snowdesktop: Immutable Debian desktop for developers
Summary
SnowLinux is a fully customizable immutable Debian-based desktop distribution for developers, built with mkosi and inspired by ParticleOS, featuring Secure Boot signing with user keys, TPM/FIDO2 LUKS encryption, and preinstalled snap, flatpak, and docker.
View Cached Full Text
Cached at: 09/30/26, 12:12 PM
frostyard/snowdesktop
Source: https://github.com/frostyard/snowdesktop
SnowLinux
SnowLinux is a fully customizable immutable distribution implementing the concepts described in Fitting Everything Together.
Note that SnowLinux is still in development, and we don’t provide any backwards compatibility guarantees at all.
SnowLinux is inspired by and derived from ParticleOS
The SnowLinux image is built using mkosi. You will need to install the current main branch of mkosi to build current SnowLinux images.
Signing keys
SnowLinux images are signed for Secure Boot with the user’s keys. To generate a new key,
run mkosi genkey. The key must be stored safely, it will be required to sign updates.
The key can be stored in a smartcard. Then you have to set the key in mkosi.local.conf:
[Validation]
SecureBootKey=pkcs11:object=Private key 1;type=private
SecureBootKeySource=provider:pkcs11
SignExpectedPcrKey=pkcs11:object=Private key 1;type=private
SignExpectedPcrKeySource=provider:pkcs11
VerityKey=pkcs11:object=Private key 1;type=private
VerityKeySource=provider:pkcs11
Installation
Before installing SnowLinux, make sure that Secure Boot is in setup mode on the
target system. The Secure Boot mode can be configured in the UEFI firmware
interface of the target system. If there’s an existing Linux installation on the
target system already, run systemctl reboot --firmware-setup to reboot into
the UEFI firmware interface. At the same time, make sure the UEFI firmware
interface is password protected so an attacker cannot just disable Secure Boot
again.
To install SnowLinux with a USB drive, first build the image on an existing
Linux system as described above. Then, burn it to the USB drive with
mkosi burn /dev/<usb>. Once burned to the USB drive, plug the USB drive into
the system onto which you’d like to install SnowLinux and boot into the USB
drive via the firmware. Then, boot into the “Installer” UKI profile. When you
end up in the root shell, run
snowctl install
to install SnowLinux to the system’s drive. Finally, reboot into the target
drive (not the USB) and the regular profile (not the installer one) to complete
the installation.
LUKS recovery key
systemd doesn’t support adding a recovery key to a partition enrolled with a token
only (tpm/fido2). It is possible to use cryptenroll to add a recovery password
to the root partition: cryptsetup luksAddKey --token-type systemd-tpm2 /dev/<id>
Firmwares
Only firmwares that are dependencies of a kernel module are included, but some
modules don’t declare their dependencies properly. Dependencies of a module can be
found with modinfo. If you experience missing firmwares, you should report
this to the module maintainer. FirmwareInclude= can be added in mkosi.local.conf
to include the firmware regardless of whether a module depends on it.
Software and Tool Installation
- snap preinstalled
- flatpak preinstalled
- docker preinstalled
- brew (user installable)
- systemd-sysext extensions (not started)
Similar Articles
Xsnow "protestware" in Debian
A Debian package xsnow includes a political Easter egg that displays Ukrainian flags when the language is set to Russian, sparking debate about DFSG compliance.
Using Fedora Silverblue for Compositor Development
A guide on using Fedora Silverblue, an atomic distribution, for developing the niri Wayland compositor, highlighting benefits of immutable systems for system component development.
Starling, a Linux Desktop written from scratch
Starling is a new Linux desktop environment built almost entirely by AI over six months, capable of running native apps like Chrome, Slack, and Zoom via Wayland and X11 support.
Ubuntu 26.04 Resolute Raccoon
Ubuntu 26.04 Resolute Raccoon positions itself as the next-generation Linux distribution optimized for developers, AI workloads, and cloud deployments.
Frood, an Alpine Initramfs NAS
Describes a method to run a NAS entirely from an Alpine Linux initramfs, enabling clean boot, A/B deployments, declarative git-tracked configuration, and reduced complexity compared to Alpine's diskless mode.