⚙️ Arch Install Generator

The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.

Prefer it explained one step at a time? Try the *nix Install Walkthrough — same result, recommended on mobile.

Arch Generator Settings

🔴 CRITICAL: Run lsblk to find your drive size and verify the correct device path!
VMware/VirtualBox: Most likely /dev/sda
Baremetal: Double check size to ensure you format the right existing drive and encounter no errors!
The keymap is not cosmetic: it is the layout in use at the boot passphrase prompt, before any desktop starts. Pick the wrong one and your LUKS passphrase will not type the way you expect.
🔴 Leaving this on No wipes the entire disk, including any other operating system on it.

Built up in layers, bottom to top. The defaults are the recommended setup — you can leave every one of these alone.

1 Container LUKS2 recommended
2 Cipher AES is hardware-accelerated
3 Post-quantum overlay optional, experimental
Layer 4: LUKS Duress Password

Registers a second passphrase on the LUKS header. Entering it at the boot prompt triggers the response below instead of unlocking normally. Your real passphrase is unaffected.

Each PIN you tick is prompted for separately when you run the script, and stored as its own Argon2id hash. They may share a password or use different ones — but if two share one, scarecrow takes the most destructive interpretation, because under coercion is the wrong moment to resolve an ambiguity in favour of doing less. The script warns you if it detects a shared password.

Post-Install Apps:

⚠️ Proprietary / non-libre software: anything marked [!] contains closed-source code or conflicts with strict libre principles — Firefox firmware blobs, the Signal Electron build, Chromium, Flatpak's default remote. They still install normally; this is just so you know what you are getting. What counts as non-libre →

🌐 Browsers
🔒 Security
💻 Dev / Terminal
🎬 Media / Files
🔧 System
🌙 Theming & Boot

⚠️ Libre users: Firefox firmware blobs, Flatpak proprietary apps, Signal Electron build, and Chromium may conflict with strict libre principles. See Wiki for details.

The payload is always captured to /var/log/anti-ducky/ with a SHA-256 for chain of custody, and the device is always deauthorized. A lock screen does not protect the LUKS key in RAM — pair it with LUKS auto-lock if that is what you need. Power-off loses unsaved work on a false positive, and these timing thresholds have never been measured on real hardware.

Emits DNS=<address>#<hostname>, which pins the certificate name. DNSOverTLS=yes on its own encrypts the query but does not authenticate the server — anyone able to answer on port 853 is then trusted, and on a hostile network that is the network. FallbackDNS= is left empty deliberately: systemd's built-in fallbacks belong to other providers.

🦀 tilas01's Security Suite (Rust)

Names are checked on the machine at install time, where the real package database is — a name this browser cannot find may still be perfectly valid. The script warns and skips rather than aborting, and prints the links that would 404 so you can check for yourself.

🛡️ Other Security Tools

Nothing is uploaded — generation happens entirely in your browser. Review the output before running any of it.