Early development

Many stars. One system.

Agent-native Linux, built around trust.

SorayaOS is an agent-native, security-focused Linux distribution for containers, servers, desktops, and fleets. A common foundation for people and agents, designed around immutable systems, explicit permissions, and verifiable changes, from one machine to a fleet.

What it is

An immutable foundation with every change declared

Minimal images. Declared inputs. Reproducible builds. The same ideas apply whether the system is a container, a server, a desktop, or a group of them.

Immutable systems

The root filesystem is read-only. Hosts move between whole images and roll back to the previous one rather than patching themselves in place.

Verifiable artifacts

Every package and image is signed, content-addressed and carries a software bill of materials and provenance. Building from the same declared inputs produces the same bytes.

Deliberate control

People and agents operate through structured interfaces with explicit identity, scope and policy. These are design principles that the running software is still growing into.

How a system is built

From a package list to a running host

Each step consumes the previous step's verified output. Nothing downstream depends on a machine's clock, hostname or path.

  1. Import packagesDebian packages become signed, content-addressed SorayaOS packages with a reproducible payload.
  2. Publish a snapshotAn immutable repository snapshot pins one version of every package per architecture.
  3. Resolve and buildAn image recipe is resolved against the snapshot into a lockfile, then assembled into an OCI image.
  4. VerifySignatures, digests, bills of materials and repository freshness are checked before anything is trusted.
  5. Boot and updateDawn mounts the verified root and hands control to Polaris. Hosts later move between images with rollback.

Steps 1 to 4 work today for container images. Boot is demonstrated in a virtual machine. Updates are planned. See what is implemented.

Editions

Three editions, one trust model

Container, Server and Desktop share the same packages, verification and image model. Fleet management spans all three.

SorayaOS Container

Minimal application and agent workload images with exactly the packages a workload declares.

Available as reproducible OCI images built from the verified repository.

SorayaOS Server

Immutable bootable hosts for managed services, with persistent data kept apart from the system image.

Experimental direct boot, networking and services in QEMU; firmware boot and disk integration continue.

SorayaOS Desktop

Interactive work by people and agents on the same immutable foundation, with personal files on persistent storage.

Planned a nested preview exists; login, sessions and persistence are not yet demonstrated.

Read about the editions and fleets

Components

Eight named parts, plain roles

The names give the system character. The roles make it understandable. You can build an image without learning any of them.

  • Atlas

    Repository access and publication

    Available
  • Mosaic

    Image resolution and construction

    Available
  • Spectra

    Artifact signing and verification

    Available
  • Dawn

    Initramfs: find, verify and mount the root

    Experimental
  • Polaris

    PID 1 and local host lifecycle

    Experimental
  • Fusion

    Reproducible source builds

    Planned
  • Orbit

    Host image updates and rollback

    Planned
  • Alcyone

    Fleet inventory and coordination

    Planned

What each component does and does not do

The name

Named for the Pleiades

Soraya is a Persian form of Thurayya, the Arabic name for the Pleiades: the familiar cluster of seven lights in Taurus. The mark is seven lights with an open rhythm, one for the whole project rather than one per component.

About the name and the project