Independent Developer Builds Hardened Arch Linux OS, Drops Cryptographic Rootfs Protection
An independent Linux developer building a security app called RoamSwitch has begun creating a companion hardened operating system, RoamSwitch OS, to address security gaps that userland applications cannot reach. The project is based on Arch Linux and packaged as a bootable ISO, layering proven tools such as AppArmor, fapolicyd, auditd, Falco, and TPM2 rather than building components from scratch. The system is implemented as a Rust workspace with around 39 crates, each handling a specific defensive feature and running as systemd services or timer units, with modules sharing state through a unified incident timeline. The developer ruled out an immutable image-based approach similar to Fedora Silverblue or ChromeOS, citing the significantly greater engineering complexity involved. The project remains in a research and showcase phase, verified on real hardware and in QEMU but not yet recommended for production use due to the absence of third-party security audits or legal review.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in