<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:fh="http://purl.org/syndication/history/1.0"><channel><title>AstrOS | Blog</title><description/><link>https://astros-linux.org/</link><language>en</language><fh:complete/><atom:link rel="self" href="https://astros-linux.org/blog/rss.xml"/><item><title>Breaking Change: Secure Boot - now with optional Microsoft key enrollment</title><link>https://astros-linux.org/blog/option-to-enroll-microsoft-secureboot-certs/</link><guid isPermaLink="true">https://astros-linux.org/blog/option-to-enroll-microsoft-secureboot-certs/</guid><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;aside aria-label=&quot;Existing Installations&quot;&gt;&lt;p aria-hidden=&quot;true&quot;&gt;Existing Installations&lt;/p&gt;&lt;div&gt;&lt;p&gt;We have also rotated our keys with this change. Current and future Secureboot
users must follow our &lt;a href=&quot;https://astros-linux.org/guides/key-rotation/&quot;&gt;key-rotation guide&lt;/a&gt;. Everyone else
&lt;em&gt;only&lt;/em&gt; needs to &lt;a href=&quot;https://astros-linux.org/astros/troubleshooting/#how-to-re-enroll-the-tpm&quot;&gt;re-enroll the TPM&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;&lt;/aside&gt;&lt;p&gt;&lt;img src=&quot;https://astros-linux.org/_astro/secure-boot.BrRoy5wq_2qpo8L.webp&quot; alt=&quot;systemd-boot menu&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;683&quot; height=&quot;326&quot;&gt;&lt;/p&gt;
&lt;p&gt;From the beginning, AstrOS has shipped its own custom Secure Boot keys.&lt;/p&gt;
&lt;p&gt;Until now, every device that wanted Secure Boot was required to enroll only our
custom keys in the firmware. This prevented the use of Secure Boot on devices
whose option ROMs were signed by Microsoft. As a result, many devices were
unable to use Secure Boot with AstrOS at all. This has changed.&lt;/p&gt;
&lt;p&gt;We now ship two prepared key sets under &lt;code dir=&quot;auto&quot;&gt;/boot/loader/keys/&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;code dir=&quot;auto&quot;&gt;astros&lt;/code&gt;: just as before, containing only our certificates and nothing else.&lt;/p&gt;
&lt;p&gt;&lt;code dir=&quot;auto&quot;&gt;astros+microsoft&lt;/code&gt;: containing our certificate plus Microsoft’s certificates
added to &lt;code dir=&quot;auto&quot;&gt;KEK&lt;/code&gt; and &lt;code dir=&quot;auto&quot;&gt;db&lt;/code&gt; alongside ours.&lt;/p&gt;
&lt;p&gt;Note that this doesn’t mean our boot chain is now signed by Microsoft. It only
allows the firmware to boot Microsoft-signed software / option ROMs.&lt;/p&gt;
&lt;p&gt;The user can choose which to enroll when booting from Setup Mode.&lt;/p&gt;
&lt;p&gt;Learn more on our &lt;a href=&quot;https://astros-linux.org/astros/secure-boot&quot;&gt;Secure Boot&lt;/a&gt; page.&lt;/p&gt;</content:encoded></item><item><title>Breaking change for steam-gaming extension users</title><link>https://astros-linux.org/blog/steam-gaming-breaking-change/</link><guid isPermaLink="true">https://astros-linux.org/blog/steam-gaming-breaking-change/</guid><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;a href=&quot;https://astros-linux.org/astros/breaking-changes/#2026-08-26-the-steam-gaming-extension-is-now-simply-called-gaming&quot;&gt;Read me&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Manual intervention required, your system won’t update if you don’t do this and have steam-gaming enabled!&lt;/p&gt;
&lt;p&gt;you can ignore this if you don’t use steam-gaming&lt;/p&gt;
</content:encoded></item><item><title>We now have a blog site</title><link>https://astros-linux.org/blog/we-now-have-a-blog-site/</link><guid isPermaLink="true">https://astros-linux.org/blog/we-now-have-a-blog-site/</guid><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;We now have a blog site! To make sure you don’t miss the latest AstrOS news,
subscribe to our &lt;a href=&quot;https://astros-linux.org/blog/rss.xml&quot;&gt;RSS feed&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Note: I’ve ported over the most important blogs from Reddit.&lt;/p&gt;
</content:encoded></item><item><title>We now have a Waydroid extension</title><link>https://astros-linux.org/blog/waydroid-extension/</link><guid isPermaLink="true">https://astros-linux.org/blog/waydroid-extension/</guid><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img alt=&quot;waydroid&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;3440&quot; height=&quot;1440&quot; src=&quot;https://astros-linux.org/_astro/waydroid.D9O5ppKQ_ab02i.webp&quot; srcset=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;Docs: &lt;a href=&quot;https://astros-linux.org/astros/waydroid&quot;&gt;Waydroid&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>We are now in beta 🎉</title><link>https://astros-linux.org/blog/we-are-in-beta/</link><guid isPermaLink="true">https://astros-linux.org/blog/we-are-in-beta/</guid><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img alt=&quot;AstrOS&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;3440&quot; height=&quot;1440&quot; src=&quot;https://astros-linux.org/_astro/astros.Co0QL1QR_Z1nauyM.webp&quot; srcset=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=8N9aY7UPsHA&quot;&gt;Beta announcement video&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;what-is-astros&quot;&gt;What is AstrOS?&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;It is an immutable, secure-by-default Linux distribution based on Arch Linux and the COSMIC desktop environment. It uses similar tooling as GNOME OS and KDE Linux.&lt;/p&gt;
&lt;p&gt;What makes AstrOS special is its immutable base, which is shipped as a hashed and signed /usr image that is booted by signed uki images. This combination protects your system from outside modification.&lt;/p&gt;
