[
{
"t": "Arch Command Cheatsheet",
"u": "docs/helpful-commands.md",
"s": "Docs",
"d": "> ⚠️ AI-Assisted Reference. Always verify commands with the [Official Arch Wiki](https://wiki.archlinux.org)."
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/01-pre-installation.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/03-base-installation.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/07-post-installation.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/maintenance.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/02-partitioning/luks1.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/02-partitioning/luks2.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/02-partitioning/lvm-on-luks2.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/02-partitioning/unencrypted.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/04-bootloaders/grub.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/04-bootloaders/systemd-boot.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/04-bootloaders/uki-no-grub.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/05-secure-boot/custom-keys-uki.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/05-secure-boot/shim-grub.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/06-dual-boot/grub-os-prober.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Guides: Accessible & Modular",
"u": "docs/06-dual-boot/systemd-boot-windows.md",
"s": "Docs",
"d": "**The ultimate, dynamically customizable, and highly secure guide to installing Arch Linux.**"
},
{
"t": "Arch Linux Command Cheatsheet",
"u": "docs/cheatsheets/arch-commands.md",
"s": "Docs",
"d": "> [!TIP]"
},
{
"t": "Arch Linux Display Servers: Xorg vs Wayland",
"u": "docs/xorg-vs-wayland.md",
"s": "Docs",
"d": "When configuring your Arch Linux graphical interface, you must choose a display server protocol. The display server is responsible for coordinating input and output between your OS"
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/01-recommended-desktop.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/02-dual-boot-windows.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/03-dual-boot-linux.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/04-unencrypted-ext4.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/05-luks1-legacy-bios.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/06-headless-server.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/07-libre-only.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/08-duskyos.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/09-arm-raspberry-pi.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/10-arm-uboot-sbc.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/11-arm-uefi.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Arch Linux — your manual install guide",
"u": "docs/examples/12-maximum-hardening.md",
"s": "Docs",
"d": "Generated by the [Arch Guides manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)."
},
{
"t": "Building the Security Tools from Source",
"u": "docs/building-from-source.md",
"s": "Docs",
"d": "Building it yourself is the only way to know what you are running. This is also"
},
{
"t": "Dusky / Hyprland Cheatsheet",
"u": "docs/cheatsheets/duskyos-hyprland.md",
"s": "Docs",
"d": "Dusky is built around the Hyprland Wayland compositor. It uses a heavily customized, keyboard-centric workflow."
},
{
"t": "Generated examples",
"u": "docs/examples/README.md",
"s": "Docs",
"d": "These are real output from the [manual walkthrough](https://tilas01.github.io/arch-guides-dynamic/manual.html)"
},
{
"t": "Generator Selections Guide",
"u": "docs/10-generator-selections-and-dusky.md",
"s": "Docs",
"d": "This section explains every dropdown selection in the Auto Script Generator so you can understand what they do and manually apply them if you prefer."
},
{
"t": "Network Security for the Security Tools",
"u": "docs/network-hardening.md",
"s": "Docs",
"d": "How the tools in this project talk to the network, and why. This covers the"
},
{
"t": "OS Shortcut & Command cheatsheet for dusky 2026 os release",
"u": "docs/dusky-cheatsheet.md",
"s": "Docs",
"d": "[Dusky by dusklinux](https://github.com/dusklinux/dusky) is a fully riced, incredibly fast Arch Linux setup."
},
{
"t": "Security Audit — the Rust Tools",
"u": "docs/security-audit.md",
"s": "Docs",
"d": "A source review of the five crates under `security-tools/`. Static review only:"
},
{
"t": "🏛️ Architecture & Generation Logic",
"u": "docs/architecture.md",
"s": "Docs",
"d": "The `arch-guides-dynamic` deployment framework relies on a fully client-side, zero-backend architecture to generate highly secure and precisely customized Arch Linux deployment env"
},
{
"t": "Applications",
"u": "docs/helpful-commands.md#applications",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "Building DWM",
"u": "docs/helpful-commands.md#building-dwm",
"s": "Docs · Arch Command Cheatsheet",
"d": "git clone https://git.suckless.org/dwm /usr/local/src/dwm"
},
{
"t": "Essential Keybindings (Default)",
"u": "docs/helpful-commands.md#essential-keybindings-default",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "GNOME Tweaks",
"u": "docs/helpful-commands.md#gnome-tweaks",
"s": "Docs · Arch Command Cheatsheet",
"d": "gnome-tweaks           # Open GUI tweaks tool"
},
{
"t": "System Info",
"u": "docs/helpful-commands.md#system-info",
"s": "Docs · Arch Command Cheatsheet",
"d": "neofetch / pfetch         # System info"
},
{
"t": "Table of Contents",
"u": "docs/helpful-commands.md#table-of-contents",
"s": "Docs · Arch Command Cheatsheet",
"d": "1. [Pacman Package Manager](#-pacman-package-manager)"
},
{
"t": "Theming / Customization",
"u": "docs/helpful-commands.md#theming-customization",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "Window Management",
"u": "docs/helpful-commands.md#window-management",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "doas / sudo equivalents",
"u": "docs/helpful-commands.md#doas-sudo-equivalents",
"s": "Docs · Arch Command Cheatsheet",
"d": "- If using **Libre (doas)**: replace `sudo pacman` with `doas pacman`"
},
{
"t": "🌀 GNOME Keyboard Shortcuts",
"u": "docs/helpful-commands.md#gnome-keyboard-shortcuts",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "🎨 Dusky Shortcuts & Commands",
"u": "docs/helpful-commands.md#duskyos-shortcuts-commands",
"s": "Docs · Arch Command Cheatsheet",
"d": "> [Dusky by dusklinux](https://github.com/dusklinux/dusky) | [YouTube Demo](https://www.youtube.com/watch?v=JmgvSdEIK8c)"
},
{
"t": "💾 Disk & Filesystem",
"u": "docs/helpful-commands.md#disk-filesystem",
"s": "Docs · Arch Command Cheatsheet",
"d": "lsblk                            # List all block devices"
},
{
"t": "📦 Pacman Package Manager",
"u": "docs/helpful-commands.md#pacman-package-manager",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "📱 Helpful Post-Install Apps Reference",
"u": "docs/helpful-commands.md#helpful-post-install-apps-reference",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "🔒 Security Auditing",
"u": "docs/helpful-commands.md#security-auditing",
"s": "Docs · Arch Command Cheatsheet",
"d": "bootctl status                                          # Check Secure Boot status"
},
{
"t": "🔧 AUR Helper (paru)",
"u": "docs/helpful-commands.md#aur-helper-paru",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "🔧 Systemd & Services",
"u": "docs/helpful-commands.md#systemd-services",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "🔵 KDE Plasma Shortcuts",
"u": "docs/helpful-commands.md#kde-plasma-shortcuts",
"s": "Docs · Arch Command Cheatsheet",
"d": ""
},
{
"t": "🛡️ Permissions & Users",
"u": "docs/helpful-commands.md#permissions-users",
"s": "Docs · Arch Command Cheatsheet",
"d": "useradd -m -G wheel -s /bin/bash <user>   # Add user with sudo/doas"
},
{
"t": "🪟 DWM Window Manager Cheatsheet",
"u": "docs/helpful-commands.md#dwm-window-manager-cheatsheet",
"s": "Docs · Arch Command Cheatsheet",
"d": "> [DWM by suckless.org](https://dwm.suckless.org/) — Built from source, configured via `config.h`"
},
{
"t": "1. Fake Kernels & Backup Kernels Strategy",
"u": "docs/maintenance.md#1-fake-kernels-backup-kernels-strategy",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "In a maximum-security (Fortress) setup, adversaries may attempt to physically replace your kernel or initramfs on the unencrypted `/efi` partition."
