Fedora Atomic · GNOME · inspired by Bluefin

The desktop that takes care of itself.

Amethystora is a Linux desktop you set up once and then simply use. Hardened at every layer, with signed, atomic updates. Windows that tile themselves, ten themes a keystroke away, and an AI agent that knows how your system works.

sudo bootc switch ghcr.io/iarsslen/amethystora:stable

From any Fedora Atomic or Universal Blue system, then restart.

  • Signed updates
  • Firewall on
  • Kernel lockdown
  • Keyboard isolation

Standing on the shoulders of

  • FedoraAtomic base
  • Universal Bluebase images
  • Bluefinthe inspiration
  • GNOMEthe desktop
  • bootcimage-based updates
  • Flathubapps

The desktop

Driven from the keyboard.
Beautiful by default.

Windows tile themselves with PaperWM, each workspace a strip that scrolls to keep the focused one in view. Six workspaces that never move. And one shortcut repaints GNOME, the terminal, the prompt, the dock and the wallpaper at once.

  • Super← →Move between windows
  • Super1–6Jump to a workspace
  • SuperReturnOpen a terminal
  • SuperSpaceSearch everything
  • SuperCtrlShiftSpacePick a theme
  • SuperF1Open the manual

Security

Secure by default.
Hardened at every layer.

Fedora Workstation leaves a lot open to be convenient. Amethystora closes it, layer by layer, and keeps the stronger options one ujustcommand away. It all works out of the box, and nothing asks you to become a security expert.

  • 5layersof defence, from the firewall to the kernel to your own accounts
  • 100%signedEvery update is verified against Amethystora's key before it installs
  • 15minHow often the security watcher checks, and tells you what's new
  1. Network

    Nothing gets in that you didn't let in.

    • The firewall rejects incoming connections. Only device discovery, file sharing, IPv6 setup and GSConnect are allowed.
    • fail2ban bans an address after five failed logins, for longer each time it comes back.
    • The SSH server stays off, and refuses root logins when you turn it on.
    ujust blocked-addresses

Check it yourself

Lynis goes through a few hundred checks and tells you what to do about each one. It reads the system and changes nothing.

ujust security-audit

Features

Everything you'd set up yourself. Already done.

Amethystora takes Fedora's rock-solid atomic base and finishes the desktop: tiling, themes, hardening and tooling, tested together and shipped as one image.

  1. Amethystorathemes, tiling, hardening, the agent
  2. Universal Bluehardware support and codecs
  3. Fedora Atomicthe base system and kernel

One image. Updated whole.

The operating system is built, tested and signed in CI, then replaced as a whole. Updates arrive in the background and take over at your next restart, all at once. Nothing is ever half-updated.

stable weekly, kernel held backlatest newest Fedorabeta what comes next

An agent that knows your system

Claude Code and opencode come set up with a skill that explains Amethystora to them. Super+Ctrl+Shift+A opens one, and it asks before it acts.

❯ amethystora-agent ask "make the dock icons smaller"

Ten themes, one keystroke

Each theme is a single palette file that everything is rendered from. Add your own in ~/.config.

  • Amethystora
  • Amethystora Light
  • Tokyo Night
  • Catppuccin Mocha
  • Catppuccin Latte
  • Gruvbox
  • Nord
  • Rosé Pine Dawn
  • Everforest
  • Matte Black

Hardened by default

Only signed updates are accepted. The firewall rejects incoming connections, and apps can't read your keyboard.

How it's hardened

Developer mode

amethystora-dx adds Docker, Incus, libvirt and VS Code. Toolchains live in containers and never touch the image.

DockerIncuslibvirtVS CodeDistrobox

Software that can't break it

Apps from Flathub through Bazaar, command-line tools from Homebrew, anything else in a container.

A manual that ships offline

Super+F1 opens a searchable guide to everything, from the hotkeys to rollbacks.

Beautiful from power-on

The boot menu, splash and login share the same crystal field, and the gem glints in fastfetch.

Atomic updates

Updates you'll never babysit.

