Cyberus Linux 26.05 is a drop-in for NixOS 26.05 with 5-years of long-term support. Some time has passed since our Cyberus Linux 26.05 launch post, so I wanted to give you an update on what’s been happening in Cyberus Linux in the last months.
We’ve Renamed to Cyberus Linux
The most visible change is obviously our new name. We’ve detailed the reasons in a blog post. We’ve made the transition for users as smooth as possible: all domains redirect, and in case you need to change your configuration, there will be actionable advice. And the most important thing: we kept our gorgeous logo. If you encounter any issues, please let us know!
CRA-Ready Image-Based Systems
We believe that Nix and NixOS are the best technologies to build Linux-based systems for the real world. But an out-of-the-box NixOS has trouble meeting the device integrity requirements of the Cyber Resilience Act. For this reason, we are developing a set of opinionated modules that allow you to build image-based systems with A/B updates, Secure Boot, and a chain of trust that extends all the way to your root partition. Under the hood, this architecture is driven by systemd-sysupdate, systemd-repart, and dm-verity and based on the amazing work that already exist in Nixpkgs. These modules are and will continue to be Open Source.
The first part of this is now available. Converting an existing NixOS configuration is usually as easy as importing the module from our flake and removing any existing bootloader or filesystem configuration. Of course, there is still work left to be done: On the roadmap for this year is support for Secure Boot and more.
Image-based systems bring another advantage: they do not require a nix-daemon to run on the target device. Configuration evaluation happens on your existing beefy CI machines instead of your target device. Given the currently high RAM prices, deploying edge systems with minimal RAM is highly appealing.
How It Fits Together
Our goal is to help people ship NixOS-based devices that meet the CRA requirements. The device integrity is only one part of these requirements. With Cyberus Linux, we address the lifetime and security requirements as well. We already offer a 5-year LTS version of 26.05 to extend the lifetime of your products with minimal maintenance costs.
With the per-customer vulnerability feeds that we are rolling out soon, the maintenance costs will shrink even further. Available as a subscription service, these feeds allow you to easily see which vulnerabilities you are affected by and whether an update of your product is necessary.
We’re eager to hear your thoughts about NixOS and the CRA! Join our Matrix room to get updates as they happen.