},
{
"t": "1. Format & Mount",
"u": "docs/02-partitioning/luks1.md#1-format-mount",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "cryptsetup luksFormat --type luks1 -c aes-xts-plain64 -s 512 -h sha512 /dev/sda2"
},
{
"t": "1. Install Base Packages & Kernel Choice",
"u": "docs/03-base-installation.md#1-install-base-packages-kernel-choice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "When installing Arch Linux, you must choose your kernel strategy. You can install multiple kernels simultaneously (e.g., one primary, one backup)."
},
{
"t": "1. Minimalist System Tools (`doas` & `pfetch`)",
"u": "docs/07-post-installation.md#1-minimalist-system-tools-doas-pfetch",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "To adhere to the minimalist philosophy, we use `doas` instead of `sudo`. If you included `opendoas` and `pfetch` during `pacstrap`, configure them now:"
},
{
"t": "1. Verify Boot Mode",
"u": "docs/01-pre-installation.md#1-verify-boot-mode",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Ensure you are in UEFI mode:"
},
{
"t": "2. Connect to the Internet",
"u": "docs/01-pre-installation.md#2-connect-to-the-internet",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Using `iwctl` for Wi-Fi:"
},
{
"t": "2. Desktop Environments",
"u": "docs/07-post-installation.md#2-desktop-environments",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "**GNOME:**"
},
{
"t": "2. Fast Wi-Fi & DNS",
"u": "docs/07-post-installation.md#2-fast-wi-fi-dns",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "pacman -S iwd systemd-resolvconf"
},
{
"t": "2. Generate fstab",
"u": "docs/03-base-installation.md#2-generate-fstab",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "genfstab -U /mnt >> /mnt/etc/fstab"
},
{
"t": "2. Pacman Hook Maintenance",
"u": "docs/maintenance.md#2-pacman-hook-maintenance",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Your system relies on `pacman` hooks to automatically resign kernels during system updates."
},
{
"t": "3. AUR Helper",
"u": "docs/07-post-installation.md#3-aur-helper",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "pacman -S git base-devel"
},
{
"t": "3. Chroot into System",
"u": "docs/03-base-installation.md#3-chroot-into-system",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "arch-chroot /mnt"
},
{
"t": "3. SSH Hardening (Keys & OTP)",
"u": "docs/maintenance.md#3-ssh-hardening-keys-otp",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Never leave default SSH configurations exposed."
},
{
"t": "3. Update the System Clock",
"u": "docs/01-pre-installation.md#3-update-the-system-clock",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "timedatectl set-ntp true"
},
{
"t": "4. Hardware & VM Specifics",
"u": "docs/maintenance.md#4-hardware-vm-specifics",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "* **Virtual Machines (VMs):** If running in VirtualBox/VMware, ensure `xf86-video-vmware` and `virtualbox-guest-utils` are installed for proper graphical acceleration and resizing."
},
{
"t": "4. Next Step",
"u": "docs/01-pre-installation.md#4-next-step",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Proceed to **[Step 2: Partitioning & Encryption](../README.md#step-2--partitioning--encryption)** and choose your path."
},
{
"t": "4. Next Steps & Maintenance",
"u": "docs/07-post-installation.md#4-next-steps-maintenance",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Congratulations! Your core setup is complete."
},
{
"t": "4. Time, Locale, Hostname",
"u": "docs/03-base-installation.md#4-time-locale-hostname",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "ln -sf /usr/share/zoneinfo/Region/City /etc/localtime"
},
{
"t": "5. Initramfs",
"u": "docs/03-base-installation.md#5-initramfs",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Edit `/etc/mkinitcpio.conf`:"
},
{
"t": "6. Root Password",
"u": "docs/03-base-installation.md#6-root-password",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "passwd"
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/01-pre-installation.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Ensure you are in UEFI mode:"
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/03-base-installation.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "When installing Arch Linux, you must choose your kernel strategy. You can install multiple kernels simultaneously (e.g., one primary, one backup)."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/07-post-installation.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "To adhere to the minimalist philosophy, we use `doas` instead of `sudo`. If you included `opendoas` and `pfetch` during `pacstrap`, configure them now:"
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/02-partitioning/luks2.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Uses AES-256-XTS which is highly resistant to Grover's algorithm (quantum brute forcing)."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/02-partitioning/lvm-on-luks2.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "LVM inside an encrypted container provides maximum flexibility for resizing and snapshots."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/02-partitioning/unencrypted.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "This is the standard, simple partitioning scheme."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/04-bootloaders/grub.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Classic, highly customizable."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/04-bootloaders/systemd-boot.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Minimal and built into systemd. Recommended for standard setups."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/04-bootloaders/uki-no-grub.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Unified Kernel Images package everything into a single `.efi` file."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/05-secure-boot/custom-keys-uki.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Provides the highest level of security by signing your own Unified Kernel Image."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/05-secure-boot/shim-grub.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "A standard approach compatible with Microsoft's Secure Boot keys."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/06-dual-boot/grub-os-prober.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "If using GRUB, you must use `os-prober` to detect Windows."
},
{
"t": "Arch Dynamic Installation Setup Guide",
"u": "docs/06-dual-boot/systemd-boot-windows.md#arch-dynamic-installation-setup-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "`systemd-boot` natively auto-detects Windows."
},
{
"t": "System Maintenance & Security Guide",
"u": "docs/maintenance.md#system-maintenance-security-guide",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "Maintaining a highly secure Arch Linux system requires consistent auditing and careful management of your boot chain."
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/01-pre-installation.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/03-base-installation.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/07-post-installation.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/maintenance.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/02-partitioning/luks1.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/02-partitioning/luks2.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/02-partitioning/lvm-on-luks2.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/02-partitioning/unencrypted.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/04-bootloaders/grub.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/04-bootloaders/systemd-boot.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/04-bootloaders/uki-no-grub.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/05-secure-boot/custom-keys-uki.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/05-secure-boot/shim-grub.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/06-dual-boot/grub-os-prober.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "⚖️ Legal Disclaimer & AI Notice",
"u": "docs/06-dual-boot/systemd-boot-windows.md#legal-disclaimer-ai-notice",
"s": "Docs · Arch Guides: Accessible & Modular",
"d": "> *⚠️ AI-Generated Content & Security Warning: Approximately 95% of the content in this repository has been generated, refactored, and formatted by AI, with manual curation by tila"
},
{
"t": "BTRFS Snapshots (snapper)",
"u": "docs/cheatsheets/arch-commands.md#btrfs-snapshots-snapper",
"s": "Docs · Arch Linux Command Cheatsheet",
"d": "> [!NOTE]"
},
{
"t": "Package Management (AUR / paru)",
"u": "docs/cheatsheets/arch-commands.md#package-management-aur-paru",
"s": "Docs · Arch Linux Command Cheatsheet",
"d": "> [!WARNING]"
},
{
"t": "Package Management (pacman)",
"u": "docs/cheatsheets/arch-commands.md#package-management-pacman",
"s": "Docs · Arch Linux Command Cheatsheet",
"d": "- **Update System**: `sudo pacman -Syu`"
},
{
"t": "Security Suite Tools",
"u": "docs/cheatsheets/arch-commands.md#security-suite-tools",
"s": "Docs · Arch Linux Command Cheatsheet",
"d": "- **Verify ISO**: `arch-iso-verifier`"
},
{
"t": "System Services (systemd)",
"u": "docs/cheatsheets/arch-commands.md#system-services-systemd",
"s": "Docs · Arch Linux Command Cheatsheet",
"d": "- **Start Service**: `sudo systemctl start service_name`"
},
{
"t": "Wayland (Modern & Secure)",
"u": "docs/xorg-vs-wayland.md#wayland-modern-secure",
"s": "Docs · Arch Linux Display Servers: Xorg vs Wayland",
"d": "Wayland is the modern, secure replacement for X11. It is simpler, has better code maintainability, and provides much better security isolation between applications."
},
{
"t": "Xorg / X11 (Legacy & Compatible)",
"u": "docs/xorg-vs-wayland.md#xorg-x11-legacy-compatible",
"s": "Docs · Arch Linux Display Servers: Xorg vs Wayland",
"d": "Xorg is the legacy display server that has been used for decades."
