Open source only.
Enforced at build time, not promised in a README. The system layer asserts that allowUnfree is off and fails the build otherwise.
wasisabi.enforceLibre = false opts out, in the open.
NixOS modules · Wayland · libre only
wasisabi is an opinionated, open-source-only Wayland desktop for NixOS. Every default is an option you can override, the install is an ordinary flake you own, and nothing asks for an account.
The two rules
Enforced at build time, not promised in a README. The system layer asserts that allowUnfree is off and fails the build otherwise.
wasisabi.enforceLibre = false opts out, in the open.
Every app works fully locally or against infrastructure you can host. No vendor accounts by default.
Sync is Syncthing, passwords are KeePassXC, search is SearXNG.
Not a distro
An ISO is only a shortcut that installs them. No knowledge of wasisabi is needed to use the system, or to leave it.
Both layers set everything with mkDefault, so anything you write wins. Nothing is a dotfile you must not touch: extend, override or ignore any part.
The installer leaves a plain flake in ~/nixos, as a git repo with two commits. Nothing reads it back and nothing manages it. The machine changes when the repo changes.
Remove the two module imports and you have a working NixOS machine that has never heard of wasisabi. Not a distro: the modules are the product.
The stack
One palette across the whole desktop, niri's scrollable tiling underneath, and a licence next to every piece.
Scrollable tiling
Windows sit in columns on an endless horizontal strip, and opening one never resizes the others. A handful of keys is enough to start.
AI and privacy, on the machine
A local model, private web search and a coding agent wired to both, with a web UI for its sessions on this machine only. All on by default, each one a single option.
A small open-weights model runs on the CPU and answers on a unix socket. No API key, no account, no network needed to think.
SearXNG and webveil give the agent the web with nothing to log in to. The pi coding agent is wired to both from the first boot.
Super+A, the Assistant launcher entry or the bar button opens its web UI, served on this machine only.
anon, anon-john and anon-jane have every connection forced through Tor by the kernel, fail-closed: if Tor is down they have no network, never yours. Each is proven with anonctl verify before use, carries nothing of yours, and has its own agent on the same local model.
anonctl verify
The building blocks live in nixos-modules, usable on any NixOS machine. What was verified and what was not: notes/agents.md.
Install
Boot the installer, answer a few questions, and what you are left with is a flake you own.
v0.1.0 · preview
Netinstall ISO
1.56 GB. A text installer that downloads the rest; needs a network.
UEFI only. SHA256SUMS · release notes
Write an ISO to a USB stick and boot it on a UEFI machine. The live ISO boots straight into the desktop, so you can try it before anything touches the disk; the netinstall one is smaller and fetches the rest.
Hostname, user, keyboard layout, disk, and whether to encrypt secrets. Skip the rest and you get the defaults, which keep following the project.
Your machine is ~/nixos. Secrets are encrypted with sops to one age key, so the repo can be pushed anywhere. The repo plus the key is the whole machine: after a wipe, restore rebuilds it.
sha256sum -c --ignore-missing SHA256SUMS
sudo dd if=wasisabi-netinstall.iso of=/dev/sdX bs=4M status=progress oflag=sync
# boot the stick, then:
sudo wasisabi-installAny version, from its tag: the same image, from source.
nix build github:wighawag/wasisabi#iso-offline
# write result/iso/*.iso to a USB stick, boot itChange it by editing it. /etc/nixos links here,
so no flag is needed.
cd ~/nixos && $EDITOR configuration.nix
sudo nixos-rebuild switch
git commit -am "..." && git pushEncrypted with sops to one age key. Keep a copy of the key: the repo plus the key is the whole machine.
wasisabi-secrets edit # decrypted, in $EDITOR
wasisabi-secrets password # in the repo and now
wasisabi-secrets backup # show the age key againAdd the flake input, import the two modules, and opt in per host and per user. Both are inert until enabled.
{
wasisabi.enable = true; # system layer
home-manager.users.me = {
imports = [ wasisabi.homeModules.wasisabi ];
wasisabi.enable = true; # apps, dotfiles, keys
};
}The installer fills in this same template, so the two paths cannot diverge.
nix flake new -t github:wighawag/wasisabi ~/nixos
cd ~/nixos && git init && git add -A
sudo nixos-rebuild switch --flake ~/nixosHow the installer works, restoring after a wipe, fleet repos and what is verified: notes/installer.md.
Imperfect, impermanent, yours.
Nothing about it needs to last longer than you want it to. Take what you like, override the rest, leave whenever.
Install wasisabi