Bitcoin operating system built for -self-custody, private peer-to-peer exchange, independent verification, and -digital sovereignty. +Sovran_SystemsOS is a free and open-source operating system for **Bitcoin +self-custody** and **digital sovereignty**. Hold your own keys, trade +peer-to-peer, and verify your own money with your own node. Then extend the +same ownership to the rest of your digital life: your files, communications, +passwords, and websites, all on hardware you control. -Every installation includes a private NixOS desktop with **Sparrow Wallet, -Bisq, and Bisq 2** ready to use. Move beyond custodial exchanges, use Bitcoin -without making a centralized platform the center of your financial life, and -grow into running your own Bitcoin and Lightning infrastructure when you are -ready. +Every installation is a private [NixOS](https://nixos.org) desktop with +[Sparrow Wallet](https://sparrowwallet.com), [Bisq](https://bisq.network), and +[Bisq 2](https://github.com/bisq-network/bisq2) ready to use. Move beyond +custodial exchanges from the first boot, and grow into your own Bitcoin and +Lightning infrastructure when you are ready. **Privacy. Sovereignty. Bitcoin.** @@ -23,10 +25,6 @@ ready. [Verify the Download](https://downloads.sovransystems.com/Sovran_SystemsOS.iso.sha256) · [Build from Source](#build-from-source) - - -
*Bitcoin sovereignty from the first boot.*
@@ -35,27 +33,64 @@ ready.
---
-## Bitcoin software should help you leave the middleman behind
+## Contents
-Bitcoin gives people the ability to hold and transfer value without asking a
-bank, exchange, or custodian for permission. But that freedom depends on the
-software and infrastructure you choose to use.
+- [Why Sovran_SystemsOS?](#why-sovran_systemsos)
+- [What is included](#what-is-included)
+- [Three modes](#three-modes)
+- [Use it your way](#use-it-your-way)
+- [The Sovran Hub](#the-sovran-hub)
+- [Install Sovran_SystemsOS](#install-sovran_systemsos)
+- [For developers](#for-developers)
+- [Security approach](#security-approach)
+- [Acknowledgements](#acknowledgements)
+- [License](#license) · [Contributing](#contributing)
-Sovran_SystemsOS brings the essential tools together in one operating system:
+---
-- **Hold your own keys** with Sparrow Wallet.
-- **Buy and sell Bitcoin peer-to-peer** with Bisq and Bisq 2.
-- **Use non-KYC Bitcoin tools** without depending on a custodial exchange account.
-- **Verify your own Bitcoin** with a full node.
-- **Connect your wallets to your node**, not a stranger's.
-- **Use Lightning** with LND and Ride The Lightning.
-- **Accept Bitcoin directly** with BTCPay Server.
-- **Route the Bitcoin stack through Tor** for stronger network privacy.
-- **Control everything from the Sovran Hub.**
+## Why Sovran_SystemsOS?
+
+Bitcoin lets you hold and transfer value without asking a bank, exchange, or
+custodian for permission. But that freedom depends on the software and
+infrastructure you choose. Your wider digital life works the same way: files,
+messages, and passwords kept on someone else's servers are never fully yours.
+
+Sovran_SystemsOS solves both with one operating system:
+
+- **Hold your own keys** with Sparrow Wallet. Create and manage wallets,
+ connect hardware signing devices, use multisignature setups, build and
+ inspect transactions, and control UTXOs and coin selection.
+- **Buy and sell Bitcoin peer-to-peer** with Bisq and Bisq 2. No central
+ company holds user funds, and no exchange account stands between buyers and
+ sellers.
+- **Verify your own Bitcoin** with a full node: [Bitcoin
+ Knots](https://bitcoinknots.org) and
+ [Electrs](https://github.com/romanz/electrs), so your wallets connect to
+ *your* node instead of a stranger's.
+- **Use Lightning** with [LND](https://github.com/lightningnetwork/lnd) and
+ [Ride The Lightning](https://github.com/Ride-The-Lightning/RTL).