&lt;p&gt;AstrOS base can be extended with currently four extensions (or your own). Including a steam gaming extension with the steamos gamescope session.&lt;/p&gt;
&lt;div&gt;&lt;h3 id=&quot;technical-details&quot;&gt;Technical details&lt;/h3&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Built using mkosi&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Uses systemd-sysupdate (rollbacks too!)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Read-only /usr with signed dm-verity&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Full disk encryption is enforced (tpm required)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Systemd-sysexts and confexts (system extensions)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Highly opinionated&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;&lt;h2 id=&quot;who-is-astros-for&quot;&gt;Who is AstrOS for?&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;Anyone who wants a secure system out of the box without having to configure anything. It’s a system that just works, and you don’t have to worry about it.&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;what-has-happened-since-our-first-announcement&quot;&gt;What has happened since our &lt;a href=&quot;https://www.reddit.com/r/AstrOS_Linux/comments/1uqam1b/astros_an_immutable_securebydefault_linux/&quot;&gt;first announcement&lt;/a&gt;&lt;/h2&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Restructured the codebase into mkosi subimages.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Four new system extensions (NVIDIA, gaming mode, virtualization, and Firewalld).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Migration to systemd-confext for /etc&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Installer improvements (TPM2 check etc).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Display keymap list during first boot instead of entering it manually&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Our own theme: Orbital&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Many bug fixes&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Safe mode uki profile&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Package additions&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Compressed images and a new download infrastructure&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We moved from GitHub to Forgejo.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Our docs/homepage: &lt;a href=&quot;https://astros-linux.org&quot;&gt;https://astros-linux.org&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;And way more!&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</content:encoded></item><item><title>Goodbye Github! Welcome Forgejo</title><link>https://astros-linux.org/blog/welcome-forgejo/</link><guid isPermaLink="true">https://astros-linux.org/blog/welcome-forgejo/</guid><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Our &lt;a href=&quot;https://github.com/astros-linux/AstrOS&quot;&gt;github repo&lt;/a&gt; now is a mirror&lt;/p&gt;
&lt;p&gt;We believe that Forgejo aligns much more closely with our values of independence, and we are happy to announce that we have moved to it. To keep the barrier to contribution low, you can log in using your existing GitHub account, which makes account creation much faster and easier.&lt;/p&gt;
&lt;p&gt;You can still make issues on GitHub, though we would prefer you to use Forgejo. Pull requests are forgejo only&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://code.astros-linux.org/AstrOS/AstrOS&quot;&gt;Forgejo&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>Introducing System Extensions &amp; Nvidia support</title><link>https://astros-linux.org/blog/introducing-system-extensions/</link><guid isPermaLink="true">https://astros-linux.org/blog/introducing-system-extensions/</guid><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img alt=&quot;sysext&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1920&quot; height=&quot;1080&quot; src=&quot;https://astros-linux.org/_astro/blog-sysext.B6LDVyAW_Z1a5823.webp&quot; srcset=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;I‘m happy to announce that we got our first four system extensions.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Steam:&lt;/strong&gt; this was our first extension introducing system-wide installed Steam and the gamescope session from the Steam Deck we all know and love.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Firewall:&lt;/strong&gt; while this may get baked into the base image in the future, it is now possible to enable firewalld including a gui to configure it.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Virtualization:&lt;/strong&gt; libvirtd &amp;#x26; virt-manager. We don’t want to be another immutable distro not supporting a proper vm tool allowing gpu / USB passthrough, etc.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Nvidia:&lt;/strong&gt; we now offer Nvidia drivers as a system extension. While I couldn’t test it myself due to me not owning any Nvidia GPU, this was reported as working.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But what are system extensions and why do they exist? System Extensions are our answer for programs that can’t easily be installed using flatpak or distrobox. While we want to keep our base unbloated and minimal, this allows us to deliver packages needing deeper system access to the users who need it.&lt;/p&gt;
&lt;p&gt;How do I install them?&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://astros-linux.org/astros/installing-software/#system-extensions&quot;&gt;Take a look at our docs&lt;/a&gt;&lt;/p&gt;
</content:encoded></item></channel></rss>