About
agentos is Fedora bootc with the agentos runtime built in. The whole OS is one container image. It updates atomically with bootc upgrade and rolls back the same way, so nothing is ever half-applied.
On top of that, every agent task is a transaction:
- The agent sees only what you grant. By default that is the current folder: no
~/.ssh, no other projects, no environment secrets. - Network is an allowlist, and every connection is logged.
- Writes land in an overlay, not in your files. You
diff, thencommitorrollback, all of it or per path. - Each tool call and each model call, with its cost, goes into a hash-chained journal the agent cannot reach. A task can carry a budget.
No root, no daemon to trust, no containers to build: user namespaces, overlayfs and Landlock, all in the kernel.
On the real OS
A booted agentos disk, checked over SSH. These are the actual outputs from the machine.
$ grep PRETTY_NAME /etc/os-releasePRETTY_NAME="Fedora Linux 42 (Adams)" $ agent --versionagent 0.0.1 (f6dc82c) $ agent doctor✓ kernel 6.19.14-101.fc42.x86_64✓ user uid 1000✓ user namespaces allowed✓ task store /var/home/ci/.local/share/agentos✓ sandbox unprivileged namespaces + overlayfs work✓ landlock ABI v7✓ seccomp available✓ limits --memory/--cpus/--pids through systemd user scopes
Get it
There is no published image or ISO yet. You build it from the repository, which takes one command.
1. Build the image
podman build -f image/Containerfile -t localhost/agentos .
2. Make a disk and boot it
Put your SSH key in image/disk.toml, then build a disk with bootc-image-builder. Boot the result in QEMU, UTM or a cloud. raw, ami and anaconda-iso work too.
sudo podman run --rm --privileged --pull=newer \ --security-opt label=type:unconfined_t \ -v ./image/disk.toml:/config.toml:ro -v ./output:/output \ -v /var/lib/containers/storage:/var/lib/containers/storage \ quay.io/centos-bootc/bootc-image-builder:latest \ --type qcow2 --rootfs xfs localhost/agentos:latest
Or move a machine you already have
On any bootc system (Fedora bootc, or Fedora Atomic such as Silverblue), once the image is in a registry you control:
sudo bootc switch ghcr.io/<you>/agentos:latest
Or just the runtime
On an existing Linux machine with kernel 5.11+ and Rust 1.85+:
cargo build --release && sudo install -m 0755 target/release/agent /usr/local/bin/agent agent doctor
What's inside
| Base | Fedora bootc 42 |
|---|---|
| Updates | bootc upgrade, bootc rollback |
| Runtime | /usr/bin/agent, the same binary CI tests |
| Service | agentd, a systemd user service |
| Tools | git, curl, python3, util-linux |
| Kernel | Landlock and unprivileged user namespaces, so agent doctor passes with nothing to configure |
Use
systemctl --user enable --now agentd agent do "your task" agent run -- CMD # the same sandbox for any command agent diff | commit | rollback | log
Give a task a budget with --budget 2usd and it cannot spend more.
Docs
README.md: overview and installdocs/DESIGN.md: the full design and roadmapimage/README.md: building and booting the OS image