+- **Accept Bitcoin directly** with [BTCPay Server](https://btcpayserver.org),
+ with no payment processor in the middle.
+- **Own the rest of your digital life** with
+ [Nextcloud](https://nextcloud.com) files and calendars,
+ [Matrix](https://matrix.org) communications, a
+ [Vaultwarden](https://github.com/dani-garcia/vaultwarden) password vault,
+ and your own [WordPress](https://wordpress.org) website.
+- **Protect your network privacy** with [Tor](https://www.torproject.org)
+ integration across the Bitcoin stack.
+- **Control everything from the Sovran Hub**, on the desktop or from any
+ browser on your local network.
No custodian needs to hold your Bitcoin. No outside node needs to tell your
-wallet what happened on the Bitcoin network. No third-party cloud needs to
-control your data or services.
+wallet what happened on the network. No third-party cloud needs to control
+your data or services.
+
+Other projects solve one piece of this puzzle: a Linux distribution that can
+run a wallet, a node project that runs Bitcoin services, a self-hosting stack
+that replaces a cloud app. Sovran_SystemsOS brings those worlds together and
+makes them approachable: Bitcoin tools from the first boot, a complete path
+from desktop to node to self-hosting, one control center, hardware you own,
+and a reproducible, auditable NixOS foundation.
> Sovran_SystemsOS provides tools for self-custody and peer-to-peer Bitcoin
> use. Users remain responsible for protecting their keys, understanding their
@@ -63,196 +98,117 @@ control your data or services.
---
-## Bitcoin tools included from day one
+## What is included
-You do not need the largest computer or a fully synchronized Bitcoin node to
-begin taking control of your Bitcoin.
+Depending on the selected mode and enabled features, Sovran_SystemsOS brings
+together a growing collection of private, open-source tools. The Sovran Hub
+presents and manages the features available on your system.
-Every Sovran_SystemsOS mode includes the standard desktop Bitcoin applications:
-**Sparrow Wallet, Bisq, and Bisq 2**.
+### Your money — Bitcoin sovereignty
-### Sparrow Wallet
+- Bitcoin Knots, Electrs, and Tor integration
+- LND and Ride The Lightning, with [Alby Hub](https://albyhub.com) for Nostr
+ Wallet Connect
+- BTCPay Server
+- Sparrow Wallet, Bisq, and Bisq 2, with automatic wallet-to-node connections
+- Optional: a self-hosted [Mempool](https://github.com/mempool/mempool)
+ explorer, or Bitcoin Core in place of Knots
-Sparrow is a privacy-focused desktop Bitcoin wallet built for transparent,
-secure self-custody.
+Run your own Bitcoin infrastructure. Verify your own money. Trust no one.
-Use Sparrow to:
+### Your voice — private communications
-- Create and manage Bitcoin wallets
-- Connect signing devices and hardware wallets
-- Build and inspect transactions
-- Manage UTXOs and coin selection
-- Use multisignature wallets
-- Connect directly to your own Electrs server in Node mode
+- The [Synapse](https://github.com/element-hq/synapse) homeserver (Matrix) and
+ the [Element](https://element.io) client
+- Optional Matrix-native calling
+- Optional [Haven](https://github.com/bitvora/haven)
+ [Nostr](https://github.com/nostr-protocol/nostr) relay
-Your keys remain under your control.
+Communicate without making Big Tech the owner of your identity or
+conversations.
-### Bisq
+### Your cloud — self-hosting and storage
-Bisq is a decentralized peer-to-peer Bitcoin exchange.
+- Nextcloud files, calendars, and contacts
+- Vaultwarden password vault
+- WordPress websites
+- [Caddy](https://caddyserver.com) with private service domains
+- Optional remote desktop
-It allows buyers and sellers to trade directly without depositing their
-Bitcoin with a centralized exchange. There is no central company holding user
-funds and no conventional exchange account standing between participants.
