A Linux desktop built for working with AI agents. Everything is there on
first boot: the claude, codex, opencode and openclaw agents,
herdr to run them side by side,
CodexBar to keep an eye on their usage limits, the
ChatGPT (with Codex) and
OpenCode desktop apps, Google Chrome,
llmman to run models locally or connect
any agent to any provider, Docker Engine
(rootful and rootless) and
Docker Sandboxes to run agents in
isolation, QEMU with KVM for full virtual machines,
GPU runtimes for Vulkan, ROCm and NVIDIA/CUDA, and a full developer
toolset.
AgenticLinux is a bootc image: the whole OS ships as a container, so updates are atomic and rollback is one command. It is built from Fedora 44 packages on the fedora-ostree-desktops images, or from CentOS Stream 10 packages (with EPEL) on the centos-bootc image, and available for x86_64 and aarch64.
-
Download the ISO for your desktop and architecture from the latest release, boot it and install as usual.
-
Add yourself to the
dockergroup, then log out and back in (or use rootless Docker instead):sudo usermod -aG docker "$USER" -
Run an agent on a local model, or on any hosted provider:
llmman launch claude --model qwen3.8 llmman launch opencode --provider openrouter --model qwen/qwen3-coder
| Variant | Built from | Desktop | Image |
|---|---|---|---|
| kde | Fedora 44 | KDE Plasma | docker.io/ericcurtin044/agenticlinux:kde |
| gnome | Fedora 44 | GNOME | docker.io/ericcurtin044/agenticlinux:gnome |
| sway | Fedora 44 | Sway | docker.io/ericcurtin044/agenticlinux:sway |
| cosmic | Fedora 44 | COSMIC | docker.io/ericcurtin044/agenticlinux:cosmic |
| xfce | Fedora 44 | Xfce | docker.io/ericcurtin044/agenticlinux:xfce |
| budgie | Fedora 44 | Budgie | docker.io/ericcurtin044/agenticlinux:budgie |
| base | Fedora 44 | none | docker.io/ericcurtin044/agenticlinux:base |
| centos-kde | CentOS Stream 10 | KDE Plasma | docker.io/ericcurtin044/agenticlinux:centos-kde |
| centos-gnome | CentOS Stream 10 | GNOME | docker.io/ericcurtin044/agenticlinux:centos-gnome |
| centos-base | CentOS Stream 10 | none | docker.io/ericcurtin044/agenticlinux:centos-base |
The variants carry the same packages on both distributions, so the list is what CentOS Stream 10, EPEL 10 and RPM Fusion have: GNOME and KDE Plasma are the desktops that exist there. CentOS Stream's kernel tracks the next RHEL 10 minor release.
On a local model, through llmman launch, the agents need no account.
Otherwise sign in once per agent:
claude: log in in the browser on first run, or setANTHROPIC_API_KEY.codex:codex login, orprintenv OPENAI_API_KEY | codex login --with-api-key.opencode:/connectin its TUI.openclaw:openclaw onboard.llmman: export the provider's key (OPENROUTER_API_KEY, ...) beforellmman launch --provider ...;llmman providersshows which are set.
The ChatGPT app asks you to sign in when it first starts. Credentials stay in your home directory, which updates leave alone.
The desktop apps of the agents that publish an RPM are installed from it,
and start from the applications menu or as chatgpt and opencode-desktop:
- ChatGPT: OpenAI's one desktop app, which is also the Codex app (the "Codex" mode inside it). Its Linux build is a preview.
- OpenCode: relocated from
/optto/usr/libso it is part of the image rather than of the machine's first install.
CodexBar shows the agents' usage limits and spend in the tray, or with
codexbar usage in a terminal. It starts at login (see its Settings); GNOME
needs a tray extension for the icon.
The apps live in the read-only /usr, so nothing in them can update itself
in place: they are updated with the image, like everything else.