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/01-recommended-desktop.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/02-dual-boot-windows.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/03-dual-boot-linux.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/04-unencrypted-ext4.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/05-luks1-legacy-bios.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/06-headless-server.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/07-libre-only.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/08-duskyos.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/09-arm-raspberry-pi.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/10-arm-uboot-sbc.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/11-arm-uefi.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "0. Before you boot the installer",
"u": "docs/examples/12-maximum-hardening.md#0-before-you-boot-the-installer",
"s": "Docs · Arch Linux — your manual install guide",
"d": "1. **Verify the image.** Hash it, and get the checksum from a host other"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/01-recommended-desktop.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/02-dual-boot-windows.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/03-dual-boot-linux.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/04-unencrypted-ext4.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/05-luks1-legacy-bios.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/06-headless-server.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/07-libre-only.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/08-duskyos.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/09-arm-raspberry-pi.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "iwctl station wlan0 connect YOUR_SSID"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/10-arm-uboot-sbc.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "iwctl station wlan0 connect YOUR_SSID"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/11-arm-uefi.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "iwctl station wlan0 connect YOUR_SSID"
},
{
"t": "1. Boot the installer and get a network",
"u": "docs/examples/12-maximum-hardening.md#1-boot-the-installer-and-get-a-network",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ls /sys/firmware/efi && echo UEFI   # confirms firmware mode"
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/01-recommended-desktop.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/02-dual-boot-windows.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/03-dual-boot-linux.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/04-unencrypted-ext4.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/05-luks1-legacy-bios.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/06-headless-server.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/07-libre-only.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/08-duskyos.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/09-arm-raspberry-pi.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/10-arm-uboot-sbc.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/11-arm-uefi.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "2. Partition `/dev/nvme0n1`",
"u": "docs/examples/12-maximum-hardening.md#2-partition-devnvme0n1",
"s": "Docs · Arch Linux — your manual install guide",
"d": "lsblk                       # identify the disk by size and model. Twice."
},
{
"t": "3. Install the base system",
"u": "docs/examples/01-recommended-desktop.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/02-dual-boot-windows.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/03-dual-boot-linux.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/04-unencrypted-ext4.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/05-luks1-legacy-bios.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/06-headless-server.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/07-libre-only.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/08-duskyos.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/09-arm-raspberry-pi.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/10-arm-uboot-sbc.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/11-arm-uefi.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "3. Install the base system",
"u": "docs/examples/12-maximum-hardening.md#3-install-the-base-system",
"s": "Docs · Arch Linux — your manual install guide",
"d": "pacstrap -K /mnt \\"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/01-recommended-desktop.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/02-dual-boot-windows.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/03-dual-boot-linux.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/04-unencrypted-ext4.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/05-luks1-legacy-bios.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/06-headless-server.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/07-libre-only.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/08-duskyos.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/09-arm-raspberry-pi.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/10-arm-uboot-sbc.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/11-arm-uefi.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "4. Configure, inside the chroot",
"u": "docs/examples/12-maximum-hardening.md#4-configure-inside-the-chroot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "ln -sf /usr/share/zoneinfo/Europe/London /etc/localtime"
},
{
"t": "5. Bootloader",
"u": "docs/examples/01-recommended-desktop.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "5. Bootloader",
"u": "docs/examples/02-dual-boot-windows.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "5. Bootloader",
"u": "docs/examples/03-dual-boot-linux.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "5. Bootloader",
"u": "docs/examples/04-unencrypted-ext4.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "bootctl install"
},
{
"t": "5. Bootloader",
"u": "docs/examples/05-luks1-legacy-bios.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "grub-install --target=x86_64-efi --efi-directory=/boot --bootloader-id=Arch"
},
{
"t": "5. Bootloader",
"u": "docs/examples/06-headless-server.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "5. Bootloader",
"u": "docs/examples/07-libre-only.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "5. Bootloader",
"u": "docs/examples/08-duskyos.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "5. Bootloader",
"u": "docs/examples/09-arm-raspberry-pi.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "The Raspberry Pi EEPROM bootloader reads `config.txt` and"
},
{
"t": "5. Bootloader",
"u": "docs/examples/10-arm-uboot-sbc.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkdir -p /boot/extlinux"
},
{
"t": "5. Bootloader",
"u": "docs/examples/11-arm-uefi.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "bootctl install"
},
{
"t": "5. Bootloader",
"u": "docs/examples/12-maximum-hardening.md#5-bootloader",
"s": "Docs · Arch Linux — your manual install guide",
"d": "UUID=$(blkid -s UUID -o value /dev/nvme0n1p2)"
},
{
"t": "6. Services",
"u": "docs/examples/01-recommended-desktop.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/02-dual-boot-windows.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/03-dual-boot-linux.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/04-unencrypted-ext4.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/05-luks1-legacy-bios.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/06-headless-server.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/07-libre-only.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/08-duskyos.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/09-arm-raspberry-pi.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/10-arm-uboot-sbc.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/11-arm-uefi.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "6. Services",
"u": "docs/examples/12-maximum-hardening.md#6-services",
"s": "Docs · Arch Linux — your manual install guide",
"d": "systemctl enable NetworkManager"
},
{
"t": "7. Reboot",
"u": "docs/examples/01-recommended-desktop.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/02-dual-boot-windows.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/03-dual-boot-linux.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/04-unencrypted-ext4.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/05-luks1-legacy-bios.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/06-headless-server.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/07-libre-only.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/08-duskyos.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/09-arm-raspberry-pi.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/10-arm-uboot-sbc.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/11-arm-uefi.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "7. Reboot",
"u": "docs/examples/12-maximum-hardening.md#7-reboot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "exit"
},
{
"t": "8. After the first boot",
"u": "docs/examples/01-recommended-desktop.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/02-dual-boot-windows.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/03-dual-boot-linux.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/04-unencrypted-ext4.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/05-luks1-legacy-bios.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/06-headless-server.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/07-libre-only.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/08-duskyos.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/09-arm-raspberry-pi.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/10-arm-uboot-sbc.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/11-arm-uefi.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "8. After the first boot",
"u": "docs/examples/12-maximum-hardening.md#8-after-the-first-boot",
"s": "Docs · Arch Linux — your manual install guide",
"d": "Do this from the installed system, logged in as `you`."
},
{
"t": "BusKill",
"u": "docs/examples/12-maximum-hardening.md#buskill",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cat | sudo tee /etc/udev/rules.d/99-buskill.rules <<'EOF'"
},
{
"t": "Configure what you installed",
"u": "docs/examples/01-recommended-desktop.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/02-dual-boot-windows.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/03-dual-boot-linux.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/04-unencrypted-ext4.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/05-luks1-legacy-bios.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/06-headless-server.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/07-libre-only.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/08-duskyos.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/09-arm-raspberry-pi.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/10-arm-uboot-sbc.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/11-arm-uefi.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Configure what you installed",
"u": "docs/examples/12-maximum-hardening.md#configure-what-you-installed",
"s": "Docs · Arch Linux — your manual install guide",
"d": "These need a decision from you, so they are asked rather than guessed."