No half-finished upgrades to recover from, nothing to clean up, no reinstall every couple of years. The new system is staged next to the running one and swapped in whole.

Automatic and quiet

The system, your Flatpaks and your Homebrew tools update in the background. Or all at once, right now:

ujust update

Rollback in one boot

The previous system is always kept. Pick it at the boot menu, or make it the default:

sudo rpm-ostree rollback

Your things stay put

/usr is the image and read-only. /home, /etc and /var are yours, and no update ever touches them.

AI agent

An agent that knows how your system works.

Every image is set up for Claude Code and opencode, with a skill that explains Amethystora to them: which paths belong to the image and which are yours, how themes and keybindings work, how to install software on an atomic system, and what to ask you first.

  • Asks before it actsIt opens in its normal mode, so every change is yours to approve.
  • Diagnoses without touchingReads logs and core dumps, changes nothing, and reports the cause.
  • Yours to switch offujust toggle-agentic removes the menu entry, the hotkey and the skill.
❯ amethystora-agent diagnose "wifi drops after suspend"Reading the journal since the last resume…Checking NetworkManager, the wifi driver and power settings…● Found it: the card drops its link on resume, three times this week.● Cause: wifi power saving is on for this adapter. Proposed fix (nothing has been changed)Turn power saving off for wifi in a file of your own under/etc/NetworkManager/conf.d/, then restart NetworkManager. Apply it? [y/N] 
An illustration: asked why wifi drops after suspend, the agent reads the journal, finds that wifi power saving is on, and proposes turning it off, without changing anything until you say yes.

Get Amethystora

Switch in one command.

Amethystora installs by switching an existing Fedora Atomic system to its image. Your files in /home, /etc and /var come along. Flatpaks, Homebrew and containers do too.

  1. Start from Fedora Atomic

    Install Fedora Silverblue, or use any Fedora Atomic or Universal Blue system you already run. Choose disk encryption in the installer.

  2. Switch the image

    Pick an image and a stream below, run the command, and restart.

  3. Enroll the Secure Boot key

    If Secure Boot is on, enroll the key when asked on the next boot. The password is amethystora.

Image
Stream

Built weekly, with the kernel held back to Fedora CoreOS's so regressions are caught first. For everyone.

sudo bootc switch ghcr.io/iarsslen/amethystora:stable

FAQ

Questions, answered.

Everything else is in the manual that ships with the image. Press Super+F1 once you're in.

Is this Fedora?

Underneath, yes. Amethystora is built on Fedora's atomic desktop and GNOME, starting from Universal Blue's Fedora images, and follows Fedora's releases. What it adds is the desktop around it, the hardening, the tools, and an image that is tested and signed before it reaches you.

How is it different from Bluefin?

Bluefin is the inspiration, not the base. Amethystora is built directly on Universal Blue's Fedora Silverblue image, and its desktop layer began as Bluefin's before it was brought in and maintained here. On top it adds PaperWM tiling with six fixed workspaces, a theme switcher that repaints the whole desktop, a hardened security baseline, the built-in AI agent, an offline manual and its own artwork from boot menu to login.

Why can't I use dnf install?

Because the system is an image, and the image is the same on every machine. That is what makes updates safe and rollbacks instant. Apps come from Flathub, tools from Homebrew, and anything else from a container, where dnf install works exactly as you know it.

Can I go back if an update breaks something?

Yes. The previous system is always kept. Pick the second entry at the boot menu, or run sudo rpm-ostree rollback and restart. Your files and settings are the same in both.

Can I play games?

Yes. Install Steam, Heroic or Lutris from Bazaar. Many Windows games run through Proton in Steam. Some launchers still need X11, which you can grant to that one app in Flatseal.

Does it work with NVIDIA graphics?

There are NVIDIA images with NVIDIA's open kernel driver, for the standard and developer desktops. They are paused at the moment, so check that the tag you want exists before switching to one.

Can I trust the image?

It is built in public on GitHub from the source in iarsslen/amethystora, signed with a key whose public half ships in every image, and only accepted by your machine if that signature checks out.

Set it up once.
Then simply use it.