+Keep your files, passwords, calendar, contacts, website, and services on
+hardware you control.
-### Bisq 2
+### Your desktop
-Bisq 2 is the next generation of the Bisq peer-to-peer trading network. It is
-installed alongside Bisq so users can access both generations of the Bisq
-ecosystem from the Sovran_SystemsOS desktop.
-
-Together, Sparrow, Bisq, and Bisq 2 provide a practical path to obtaining,
-holding, and using Bitcoin without making a custodial exchange the center of
-your financial life.
+- [GNOME](https://www.gnome.org) desktop
+- [Brave](https://brave.com) and
+ [Firefox](https://www.mozilla.org/firefox) browsers
+- File management, email, calendar, and office applications
+- System monitoring and administration tools
---
-## Three modes, one path toward Bitcoin sovereignty
+## Three modes
-Every mode includes the same private NixOS and GNOME foundation, the Sovran
-Hub, Sparrow Wallet, Bisq, and Bisq 2.
+Every mode shares the same foundation: the private NixOS and GNOME desktop,
+the Sovran Hub, and Sparrow, Bisq, and Bisq 2. What changes is how much
+Bitcoin and self-hosting infrastructure runs on the machine.
-What changes is how much Bitcoin and self-hosting infrastructure runs on the
-machine.
-
-| Mode | Best for | Bitcoin capability |
+| Mode | Best for | What you get |
|---|---|---|
| **Desktop** | Everyday users and computers with modest hardware | Sparrow, Bisq, and Bisq 2 for self-custody and peer-to-peer Bitcoin use |
-| **Node** | People ready to verify and operate their own Bitcoin infrastructure | Everything in Desktop plus Bitcoin Knots, Electrs, LND, RTL, BTCPay Server, Tor, and wallet-to-node connections |
-| **Server + Desktop** | Bitcoiners who also want to reclaim their communications, cloud, passwords, and web services | The complete Node stack plus private self-hosted services |
+| **Node** | People ready to verify and operate their own Bitcoin infrastructure | Everything in Desktop, plus the full Bitcoin stack: Bitcoin Knots, Electrs, LND, Ride The Lightning, BTCPay Server, and wallet-to-node connections |
+| **Server + Desktop** | Bitcoiners who want the same sovereignty over their communications, cloud, passwords, and web services | The complete Node stack, plus the private self-hosted services |
-### Desktop — start with your keys
-
-Desktop mode is not a reduced or Bitcoin-free edition.
-
-It is a private everyday computer that includes:
-
-- Sparrow Wallet
-- Bisq
-- Bisq 2
-- A clean GNOME desktop
-- Privacy-respecting everyday applications
-- Tor
-- The Sovran Hub
-
-This gives people a lower-hardware path to Bitcoin self-custody and
-peer-to-peer, non-KYC Bitcoin tools from the first boot.
-
-You can begin with Desktop today and move to your own node when your hardware,
+**Desktop: start with your keys.** Desktop is not a reduced or Bitcoin-free
+edition. It is a complete, private everyday computer with a clean GNOME
+desktop, Tor, and the Sovran Hub, giving you a lower-hardware path to
+self-custody and non-KYC Bitcoin tools from the first boot. You do not need a
+fully synchronized node to begin; move to Node mode when your hardware,
storage, and needs are ready.
-**Recommended hardware:**
+**Node: verify your own money.** Instead of asking someone else's server
+about your wallet and transactions, you operate the infrastructure that
+performs the verification. Your node verifies. Your wallet connects to it.
+Your keys remain yours.
-- 64-bit Intel or AMD processor, approximately 2015 or newer
-- 8 GB RAM
-- 256 GB SSD
-- Any broadband connection
+**Server + Desktop: sovereignty beyond money.** Bitcoin sovereignty is the
+foundation. Server + Desktop applies the same principle to your data,
+communications, identity, and services.
-### Node — verify your own money
+### Recommended hardware
-Node mode includes the private desktop and adds the full Bitcoin stack.