},
{
"t": "Encrypt",
"u": "docs/examples/01-recommended-desktop.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/02-dual-boot-windows.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/03-dual-boot-linux.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/05-luks1-legacy-bios.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks1 /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/06-headless-server.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/07-libre-only.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/08-duskyos.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/09-arm-raspberry-pi.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/10-arm-uboot-sbc.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/11-arm-uefi.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Encrypt",
"u": "docs/examples/12-maximum-hardening.md#encrypt",
"s": "Docs · Arch Linux — your manual install guide",
"d": "cryptsetup luksFormat --type luks2 --pbkdf argon2id /dev/nvme0n1p2"
},
{
"t": "Firewall",
"u": "docs/examples/01-recommended-desktop.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/02-dual-boot-windows.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/03-dual-boot-linux.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/04-unencrypted-ext4.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/05-luks1-legacy-bios.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/07-libre-only.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/08-duskyos.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/09-arm-raspberry-pi.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/10-arm-uboot-sbc.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/11-arm-uefi.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Firewall",
"u": "docs/examples/12-maximum-hardening.md#firewall",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo ufw default deny incoming"
},
{
"t": "Format and mount",
"u": "docs/examples/01-recommended-desktop.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/02-dual-boot-windows.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.btrfs -f /dev/mapper/cryptroot"
},
{
"t": "Format and mount",
"u": "docs/examples/03-dual-boot-linux.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.btrfs -f /dev/mapper/cryptroot"
},
{
"t": "Format and mount",
"u": "docs/examples/04-unencrypted-ext4.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/05-luks1-legacy-bios.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/06-headless-server.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/07-libre-only.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/08-duskyos.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/09-arm-raspberry-pi.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/10-arm-uboot-sbc.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/11-arm-uefi.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Format and mount",
"u": "docs/examples/12-maximum-hardening.md#format-and-mount",
"s": "Docs · Arch Linux — your manual install guide",
"d": "mkfs.fat -F32 /dev/nvme0n1p1"
},
{
"t": "Security tools",
"u": "docs/examples/12-maximum-hardening.md#security-tools",
"s": "Docs · Arch Linux — your manual install guide",
"d": "curl -fsSL https://raw.githubusercontent.com/tilas01/arch-guides-dynamic/main/scripts/install-security-suite.sh -o install.sh"
},
{
"t": "Snapshots",
"u": "docs/examples/01-recommended-desktop.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/02-dual-boot-windows.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/03-dual-boot-linux.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/05-luks1-legacy-bios.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/06-headless-server.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/07-libre-only.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/08-duskyos.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/09-arm-raspberry-pi.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/10-arm-uboot-sbc.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/11-arm-uefi.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Snapshots",
"u": "docs/examples/12-maximum-hardening.md#snapshots",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sudo umount /.snapshots && sudo rm -rf /.snapshots"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/01-recommended-desktop.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/02-dual-boot-windows.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/03-dual-boot-linux.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/05-luks1-legacy-bios.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/06-headless-server.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/07-libre-only.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/08-duskyos.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/09-arm-raspberry-pi.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/10-arm-uboot-sbc.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/11-arm-uefi.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Tell the initramfs about the encryption",
"u": "docs/examples/12-maximum-hardening.md#tell-the-initramfs-about-the-encryption",
"s": "Docs · Arch Linux — your manual install guide",
"d": "vim /etc/mkinitcpio.conf"
},
{
"t": "Where to go from here",
"u": "docs/examples/01-recommended-desktop.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/02-dual-boot-windows.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/03-dual-boot-linux.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/04-unencrypted-ext4.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/05-luks1-legacy-bios.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/06-headless-server.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/07-libre-only.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/08-duskyos.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/09-arm-raspberry-pi.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/10-arm-uboot-sbc.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/11-arm-uefi.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Where to go from here",
"u": "docs/examples/12-maximum-hardening.md#where-to-go-from-here",
"s": "Docs · Arch Linux — your manual install guide",
"d": "- [The wiki](https://tilas01.github.io/arch-guides-dynamic/wiki.html) — every option above, explained in full"
},
{
"t": "Your choices",
"u": "docs/examples/01-recommended-desktop.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/02-dual-boot-windows.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/03-dual-boot-linux.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/04-unencrypted-ext4.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/05-luks1-legacy-bios.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/06-headless-server.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/07-libre-only.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/08-duskyos.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/09-arm-raspberry-pi.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/10-arm-uboot-sbc.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/11-arm-uefi.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your choices",
"u": "docs/examples/12-maximum-hardening.md#your-choices",
"s": "Docs · Arch Linux — your manual install guide",
"d": ""
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/01-recommended-desktop.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/02-dual-boot-windows.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/03-dual-boot-linux.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/06-headless-server.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/07-libre-only.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/08-duskyos.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Your own Secure Boot keys",
"u": "docs/examples/12-maximum-hardening.md#your-own-secure-boot-keys",
"s": "Docs · Arch Linux — your manual install guide",
"d": "sbctl status                 # firmware must be in Setup Mode"
},
{
"t": "Cross-platform",
"u": "docs/building-from-source.md#cross-platform",
"s": "Docs · Building the Security Tools from Source",
"d": "These are Linux tools. `kernel-watcher` uses `nix::sys::signal` and"
},
{
"t": "Hardening flags",
"u": "docs/building-from-source.md#hardening-flags",
"s": "Docs · Building the Security Tools from Source",
"d": "`.cargo/config.toml` also applies:"
},
{
"t": "Installing what you built",
"u": "docs/building-from-source.md#installing-what-you-built",
"s": "Docs · Building the Security Tools from Source",
"d": "sudo install -Dm755 target/release/arch-security-suite /usr/local/bin/"
},
{
"t": "Optimisation, and one thing to avoid",
"u": "docs/building-from-source.md#optimisation-and-one-thing-to-avoid",
"s": "Docs · Building the Security Tools from Source",
"d": "The release profile already applies the settings that matter:"
},
{
"t": "Per-tool notes",
"u": "docs/building-from-source.md#per-tool-notes",
"s": "Docs · Building the Security Tools from Source",
"d": ""
},
{
"t": "Prerequisites",
"u": "docs/building-from-source.md#prerequisites",
"s": "Docs · Building the Security Tools from Source",
"d": "sudo pacman -S --needed rust base-devel pkg-config systemd-libs git"
},
{
"t": "Quick build",
"u": "docs/building-from-source.md#quick-build",
"s": "Docs · Building the Security Tools from Source",
"d": "Everything, as one binary:"
},
{
"t": "Reproducible build — verifying a published binary",
"u": "docs/building-from-source.md#reproducible-build-verifying-a-published-binary",
"s": "Docs · Building the Security Tools from Source",
"d": "Two builds of the same commit should produce byte-identical output. To check a"
},
{
"t": "Running the tests",
"u": "docs/building-from-source.md#running-the-tests",
"s": "Docs · Building the Security Tools from Source",
"d": "cd security-tools/<tool>"
},
{
"t": "What makes it reproducible",
"u": "docs/building-from-source.md#what-makes-it-reproducible",
"s": "Docs · Building the Security Tools from Source",
"d": ""
},
{
"t": "Advanced Dusky Commands",
"u": "docs/cheatsheets/duskyos-hyprland.md#advanced-dusky-commands",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "> [!NOTE]"
},
{
"t": "Application Launching",
"u": "docs/cheatsheets/duskyos-hyprland.md#application-launching",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "- **Terminal (Alacritty / Kitty)**: `SUPER + Enter`"
},
{
"t": "Essential Keybinds",
"u": "docs/cheatsheets/duskyos-hyprland.md#essential-keybinds",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "*Note: The primary modifier key (SUPER) is typically the Windows key.*"
},
{
"t": "System Commands",
"u": "docs/cheatsheets/duskyos-hyprland.md#system-commands",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "- **Lock Screen**: `SUPER + L`"
},
{
"t": "Troubleshooting",
"u": "docs/cheatsheets/duskyos-hyprland.md#troubleshooting",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "> [!WARNING]"
},
{
"t": "Window Management",
"u": "docs/cheatsheets/duskyos-hyprland.md#window-management",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "- **Close Focused Window**: `SUPER + Q` or `SUPER + Shift + Q`"
},
{
"t": "Workspaces",
"u": "docs/cheatsheets/duskyos-hyprland.md#workspaces",
"s": "Docs · Dusky / Hyprland Cheatsheet",
"d": "- **Switch Workspace**: `SUPER + [1-9]`"
},
{
"t": "The examples",
"u": "docs/examples/README.md#the-examples",
"s": "Docs · Generated examples",
"d": ""
},
{
"t": "What each one chose",
"u": "docs/examples/README.md#what-each-one-chose",
"s": "Docs · Generated examples",
"d": ""
},
{
"t": "Why twelve and not all of them",
"u": "docs/examples/README.md#why-twelve-and-not-all-of-them",
"s": "Docs · Generated examples",
"d": "The walkthrough has **578** distinct answer combinations across the axes that"
},
{
"t": "Arch ISO Setup Utilities",
"u": "docs/10-generator-selections-and-dusky.md#arch-iso-setup-utilities",
"s": "Docs · Generator Selections Guide",
"d": "- **None**: You are running the generator on your local machine and will type/paste commands into the Arch ISO."
