In depth
The rest of this handbook is for the owner of a box. This chapter is for the people who build LosOS, run an edge or cut a release: how the pieces fit together, why each one sits where it does, and how to change them.
LosOS is a NixOS appliance for a mini-PC. It runs Nextcloud for your own files and can lend spare disk and CPU to a mesh of other LosOS boxes. There is no SSH and no login shell. You administer it from a web page, and it upgrades itself.
The root filesystem is a tmpfs that is rebuilt on every boot. Only the
directories listed in modules/impermanence.nix survive, on an encrypted
/persist partition.
Pages
- Install in depth. The installer ISO, Secure Boot, TPM, the demo image, growing the disk.
- Administration. The admin UI, settings, upgrades and the nightly reboot.
- Mesh. Contributing storage and compute to other boxes.
- Market. Selling the disk and CPU a box already shares (planned).
- Virtual machines. Renting machines on the mesh and hosting other boxes' machines.
- Widget builder. An AI agent writes a widget from a description, paid from a prepaid balance.
- Master proxy. Reaching the box from the internet without opening a port.
- Edge federation. Your own edge on the LAN, relayed through the official ones.
- Lab. The setup visualiser at
/lab/, its simulated and real guests. - Hardening. The default hardening baseline and the opt-in flags.
- TPM and the disk key. What the chip does, and what a box without one gives up.
- Security model. What is and is not defended.
- Architecture. How the pieces fit together.
Compared with alternatives
- A NAS (Synology, QNAP). Same idea, a box with a web UI. The difference is that the root here is discarded on every boot, so an attacker's changes last until the next reboot, which comes at 00:07 each night at the latest. You can also read and rebuild everything the box runs.
- A VPS. The box is in your home and its disk is encrypted. The key is sealed to the box's TPM chip, or kept on the boot partition on a machine without one. The optional master proxy gives it a public address without an inbound port.
- Plain NixOS. You could write all of this yourself. Here it is already written, and the user isolation, encrypted persistence, disk growth, hardening and mesh gating each have a VM test.
- Other self-hosting stacks. None of them lend capacity to a mesh only while the owner's time window is open and the box is idle.
What it is not
- Not a general-purpose server. There is no shell by design.
- Not a backup. Keep copies of
/persistsomewhere else. - Not finished.