A risograph print: a wide cream brush circle sweeping across dark indigo paper.

NixOS modules · Wayland · libre only

A desktop that stays yours.

wasisabi is an opinionated, open-source-only Wayland desktop for NixOS. Every default is an option you can override, the install is an ordinary flake you own, and nothing asks for an account.

The two rules

Everything else is a default you can change.

Open source only.

Enforced at build time, not promised in a README. The system layer asserts that allowUnfree is off and fails the build otherwise.

wasisabi.enforceLibre = false opts out, in the open.

No service you cannot run yourself.

Every app works fully locally or against infrastructure you can host. No vendor accounts by default.

Sync is Syncthing, passwords are KeePassXC, search is SearXNG.

Not a distro

The modules are the product.

An ISO is only a shortcut that installs them. No knowledge of wasisabi is needed to use the system, or to leave it.

Every default is an option

Both layers set everything with mkDefault, so anything you write wins. Nothing is a dotfile you must not touch: extend, override or ignore any part.

An ordinary flake you own

The installer leaves a plain flake in ~/nixos, as a git repo with two commits. Nothing reads it back and nothing manages it. The machine changes when the repo changes.

Easy to leave

Remove the two module imports and you have a working NixOS machine that has never heard of wasisabi. Not a distro: the modules are the product.

The stack

Chosen once, carefully. Swappable forever.

One palette across the whole desktop, niri's scrollable tiling underneath, and a licence next to every piece.

Desktop

Compositor
niri, scrollable tiling GPL-3.0
Login
greetd + Noctalia greeter, or tuigreet GPL / MIT
Shell
Noctalia, or Waybar + fuzzel + mako MIT
Lock and idle
swaylock + swayidle MIT
Terminal
Ghostty, or foot, kitty MIT / GPL
Files
Thunar, or Nautilus GPL

Everyday

Browser
Firefox, or LibreWolf, Chromium MPL
Editors
Neovim and Helix, both ship Apache-2.0 / MPL
Passwords
KeePassXC, local-first GPL
Sync
Syncthing, peer to peer MPL
Media
mpv + imv GPL / MIT
Terminal tools
bash + ble.sh, fzf, zoxide, atuin, zellij BSD / MIT

On the machine

Local model
llama.cpp + Gemma 4 E4B, on the CPU MIT / Apache-2.0
Coding agent
pi, with wherever as its web UI MIT / AGPL
Search
SearXNG + webveil AGPL
Recall
memonaut, your past agent sessions AGPL
Browser automation
webhands on Chromium AGPL / BSD
Anonymous accounts
anonctl, every packet through Tor AGPL

Scrollable tiling

Windows sit in columns on an endless horizontal strip, and opening one never resizes the others. A handful of keys is enough to start.

  • SuperEnter Terminal
  • SuperD Launcher
  • SuperA The assistant
  • SuperH J K L Move focus
  • SuperO Overview
  • SuperShift/ Every other key

AI and privacy, on the machine

An assistant that needs no account anywhere.

A local model, private web search and a coding agent wired to both, with a web UI for its sessions on this machine only. All on by default, each one a single option.

A model that never leaves

A small open-weights model runs on the CPU and answers on a unix socket. No API key, no account, no network needed to think.

Search without a profile

SearXNG and webveil give the agent the web with nothing to log in to. The pi coding agent is wired to both from the first boot.

One key away

Super+A, the Assistant launcher entry or the bar button opens its web UI, served on this machine only.

Three accounts that cannot leak your address

anon, anon-john and anon-jane have every connection forced through Tor by the kernel, fail-closed: if Tor is down they have no network, never yours. Each is proven with anonctl verify before use, carries nothing of yours, and has its own agent on the same local model.

anonctl verify

The building blocks live in nixos-modules, usable on any NixOS machine. What was verified and what was not: notes/agents.md.

Install

Install it. Then keep the repo.

Boot the installer, answer a few questions, and what you are left with is a flake you own.

v0.1.0 · preview

Netinstall ISO

1.56 GB. A text installer that downloads the rest; needs a network.

Download the netinstall ISO

UEFI only. SHA256SUMS · release notes

  1. 01

    Boot the installer

    Write an ISO to a USB stick and boot it on a UEFI machine. The live ISO boots straight into the desktop, so you can try it before anything touches the disk; the netinstall one is smaller and fetches the rest.

  2. 02

    Answer a few questions

    Hostname, user, keyboard layout, disk, and whether to encrypt secrets. Skip the rest and you get the defaults, which keep following the project.

  3. 03

    Keep the repo

    Your machine is ~/nixos. Secrets are encrypted with sops to one age key, so the repo can be pushed anywhere. The repo plus the key is the whole machine: after a wipe, restore rebuilds it.

Check it, write it, install

shell
sha256sum -c --ignore-missing SHA256SUMS
sudo dd if=wasisabi-netinstall.iso of=/dev/sdX bs=4M status=progress oflag=sync
# boot the stick, then:
sudo wasisabi-install

Or build an ISO yourself

Any version, from its tag: the same image, from source.

shell
nix build github:wighawag/wasisabi#iso-offline
# write result/iso/*.iso to a USB stick, boot it

Then the machine is the repo

Change it by editing it. /etc/nixos links here, so no flag is needed.

shell
cd ~/nixos && $EDITOR configuration.nix
sudo nixos-rebuild switch
git commit -am "..." && git push

Secrets that can be pushed

Encrypted with sops to one age key. Keep a copy of the key: the repo plus the key is the whole machine.

secrets
wasisabi-secrets edit       # decrypted, in $EDITOR
wasisabi-secrets password   # in the repo and now
wasisabi-secrets backup     # show the age key again

Already on NixOS?

Add the flake input, import the two modules, and opt in per host and per user. Both are inert until enabled.

configuration.nix
{
  wasisabi.enable = true;          # system layer
  home-manager.users.me = {
    imports = [ wasisabi.homeModules.wasisabi ];
    wasisabi.enable = true;        # apps, dotfiles, keys
  };
}

Or by hand, without the ISO

The installer fills in this same template, so the two paths cannot diverge.

shell
nix flake new -t github:wighawag/wasisabi ~/nixos
cd ~/nixos && git init && git add -A
sudo nixos-rebuild switch --flake ~/nixos

How the installer works, restoring after a wipe, fleet repos and what is verified: notes/installer.md.

Imperfect, impermanent, yours.

Nothing about it needs to last longer than you want it to. Take what you like, override the rest, leave whenever.

Install wasisabi