},
{
"t": "Base System",
"u": "docs/10-generator-selections-and-dusky.md#base-system",
"s": "Docs · Generator Selections Guide",
"d": "- **Software Paradigm**: Choose strict adherence to free software using [doas](https://github.com/Duncaen/OpenDoas) (Libre ONLY), pragmatic usage with [sudo](https://www.sudo.ws/) "
},
{
"t": "Desktop Environments & Applications",
"u": "docs/10-generator-selections-and-dusky.md#desktop-environments-applications",
"s": "Docs · Generator Selections Guide",
"d": "- **Desktop Environment**: [GNOME](https://www.gnome.org/), [KDE Plasma](https://kde.org/plasma-desktop/), [DWM](https://dwm.suckless.org/), or **[Dusky](https://github.com/dusk"
},
{
"t": "Disks & Filesystems",
"u": "docs/10-generator-selections-and-dusky.md#disks-filesystems",
"s": "Docs · Generator Selections Guide",
"d": "- **Disk Partitioning**: Standard, LVM, or Encrypted (LUKS)."
},
{
"t": "Hardware & Drivers",
"u": "docs/10-generator-selections-and-dusky.md#hardware-drivers",
"s": "Docs · Generator Selections Guide",
"d": "- **CPU Brand**: Installs `amd-ucode` or `intel-ucode`."
},
{
"t": "Output Format",
"u": "docs/10-generator-selections-and-dusky.md#output-format",
"s": "Docs · Generator Selections Guide",
"d": "- **Bash Script**: Generates a raw executable `.sh` file."
},
{
"t": "Security & Network",
"u": "docs/10-generator-selections-and-dusky.md#security-network",
"s": "Docs · Generator Selections Guide",
"d": "- **DNS Caching Service**: `systemd-resolved` (default), [unbound](https://nlnetlabs.nl/projects/unbound/about/) (validating caching), [dnscrypt-proxy](https://dnscrypt.info/) (enc"
},
{
"t": "A correction worth stating up front",
"u": "docs/network-hardening.md#a-correction-worth-stating-up-front",
"s": "Docs · Network Security for the Security Tools",
"d": "The goal was described as \"post-quantum + AES + RSA-GCM on top\". Two parts of"
},
{
"t": "Certificate pinning",
"u": "docs/network-hardening.md#certificate-pinning",
"s": "Docs · Network Security for the Security Tools",
"d": "TLS on its own answers \"is this a valid certificate for this name?\" — any of the"
},
{
"t": "Checklist",
"u": "docs/network-hardening.md#checklist",
"s": "Docs · Network Security for the Security Tools",
"d": "- [ ] TLS 1.3 only; TLS 1.2 and below refused"
},
{
"t": "Post-quantum key exchange",
"u": "docs/network-hardening.md#post-quantum-key-exchange",
"s": "Docs · Network Security for the Security Tools",
"d": "Use the hybrid group `X25519MLKEM768`. Hybrid means the shared secret is derived"
},
{
"t": "The layers, and what each one defends against",
"u": "docs/network-hardening.md#the-layers-and-what-each-one-defends-against",
"s": "Docs · Network Security for the Security Tools",
"d": ""
},
{
"t": "Verifying downloads",
"u": "docs/network-hardening.md#verifying-downloads",
"s": "Docs · Network Security for the Security Tools",
"d": "Never trust the transport alone."
},
{
"t": "Webhook alerts",
"u": "docs/network-hardening.md#webhook-alerts",
"s": "Docs · Network Security for the Security Tools",
"d": "The tools can send alerts (ntfy, Discord, Slack). Points to get right:"
},
{
"t": "What this does *not* protect against",
"u": "docs/network-hardening.md#what-this-does-not-protect-against",
"s": "Docs · Network Security for the Security Tools",
"d": "Being honest about the boundary is part of the design:"
},
{
"t": "Essential Shortcuts",
"u": "docs/dusky-cheatsheet.md#essential-shortcuts",
"s": "Docs · OS Shortcut & Command cheatsheet for dusky 2026 os release",
"d": ""
},
{
"t": "Root Account & Usage",
"u": "docs/dusky-cheatsheet.md#root-account-usage",
"s": "Docs · OS Shortcut & Command cheatsheet for dusky 2026 os release",
"d": "With Dusky, it is recommended to run as your regular user and elevate privileges using `sudo` or `doas` when necessary. If you selected \"No\" for Root SSH Access in the generator"
},
{
"t": "Deliberately not \"fixed\"",
"u": "docs/security-audit.md#deliberately-not-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "**Plain `!=` when comparing the `/boot` hash.** Constant-time comparison is not"
},
{
"t": "HIGH — Baseline hash was not deterministic · **Fixed**",
"u": "docs/security-audit.md#high-baseline-hash-was-not-deterministic-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "`kernel-watcher::setup_evil_maid_hash()` / `check_evil_maid_hash()`"
},
{
"t": "HIGH — Integrity check failed open on a missing baseline · **Fixed**",
"u": "docs/security-audit.md#high-integrity-check-failed-open-on-a-missing-baseline-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "`kernel-watcher::check_evil_maid_hash()`"
},
{
"t": "LOW — Argon2 parameters were the bare minimum · **Fixed**",
"u": "docs/security-audit.md#low-argon2-parameters-were-the-bare-minimum-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "`Argon2::default()` is m=19 MiB, t=2, p=1 — the OWASP *floor*. For a password"
},
{
"t": "MEDIUM — Lockout destroyed the user's OTP secret · **Fixed**",
"u": "docs/security-audit.md#medium-lockout-destroyed-the-users-otp-secret-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "`anti-evil-maid::enforce_lockout()`"
},
{
"t": "MEDIUM — Master-password hash was world-readable · **Fixed**",
"u": "docs/security-audit.md#medium-master-password-hash-was-world-readable-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "`kernel-watcher::run_setup()` wrote the Argon2 hash with `fs::write`, which"
},
{
"t": "MEDIUM — Tools and installer disagreed on where state lives · **Fixed**",
"u": "docs/security-audit.md#medium-tools-and-installer-disagreed-on-where-state-lives-fixed",
"s": "Docs · Security Audit — the Rust Tools",
"d": "`kernel-watcher`, `anti-evil-maid`, `anti-ducky`, `scripts/install-security-suite.sh`"
},
{
"t": "Reviewed and found correct",
"u": "docs/security-audit.md#reviewed-and-found-correct",
"s": "Docs · Security Audit — the Rust Tools",
"d": "* **`libre-otp` secret storage.** Creates the file, chmods to `0600`, *then*"
},
{
"t": "Still outstanding",
"u": "docs/security-audit.md#still-outstanding",
"s": "Docs · Security Audit — the Rust Tools",
"d": "Honest about what this review did **not** cover:"
},
{
"t": "1. Firmware (UEFI vs BIOS)",
"u": "docs/architecture.md#1-firmware-uefi-vs-bios",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "- **UEFI:** Unlocks the ability to use **systemd-boot**, **Unified Kernel Images (UKI)**, and **Secure Boot** methodologies. It allows for the modern ESP (EFI System Partition) str"
},
{
"t": "2. Encryption (LUKS1 vs LUKS2 vs Unencrypted)",
"u": "docs/architecture.md#2-encryption-luks1-vs-luks2-vs-unencrypted",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "- **LUKS2:** The modern post-quantum secure standard. However, GRUB has extremely limited support for LUKS2 PBKDF2 formats and zero support for Argon2. If you select GRUB with LUKS"
},
{
"t": "3. Init Systems (systemd vs busybox)",
"u": "docs/architecture.md#3-init-systems-systemd-vs-busybox",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "- **systemd hook:** Faster boot times and deeper integration with systemd-boot and sd-encrypt. It handles LVM and LUKS mounting inherently via systemd targets."