-
-Instead of asking someone else's server about your wallet and transactions,
-you operate the infrastructure that performs the verification.
-
-The Node stack includes:
-
-- **Bitcoin Knots** — independently verify the Bitcoin timechain and consensus rules
-- **Electrs** — connect compatible wallets to your own node
-- **LND** — operate a Lightning node
-- **Ride The Lightning** — manage Lightning through a web interface
-- **BTCPay Server** — accept Bitcoin payments without a payment processor
-- **Sparrow Wallet** — connect your wallet to your own infrastructure
-- **Bisq and Bisq 2** — trade Bitcoin peer-to-peer
-- **Tor integration** — improve network privacy across the Bitcoin stack
-- **Sovran Hub** — launch, monitor, and reach everything from one place
-
-Your node verifies. Your wallet connects to it. Your keys remain yours.
-
-**Recommended hardware:**
-
-- x86 Intel or AMD processor, approximately three years old or newer
-- 16 GB RAM
-- 500 GB NVMe SSD for the operating system
-- 2 TB NVMe SSD for the Bitcoin timechain
-- Unmetered broadband
-- Approximately 200 Mbps download and 50 Mbps upload
-
-### Server + Desktop — sovereignty beyond money
-
-Server + Desktop includes the complete Bitcoin Node stack and extends the same
-ownership model to the rest of your digital life.
-
-Run your own:
-
-- Private cloud
-- Files, calendars, and contacts
-- Encrypted communications
-- Password vault
-- Website
-- Nostr relay
-- Bitcoin payment infrastructure
-
-Bitcoin sovereignty is the foundation. Server + Desktop applies that principle
-to your data, communications, identity, and services.
-
-**Recommended hardware:**
-
-- x86 Intel or AMD processor, approximately three years old or newer
-- 32 GB RAM
-- 500 GB NVMe SSD for the operating system
-- 2 TB NVMe SSD for the Bitcoin timechain
-- Unmetered broadband
-- Approximately 200 Mbps download and 50 Mbps upload
-- A domain for publicly accessible self-hosted services
+| | **Desktop** | **Node** | **Server + Desktop** |
+|---|---|---|---|
+| Processor | 64-bit Intel or AMD, ~2015 or newer | Intel or AMD x86, ~3 years old or newer | Same as Node |
+| RAM | 8 GB | 16 GB | 32 GB |
+| Storage | 256 GB SSD | 500 GB NVMe (OS) + 2 TB NVMe (timechain) | Same as Node |
+| Network | Any broadband | Unmetered, ~200 Mbps down / 50 Mbps up | Same as Node |
+| Also needed | — | — | A domain for publicly accessible services |
---
-## Use Sovran_SystemsOS your way
+## Use it your way
You do not have to replace the operating system on your current computer to
benefit from Sovran_SystemsOS.
-### Use it as your everyday computer
+### As your everyday computer
Install Sovran_SystemsOS on a desktop, laptop, or mini PC and use its clean
-GNOME desktop as your daily operating system.
+GNOME desktop as your daily operating system, with the Bitcoin software and
+the tools of your selected mode already in place.
-You receive a private desktop, the Sovran Hub, everyday applications, Bitcoin
-software, and the tools included with your selected mode.
+### As a private Bitcoin and home server
-### Use it as a private Bitcoin and home server
+Prefer to keep using Windows, macOS, Linux, Android, or iOS? Install
+Sovran_SystemsOS on a separate computer and let it run quietly on your local
+network, with or without a monitor. From any other device on the same network,
+open a browser, visit `http://sovransystemsos.local`, and manage everything
+from [The Sovran Hub](#the-sovran-hub).
-Prefer to keep using Windows, macOS, Linux, Android, or iOS?
