Open-source operating system
RegicideOS: Immutable Linux, built from source
A Rust-first, immutable Linux distribution built on Gentoo and Catalyst for defense, cybersecurity, healthcare, manufacturing, finance, and any organization that treats self-ownership and auditability as requirements. Commercial support is available on a sliding scale.
Current status
Shipped
- Immutable Gentoo + Catalyst stage4 base image
- COSMIC desktop default environment
- Btrfs read-only root with rollback support
- Rust-first local tooling and Dagger build pipeline
- Public GitHub repo and documentation
On the roadmap
- Secure Boot and measured boot flows
- Automated SBOM and CVE scanning
- hardened SELinux/AppArmor policies
- Fleet management and remote attestation
Security honesty: RegicideOS is not a hardened distribution by default. It does not ship Secure Boot, measured boot, mandatory access control beyond Gentoo defaults, or automated SBOM/CVE scanning. These can be added on top, and they are on the roadmap, but they are not part of the default image today.
Immutable by design
Gentoo + Catalyst stage4 with COSMIC desktop as the default install. Read-only root, transactional updates, and a build pipeline you can change manually or with automation, with docs, AGENTS.md, and Skills.md.
Rust-first tooling
Core utilities are written in Rust for memory safety and auditability, with secure local builds from source.
Btrfs by default
Read-only Btrfs root with separate stateful subvolumes, atomic updates, and straightforward rollback when a new image needs to be undone.
Compared to other immutable distributions
RegicideOS is inspired by projects like Fedora Silverblue and Fedora Atomic, but it works with Gentoo's emerge and Portage, uses Btrfs for updates and versioning, and prefers Distrobox for containers over Toolbox. Because updates and rollbacks live inside Btrfs subvolumes instead of a separate image orchestrator, the moving-parts surface is smaller than rpm-ostree, while keeping the flexibility of source-based package management.
RegicideOS is not a hardened distribution. It does not ship Secure Boot, measured boot, mandatory access control beyond Gentoo defaults, or automated SBOM/CVE scanning. Those can be added on top, but they are not part of the default image.
How you are meant to use it
The intention is to boot into an immutable GUI desktop, then live inside containers and Flatpaks. Install GUI applications through Flatpak. Do development work inside Distrobox containers, choosing whatever Linux distribution a project needs, so each workspace gets its own toolchain and project isolation. Changes to the root filesystem happen less often than on a normal Gentoo install, but when they do happen they can be reproduced through the Dagger build pipeline, where every OS setting can be modified to match your intent.
If you have ever used Linux before, the value is immediate: instead of a vendor-curated desktop that drifts behind opaque updates, you get a system you can rebuild from source, inspect line by line, and roll back when policy or reality changes. A full source build of Gentoo takes a long time, but the result is a desktop, workstation, or fleet image your organization actually owns.
What you get with business support
Direct engineering support from the team behind RegicideOS for organizations running it in demanding environments. No retainers, no lock-in. Pay as you go, with sliding-scale pricing for defense, cybersecurity, healthcare, manufacturing, finance, research teams, and other regulated or high-sovereignty deployments.
Build pipeline help
Get unstuck on Catalyst specs, Portage overlays, COSMIC desktop customization, local builds from source, and ISO generation.
Deployment & install
Assistance with legacy and UEFI bootloader setup, LUKS + Btrfs layouts, GRUB issues, and hardware bring-up on target systems.
Operations & monitoring
Connect alerts to your monitoring stack, tune update policies, and extend the local tooling API to fit your workflow.
Security & hardening
Guidance on immutable root policies, SBOM generation, CVE scanning, container runtime setup, and secure boot flows.
Support for demanding deployments
Tell me what you are building, the environment it needs to run in, and the budget you are working with. I'll propose a fair rate and scope before any work starts.
Email hello@vibecodingagency.comTypical response time: one business day.