},
{
"t": "4. Bootloaders & Secure Boot",
"u": "docs/architecture.md#4-bootloaders-secure-boot",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "- **Unified Kernel Image (UKI):** Bundles the kernel, initramfs, and cmdline into a single .efi executable. This entirely bypasses traditional bootloaders like GRUB, directly booti"
},
{
"t": "How Your Choices Affect The Installation",
"u": "docs/architecture.md#how-your-choices-affect-the-installation",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "Every choice you make in the interactive generator fundamentally shapes the required commands and compatibility for later steps. The dynamic generator handles these complexities, b"
},
{
"t": "How the Website Generator Works",
"u": "docs/architecture.md#how-the-website-generator-works",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "The Interactive Generator (`website/index.html` and `website/script.js`) works locally in your browser to build the installation pipeline. No server requests are made to parse your"
},
{
"t": "Native Rust Security Tools",
"u": "docs/architecture.md#native-rust-security-tools",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "Instead of relying on bloated, proprietary modules, this framework maintains its own suite of Rust-native security tools available during deployment:"
},
{
"t": "🦆 Anti-RubberDucky Daemon",
"u": "docs/architecture.md#anti-rubberducky-daemon",
"s": "Docs · 🏛️ Architecture & Generation Logic",
"d": "A daemon that interfaces directly with `/dev/input/eventX`. It profiles keystroke intervals using sub-millisecond precision (`THRESHOLD_MS=20`). If anomalous speeds are detected—sy"
},
{
"t": "Install Script (.sh)",
"u": "index.html#title-install-sh",
"s": "Generator",
"d": "Post-Install Script (.sh) ✅ Finalized Output <button type=\"button\" class=\"btn nav-tooltip\" data-title=\"Download All\" data-desc=\"Downloads a .zip containing the markdown guide, the…"
},
{
"t": "⚙️ App Configurer",
"u": "index.html#modal-title",
"s": "Generator",
"d": ""
},
{
"t": "⚙️ Install Script (.sh)",
"u": "index.html#static-title-install",
"s": "Generator",
"d": "Download 🚀 Post-Install Script (.sh) Download 🕰️ Generation History <button type=\"button\" aria-label=\"Close history\" onclick=\"closeHistoryModal()\" style=\"background:transparent; bo…"
},
{
"t": "✅ Finalized Output",
"u": "index.html#output-section",
"s": "Generator",
"d": "Step 1: On the target Arch machine (Live ISO), start the SSH service and set a temporary root password:"
},
{
"t": "📝 Live Editor (Staging)",
"u": "index.html#live-editor",
"s": "Generator",
"d": "Raw Edit Syntax Preview Split Install / Post-Install ✅ Confirm & Save Markdown Guide (.md) <pre id=\"live"
},
{
"t": "Audio",
"u": "wiki.html#desktop",
"s": "Manual walkthrough",
"d": "PipeWire replaced PulseAudio and JACK and is what Arch ships now.  Choose none for a server."
},
{
"t": "BusKill dead-man switch?",
"u": "wiki.html#usb-kill",
"s": "Manual walkthrough",
"d": "BusKill is a magnetic USB cable. Pull the laptop away — or have  it pulled away — and the magnet separates, the USB device  disappears, and udev fires a rule. It turns physical separation  from the ma"
},
{
"t": "CPU microcode",
"u": "wiki.html#cpu_brand",
"s": "Manual walkthrough",
"d": "Microcode updates fix CPU errata, including the ones behind  speculative-execution vulnerabilities. Loaded early by the  initramfs. There is no equivalent on ARM — firmware comes from the  board vendo"
},
{
"t": "Colour palette",
"u": "wiki.html#desktop",
"s": "Manual walkthrough",
"d": "Applied to the terminal, the editor and the shell prompt so they  agree with each other. All of these are dark schemes designed for  long sessions."
},
{
"t": "Console keymap",
"u": "wiki.html#manual-install",
"s": "Manual walkthrough",
"d": "The console layout, used before any desktop starts. Get this  wrong and your disk passphrase will not type the way you expect  at the boot prompt."
},
{
"t": "Desktop environment",
"u": "wiki.html#desktop",
"s": "Manual walkthrough",
"d": "Nothing here is required to have a working system. Get the base  system booting first — debugging a desktop is much easier from  something you know boots."
},
{
"t": "Display server",
"u": "wiki.html#display_server",
"s": "Manual walkthrough",
"d": "Wayland isolates clients from each other, so one window cannot  read another's keystrokes or screen. Xorg cannot make that  guarantee, but some older applications and some accessibility  tools still n"
},
{
"t": "Encrypt the disk?",
"u": "wiki.html#partitioning",
"s": "Manual walkthrough",
"d": "Full-disk encryption is what makes a stolen laptop a stolen laptop  rather than a data breach. It costs you a passphrase at every boot  and nothing else. LUKS2 with Argon2id is the current default and"
},
{
"t": "Enforce a strictly libre software policy?",
"u": "wiki.html#libre-policy",
"s": "Manual walkthrough",
"d": "On, the guide refuses anything with proprietary or closed-source  components: no microcode, no proprietary graphics drivers, no  Discord, no Steam. Off, you get microcode and the drivers your  hardwar"
},
{
"t": "Firewall",
"u": "wiki.html#firewall-profiles",
"s": "Manual walkthrough",
"d": "A default-deny inbound policy closes everything you did not  deliberately open. Two commands, and it is the highest  security-per-effort item in this whole guide."
},
{
"t": "Firmware mode",
"u": "wiki.html#firmware",
"s": "Manual walkthrough",
"d": "Check with \"ls /sys/firmware/efi\" from the live environment — if  that directory exists you booted UEFI. Legacy BIOS restricts you  to GRUB and LUKS1 and rules out Secure Boot entirely."
},
{
"t": "Hostname",
"u": "wiki.html#manual-install",
"s": "Manual walkthrough",
"d": "The machine's name on your network. Letters, digits and hyphens."
},
{
"t": "How does this board boot?",
"u": "wiki.html#arch-arm",
"s": "Manual walkthrough",
"d": "ARM boards do not agree on a boot mechanism. This decides whether  the guide writes an EFI loader entry, an extlinux.conf, or the  Raspberry Pi config.txt and cmdline.txt."
},
{
"t": "How much should the generated script say?",
"u": "wiki.html#advanced-config-verbosity",
"s": "Manual walkthrough",
"d": "Debug injects \"set -x\", so bash prints every command with its  arguments before running it. That is what you want the first time  something fails."
},
{
"t": "Is anything else staying on this machine?",
"u": "wiki.html#dual-boot",
"s": "Manual walkthrough",
"d": "Dual booting is the most common way people lose data during an  Arch install. What you pick here changes the partitioning, whether  the EFI system partition is created or reused, and which warnings  t"
},
{
"t": "Locale",
"u": "wiki.html#manual-install",
"s": "Manual walkthrough",
"d": "Sets language, date format, sort order and currency. UTF-8  variants only — anything else will bite you the first time a  filename has an accent in it."
},
{
"t": "Login shell",
"u": "wiki.html#desktop",
"s": "Manual walkthrough",
"d": "bash is what every guide on the internet assumes. zsh with a  prompt framework is the common upgrade. fish is friendlier out of  the box but is not POSIX, so pasted shell snippets can fail."
},
{
"t": "Monospace font",
"u": "wiki.html#desktop",
"s": "Manual walkthrough",
"d": "The font your terminal and editor use. Nerd Font variants include  the glyphs that status bars and shell prompts expect; without  them you get boxes."