-
-Install Sovran_SystemsOS on a separate computer and let it run quietly on your
-local network. From another device connected to the same network, open a web
-browser and visit:
-
-```text
-http://sovransystemsos.local
-```
-
-Sign in to the Sovran Hub and manage the system from your:
-
-- Windows computer
-- Mac
-- Linux computer
-- Phone
-- Tablet
-- Any other device with a modern web browser
-
-Your Sovran_SystemsOS machine can operate as a private, headless Bitcoin and
-self-hosting appliance. It can run without a monitor during everyday use while
-you control it from the devices you already know.
-
-Your existing devices remain familiar. Sovran_SystemsOS provides the
-independent infrastructure behind them.
-
-> **Local access:** `sovransystemsos.local` is intended for devices connected
-> to the same local network as the Sovran_SystemsOS machine. The Hub is
-> protected by authentication and is not automatically exposed to the public
-> internet.
+Your existing devices stay familiar. Sovran_SystemsOS provides the independent
+infrastructure behind them.
---
@@ -262,29 +218,16 @@ independent infrastructure behind them.
The Sovran Hub is the command center built into Sovran_SystemsOS. It is both a
local desktop application and a private web interface served directly by your
-Sovran_SystemsOS machine.
-
-Use the Hub directly from the Sovran_SystemsOS desktop, or open it from another
-device at:
-
-```text
-http://sovransystemsos.local
-```
+Sovran_SystemsOS machine. Nothing needs to be installed on the device opening
+the Hub: you only need a modern browser and access to the same local network.
From one place, the Hub helps you:
-- Open and monitor your services
-- See what is running
-- Start and stop supported services
-- Configure system features
-- Manage service domains
-- Reach your Bitcoin tools
-- Manage your private cloud and communications
-- Perform supported system operations
-- Control Sovran_SystemsOS without everyday terminal commands
-
-Nothing needs to be installed on the device opening the Hub. You only need a
-modern browser and access to the same local network.
+- Open, monitor, start, and stop your services
+- See what is running and configure system features
+- Manage service domains and credentials
+- Reach your Bitcoin tools, private cloud, and communications
+- Perform supported system operations without everyday terminal commands
### Example home setup
@@ -316,199 +259,71 @@ modern browser and access to the same local network.
Keep using the devices you already own. Sovran_SystemsOS becomes the private
Bitcoin and digital infrastructure behind them.
----
-
-## What is included?
-
-Depending on the selected mode and enabled features, Sovran_SystemsOS brings
-together a growing collection of private, open-source tools.
-
-### Your money — Bitcoin sovereignty
-
-- Bitcoin Knots
-- Electrs
-- LND
-- Ride The Lightning
-- BTCPay Server
-- Sparrow Wallet
-- Bisq
-- Bisq 2
-- Tor integration
-- Automatic wallet-to-node connections
-- Optional Mempool explorer
-
-Run your own Bitcoin infrastructure. Verify your own money. Trust no one.
-
-### Your voice — private communications
-
-- Matrix Synapse
-- Element
-- Optional Element calling
-- Optional Haven Nostr relay
-
-Communicate without making Big Tech the owner of your identity or
-conversations.
-
-### Your cloud — self-hosting and storage
-
-- Nextcloud
-- Vaultwarden
-- WordPress
-- Caddy
-- Private service domains
-- Optional remote desktop
-
-Keep your files, passwords, calendar, contacts, website, and services on
-hardware you control.
-
-### Your desktop
-
-- GNOME desktop
-- Brave
-- Firefox
-- File management
-- Calendar and contacts
-- Email client
-- Office applications
-- System monitoring tools
-- Administration utilities
-
-Not every service is enabled in every mode. The Sovran Hub presents and
-manages the features available on your system.
+> **Local access:** the Hub is available at
+> `http://sovransystemsos.local` to devices connected to the same local
+> network. It is protected by authentication and is not automatically exposed
+> to the public internet.
---
-## What makes Sovran_SystemsOS different?
-
-There are Linux distributions that can run a Bitcoin wallet. There are node
-projects that can run Bitcoin services. There are self-hosting projects that
-can replace individual cloud applications.