Two daemons, with separate images and containers:
-
Rootful: the system
docker.service, for members of thedockergroup. It is the CLI'sdefaultcontext and has the NVIDIA runtime (--gpus all). -
Rootless: a daemon per user, without root privileges. Set it up once (add
--forceif you are in thedockergroup):dockerd-rootless-setuptool.sh install
This starts it as a systemd user service and switches the CLI to its
rootlesscontext. Switch back withdocker context use default. To keep it running after logout, runsudo loginctl enable-linger "$USER".
The ISO is a network installer preset to pull the matching image from Docker Hub, so the install needs a network connection; disk, user and locale are chosen in the installer as usual, with plain xfs partitions as the default.
Or switch an existing bootc system:
sudo bootc switch docker.io/ericcurtin044/agenticlinux:kdeThe root filesystem (which holds /var, /home and /root) defaults to xfs
for both bootc install and the ISO.
The images are not signed: pulling one, from the ISO or bootc switch, relies
on Docker Hub over HTTPS.
The whole OS is one image, rebuilt every Monday and on every push to main;
the variant's tag (kde) is the newest. /etc and /var (so your home
directory) carry over between images.
bootc status # running, staged and rollback images
sudo bootc upgrade # fetch the newest image, boot into it next time
sudo bootc upgrade --apply # the same, and reboot now
sudo bootc rollback # boot the previous image next time; again to undo/var is shared by both images, so a rollback does not undo changes to your
data.
Every build is also tagged <variant>-<version>, the name of a
release. Switch to one
to pin it, and back to the variant's tag to follow the newest:
sudo bootc switch docker.io/ericcurtin044/agenticlinux:kde-44.YYYYMMDD.NNothing updates on its own by default. bootc's timer checks an hour after boot and about every eight hours after that, and reboots as soon as it finds a new image:
sudo systemctl enable --now bootc-fetch-apply-updates.timer- Vulkan: Mesa drivers and
vulkaninfo. - ROCm (x86_64): HIP runtime, OpenCL, rocBLAS, hipBLAS, hipBLASLt, RCCL,
rocminfo,rocm-smi. Containers get GPU access with--device /dev/kfd --device /dev/dri. - ROCm on CentOS Stream is EPEL's build: HIP, rocBLAS, hipBLAS, hipBLASLt,
RCCL,
rocminfo,rocm-smi; EPEL has no ROCm OpenCL. - NVIDIA: the RPM Fusion driver with the kernel module prebuilt for the
image's kernel, CUDA driver libraries and
nvidia-container-toolkitregistered with Docker (docker run --gpus all ...). The module is unsigned, so disable Secure Boot or enroll your own MOK. nouveau is blacklisted via kernel arguments. On CentOS Stream the driver is RPM Fusion's EL10 build, the 580 series. On aarch64 the driver is best effort: when RPM Fusion's aarch64 build is broken the image is published without it (and with nouveau), see build.sh.
packages.txt lists the RPMs, build.sh does the
rest, and usr/ is copied over the image. Each variant's base image is at the
top of the Dockerfile; VARIANT must match its distribution. The
published image is the chunked target, an OCI layout that Docker only loads
with the containerd image store. Enable it in /etc/docker/daemon.json:
{"features": {"containerd-snapshotter": true}}Then:
docker build --target chunked \
--build-arg BASE=quay.io/fedora-ostree-desktops/kinoite:44 --build-arg VARIANT=kde \
-o type=tar,dest=image.tar .
docker load -i image.tar # loads it as agenticlinux:kdeThe smoke test runs in a container of the image; it pulls a small local model and runs each agent on it, so it takes a while:
docker build -f test/Dockerfile --build-arg IMAGE=agenticlinux:kde -t agenticlinux:smoke .
docker run --rm agenticlinux:smoke smoke-vmCI also boots each x86_64 image in qemu with test/smoke.sh,
which covers what needs a real boot: Docker (rootful and rootless) and podman.
build.yml publishes only if every variant passes
on both architectures. A fork needs the DOCKER_HUB_USER variable, the
DOCKER_HUB_PAT secret, and an assets release with the logo files, which
build.sh downloads from REPO_URL.