},
{
"t": "Network management",
"u": "wiki.html#firewall",
"s": "Manual walkthrough",
"d": "Pick exactly one. Two network managers fighting over the same  interface is a classic way to end up with no network at all."
},
{
"t": "Post-install software",
"u": "wiki.html#advanced-config",
"s": "Manual walkthrough",
"d": "Installed and configured after the first boot, not during the  base install. Anything needing a decision from you is asked at  that point rather than guessed."
},
{
"t": "Secure Boot",
"u": "wiki.html#bootloader",
"s": "Manual walkthrough",
"d": "Secure Boot stops the firmware executing an unsigned bootloader.  Enrolling your own keys means you decide what may boot, rather  than a third-party certificate authority. Turning it off for Arch  als"
},
{
"t": "Snapshots",
"u": "wiki.html#filesystem",
"s": "Manual walkthrough",
"d": "A snapshot taken automatically before every pacman transaction  turns a broken update into a reboot. Only useful on Btrfs."
},
{
"t": "Swap?",
"u": "wiki.html#swap_size",
"s": "Manual walkthrough",
"d": "zram compresses swap in RAM and is the sensible default on almost  any modern machine. A swap file or partition is only needed if you  want hibernation, which needs swap at least as large as RAM."
},
{
"t": "Time zone",
"u": "wiki.html#manual-install",
"s": "Manual walkthrough",
"d": "An IANA zone name. \"timedatectl list-timezones\" lists them all.  The clock is kept in UTC; if you dual boot Windows the guide adds  the step that stops the two disagreeing."
},
{
"t": "Where is the existing EFI system partition?",
"u": "wiki.html#dual-boot-esp",
"s": "Manual walkthrough",
"d": "Run \"lsblk -f\" on the running system. The ESP is the small FAT32  partition, usually 100-500 MiB, with partition type EF00. This  partition is mounted, never formatted — formatting it deletes the  oth"
},
{
"t": "Which ARM board?",
"u": "wiki.html#arch-arm",
"s": "Manual walkthrough",
"d": "ARM boards do not share a boot path the way PCs do. The board  decides whether you get UEFI, U-Boot, or vendor firmware in an  EEPROM, and which device tree the kernel needs."
},
{
"t": "Which CPU architecture are you installing on?",
"u": "wiki.html#architecture",
"s": "Manual walkthrough",
"d": "Everything downstream depends on this. x86_64 is any Intel or AMD  desktop or laptop. aarch64 is 64-bit ARM: Raspberry Pi, Pine64,  most ARM servers. Run \"uname -m\" on the machine if you are unsure.  "
},
{
"t": "Which bootloader?",
"u": "wiki.html#bootloader",
"s": "Manual walkthrough",
"d": "A unified kernel image bundles kernel, initramfs and command line  into one signed EFI file, which is what makes Secure Boot with  your own keys meaningful. systemd-boot is the simplest thing that  wo"
},
{
"t": "Which disk are you installing to?",
"u": "wiki.html#target-disk",
"s": "Manual walkthrough",
"d": "Run \"lsblk\" and identify the disk by its size and model, not by  the name you expect. This is the single most destructive value in  the whole guide: every partitioning command below is aimed at it."
},
{
"t": "Which filesystem?",
"u": "wiki.html#filesystem",
"s": "Manual walkthrough",
"d": "Btrfs gives you snapshots, so a bad update is one rollback away,  at the cost of subvolumes to lay out and its own tooling. ext4 is  the fewest moving parts and is extremely well understood."
},
{
"t": "Which kernels? (pick at least one)",
"u": "wiki.html#kernel-main",
"s": "Manual walkthrough",
"d": "Installing two is cheap insurance: if an update breaks the main  kernel you can boot the other one and fix it. linux-hardened  trades some performance and some out-of-tree driver compatibility  for ex"
},
{
"t": "Which security tools?",
"u": "wiki.html#security-suite",
"s": "Manual walkthrough",
"d": "Read what each one does before enabling it. Several can lock you  out of your own machine, which is the point of them, and the  reason none are enabled automatically."
},
{
"t": "Your username",
"u": "wiki.html#manual-install",
"s": "Manual walkthrough",
"d": "The everyday account. It goes in the wheel group so it can use  sudo; you should not be logging in as root."
},
{
"t": "📄 Your guide, so far",
"u": "manual.html#question-host",
"s": "Manual walkthrough",
"d": "Answer the first question and this fills in. Right-click any question to open the wiki section that explains it."
},
{
"t": "Generator",
"u": "index.html",
"s": "Page",
"d": "The ultimate dynamically customizable, highly secure guide to installing Arch Linux. Generate custom scripts and markdown tutorials."
},
{
"t": "Live editor",
"u": "live.html",
"s": "Page",
"d": "Live script editor for Arch Guides Dynamic. Edit, preview, and download your generated install scripts and markdown guides."
},
{
"t": "Manual walkthrough",
"u": "manual.html",
"s": "Page",
"d": "A guided manual Arch Linux install. Answer one question at a time, see what each choice means, and build a guide with every command and the reason for it. Full parity with the dynamic generator, and the recommended path on mobile."
},
{
"t": "Releases",
"u": "releases.html",
"s": "Page",
"d": "Download the latest stable releases of the Arch Rusty Security Suite (ARSS) by tilas01. Direct GitHub download links, GPG verification, and full changelog."
},
{
"t": "Repository",
"u": "repo.html",
"s": "Page",
"d": ""
},
{
"t": "Security tools",
"u": "security-tools.html",
"s": "Page",
"d": "Every security tool in the Arch Guides Dynamic project: tilas01's native Rust suite with live GitHub release stats, plus the vetted third-party hardening tools. Select a set and send it straight to the generator."
},
{
"t": "Verify an ISO",
"u": "iso-verify.html",
"s": "Page",
"d": "Verify an Arch Linux ISO before you install from it. Hashing happens in your browser and the file never leaves your machine, and the checksum is sourced from mirrors other than the one that served the image."
},
{
"t": "Wiki",
"u": "wiki.html",
"s": "Page",
"d": "The Arch Guides wiki: every generator option explained, a choose-your-own-path setup guide, the security tool suite, hardware security (BusKill, coreboot, Heads), and command cheatsheets."
},
{
"t": "1 Download the image",
"u": "iso-verify.html#step-download",
"s": "Verify an ISO",
"d": "The authority for what Arch has released is archlinux.org/download . Start there. Everything below is a convenience, not a replacement."
},
{
"t": "2 Get the checksums from somewhere else",
"u": "iso-verify.html#step-checksums",
"s": "Verify an ISO",
"d": "Two mirrors, neither of them the one that gave you the image, and where possible in different countries. Open both, copy the contents, and paste them into step 3."
},
{
"t": "3 Hash your file and compare",
"u": "iso-verify.html#step-verify",
"s": "Verify an ISO",
"d": "Drop your .iso here, or click to choose Read locally in 8 MiB pieces. It is never uploaded, and nothing about it is sent anywhere. Expect roughly a minute for a full ISO. Cancel Fi…"
},
{
"t": "4 Check the signature. Do not skip this.",
"u": "iso-verify.html#step-gpg",
"s": "Verify an ISO",
"d": "A matching hash proves your file is what those mirrors serve. It does not prove Arch published it. Only the GPG signature does that, because only the release engineer holds the key…"
},
{
"t": "5 Write it, and mind the dual boot",
"u": "iso-verify.html#step-write",
"s": "Verify an ISO",
"d": "Verify before writing. Writing an image you have not checked and verifying the USB afterwards tells you the copy succeeded, not that the original was genuine."