-
-Sovran_SystemsOS brings those worlds together.
-
-### Bitcoin from the first boot
-
-Sparrow, Bisq, and Bisq 2 are not optional suggestions buried in
-documentation. They are installed as part of the operating system and
-available from the desktop.
-
-### A complete path
-
-Begin with a private desktop and self-custody. Grow into peer-to-peer Bitcoin
-exchange, your own node, Lightning, Bitcoin payments, and complete
-self-hosting.
-
-### One control center
-
-The Sovran Hub brings the Bitcoin stack, private services, credentials, system
-status, and supported configuration into one interface.
-
-### Your hardware
-
-The system runs on a computer you control. Your node, wallets, data, services,
-and system configuration do not depend on a Sovran Systems cloud account.
-
-### Reproducible foundation
-
-Sovran_SystemsOS is built declaratively with NixOS and Nix flakes. Its inputs
-are pinned, its configuration can be audited, and the system can be rebuilt
-from source.
-
----
-
-# Download and install it yourself
+## Install Sovran_SystemsOS
Sovran_SystemsOS is free and open source. You can download the installer,
-verify it, write it to a USB drive, and install it yourself.
-
-You remain in control from the very first step.
-
-## What is an ISO?
+verify it, write it to a USB drive, and install it yourself, staying in
+control from the very first step.
An ISO is a complete installation image containing the operating system and
-the files required to boot the Sovran_SystemsOS installer.
+installer. It is not copied to a USB drive like a document; it must be written
+with an imaging application such as [Balena Etcher](https://etcher.balena.io).
-The ISO is not copied to a USB drive like an ordinary document. It must be
-written to the USB drive with an imaging application such as Balena Etcher.
+**Before you begin, you will need:**
-## What you need
-
-Before beginning, you will need:
-
-- A compatible 64-bit computer
+- A compatible 64-bit computer, and a backup of anything important on it
- A USB drive that can be erased
- Another computer for downloading and preparing the installer
- An internet connection
-- A USB imaging application such as Balena Etcher
-- A backup of anything important on the destination computer
> **Important:** Installing an operating system can erase the selected
> destination drive. Back up important files and review every disk selection
> carefully before continuing.
----
+### 1. Download the ISO and checksum
-## Step 1: Download the ISO
+- [Download Sovran_SystemsOS.iso](https://downloads.sovransystems.com/Sovran_SystemsOS.iso)
+- [Download Sovran_SystemsOS.iso.sha256](https://downloads.sovransystems.com/Sovran_SystemsOS.iso.sha256)
-Download the Sovran_SystemsOS installer:
+The download may take some time. Do not rename or modify the ISO before
+verifying it, and keep both files in the same folder.
-### [Download Sovran_SystemsOS.iso](https://downloads.sovransystems.com/Sovran_SystemsOS.iso)
+### 2. Verify the checksum
-Depending on your browser and internet connection, the download may take some
-time. Do not rename or modify the file before verifying it.
+A checksum is a digital fingerprint of a file. Verifying it confirms that the
+ISO downloaded completely, was not accidentally corrupted, and matches the
+published image. The checksum produced from your ISO must match the published
+checksum exactly.
-The downloaded file should be named:
-
-```text
-Sovran_SystemsOS.iso
-```
-
----
-
-## Step 2: Download the checksum
-
-Download the matching SHA-256 checksum:
-
-### [Download Sovran_SystemsOS.iso.sha256](https://downloads.sovransystems.com/Sovran_SystemsOS.iso.sha256)
-
-A checksum is a digital fingerprint of a file.
-
-Verifying the checksum confirms that:
-
-- The complete ISO downloaded successfully
-- The file was not accidentally corrupted
-- The downloaded file matches the published image
-
-The checksum produced from your ISO must match the published checksum exactly.
-
----
-
-## Step 3: Verify the ISO
-
-Place the ISO and checksum file in the same folder, then follow the
-instructions for your current operating system.
-
-### Linux
+