},
{
"t": "0 · Before you boot the installer",
"u": "wiki.html#mi-0",
"s": "Wiki",
"d": "loadkeys uk # your layout; skip for US ls /sys/firmware/efi && echo UEFI # confirms firmware mode # Wired: usually already up. Wireless: iwctl [iwd]# device list [iwd]# station wla…"
},
{
"t": "1 · Boot and get a network",
"u": "wiki.html#mi-1",
"s": "Wiki",
"d": "loadkeys uk # your layout; skip for US ls /sys/firmware/efi && echo UEFI # confirms firmware mode # Wired: usually already up. Wireless: iwctl [iwd]# device list [iwd]# station wla…"
},
{
"t": "100% Libre Software Policy",
"u": "wiki.html#advanced-config-libre",
"s": "Wiki",
"d": "If you toggle the Enforce 100% Libre Software Policy in the generator, the interface will dynamically audit your selections. Any software containing proprietary or closed-source co…"
},
{
"t": "2 · Decide: encrypted or not",
"u": "wiki.html#mi-2",
"s": "Wiki",
"d": "LUKS2 with Argon2id. Costs you a passphrase at every boot. Means a stolen laptop is a stolen laptop, not a data breach. Continue at step 3 and take the encrypted branch."
},
{
"t": "3 · Partition",
"u": "wiki.html#mi-3",
"s": "Wiki",
"d": "UEFI + GPT, which is what you want unless the firmware gives you no choice:"
},
{
"t": "4 · Decide: Btrfs or ext4",
"u": "wiki.html#mi-4",
"s": "Wiki",
"d": "Btrfs subvolume layout that makes snapshots useful:"
},
{
"t": "5 · Install the base system",
"u": "wiki.html#mi-5",
"s": "Wiki",
"d": "# Choose your kernel here. linux-hardened trades some performance and some # out-of-tree driver compatibility for exploit mitigations; linux-lts trades # newest hardware support fo…"
},
{
"t": "6 · Configure inside the chroot",
"u": "wiki.html#mi-6",
"s": "Wiki",
"d": "ln -sf /usr/share/zoneinfo/Region/City /etc/localtime hwclock --systohc sed -i 's/^#en_GB.UTF-8/en_GB.UTF-8/' /etc/locale.gen locale-gen echo \"LANG=en_GB.UTF-8\" > /etc/locale.conf…"
},
{
"t": "7 · Decide: which bootloader",
"u": "wiki.html#mi-7",
"s": "Wiki",
"d": "Full walkthroughs: docs/04-bootloaders and Secure Boot with your own keys . Minimal systemd-boot:"
},
{
"t": "8 · Decide: what goes on top",
"u": "wiki.html#mi-8",
"s": "Wiki",
"d": "Nothing here is required to have a working system. Reboot first, confirm you can log in, then add things — debugging a desktop environment is much easier from a system you know boo…"
},
{
"t": "9 · Reboot",
"u": "wiki.html#mi-9",
"s": "Wiki",
"d": "exit umount -R /mnt reboot If it does not come up: boot the installer again, cryptsetup open , remount, arch-chroot , and you are back where you were. Almost nothing at this stage…"
},
{
"t": "AEM Decoy Count",
"u": "wiki.html#advanced-config-aem",
"s": "Wiki",
"d": "Anti-Evil Maid secures your /boot partition by verifying decoy kernels. You can select how many decoy images to generate. 1 Decoy is standard. 3 Decoys is for maximum paranoia but…"
},
{
"t": "Automatic System Updates",
"u": "wiki.html#auto_updates",
"s": "Wiki",
"d": "Pacman hook runs on transactions; systemd timer runs on a schedule and requires systemd as your init. Unattended updates on a rolling release can pull in a broken package, so keep…"
},
{
"t": "Backup Kernel",
"u": "wiki.html#kernel-backup",
"s": "Wiki",
"d": "A second kernel to boot when an update leaves the main one unbootable. Strongly recommended — linux-lts is the usual choice. Selecting None means a bad kernel update leaves you rea…"
},
{
"t": "Bootloader & Secure Boot",
"u": "wiki.html#bootloader",
"s": "Wiki",
"d": "UKI + Custom Keys enrols your own Secure Boot keys and signs a single EFI binary containing kernel, initramfs and cmdline — nothing unsigned on the ESP to tamper with. UKI + Shim u…"
},
{
"t": "CPU Brand",
"u": "wiki.html#cpu_brand",
"s": "Wiki",
"d": "Selects the microcode package: amd-ucode or intel-ucode . Microcode carries silicon errata and speculative-execution mitigations, so it matters for security, not just stability."
},
{
"t": "Check it actually took effect",
"u": "wiki.html#bios-verify",
"s": "Wiki",
"d": "# Are we on UEFI at all? ls /sys/firmware/efi && echo \"UEFI\" || echo \"Legacy BIOS\" # Is Secure Boot enforcing? bootctl status | grep -i \"secure boot\" # Is the TPM present and which…"
},
{
"t": "DNS Caching",
"u": "wiki.html#dns",
"s": "Wiki",
"d": "systemd-resolved is built in and supports DNS-over-TLS. unbound is a full validating recursive resolver. dnscrypt-proxy encrypts queries to upstream resolvers. dnsmasq and BIND sui…"
},
{
"t": "Desktop Environment",
"u": "wiki.html#desktop",
"s": "Wiki",
"d": "None leaves a pure TTY. GNOME and KDE are full environments. DWM is a minimal tiling WM requiring Xorg. Dusky is a pre-configured Hyprland setup by dusklinux and forces Wayland."
},
{
"t": "Display Server",
"u": "wiki.html#display_server",
"s": "Wiki",
"d": "Wayland isolates clients from each other, so one window cannot read another's input or framebuffer — a real security improvement over Xorg , where any client can. Xorg is still nee…"
},
{
"t": "Do not reformat the EFI system partition",
"u": "wiki.html#dual-boot-esp",
"s": "Wiki",
"d": "Windows and Arch share one ESP quite happily. What breaks it is formatting the existing one — that deletes \\EFI\\Microsoft\\Boot\\bootmgfw.efi and with it the Windows boot entry."
},
{
"t": "Doas Integration Mode",
"u": "wiki.html#advanced-config-doas",
"s": "Wiki",
"d": "Passwords are never stored in the UI or inside the generated scripts for your security. Regardless of the Configuration Mode you choose:"
},
{
"t": "Double OTP Verification",
"u": "wiki.html#otp_double",
"s": "Wiki",
"d": "Requires two consecutive valid codes, meaning a 30-second wait between them, or codes from two separate authenticators. Meaningful extra assurance, meaningful extra friction."
},
{
"t": "Duress Decoy Environment",
"u": "wiki.html#luks_duress_decoy",
"s": "Wiki",
"d": "Which environment a duress boot presents. Requires a pre-created partition labelled decoy — see setting up the decoy volume ."
},
{
"t": "Dusky Automated Setup",
"u": "wiki.html#dusky_setup",
"s": "Wiki",
"d": "A single yes/no. Yes installs Dusky by dusklinux: a pre-configured Hyprland desktop with dotfiles, theming and a full Wayland environment. Because Dusky brings its own answers, c…"
},
{
"t": "Encryption alongside Windows",
"u": "wiki.html#dual-boot-encryption",
"s": "Wiki",
"d": "LUKS on the Arch partitions and BitLocker on the Windows one coexist without trouble — they are separate partitions with separate keys. What does not work is expecting either one t…"
},
{
"t": "File System",
"u": "wiki.html#filesystem",
"s": "Wiki",
"d": "BTRFS gives subvolumes, transparent zstd compression and instant snapshots (paired with Snapper). Ext4 is the conservative, universally understood choice. XFS performs well on larg…"
},
{
"t": "Firewall Setup",
"u": "wiki.html#firewall",
"s": "Wiki",
"d": "UFW + Gufw is the recommended default-deny setup with a GUI. Firewalld suits zone-based configurations. iptables is for people who want to write their own rules. None leaves every…"
},
{
"t": "Firmware Interface",
"u": "wiki.html#firmware",
"s": "Wiki",
"d": "UEFI is required for Unified Kernel Images, systemd-boot and Secure Boot. Legacy BIOS can only use GRUB and cannot read a LUKS2 header at boot, so the generator restricts you to GR…"
},
{
"t": "GPU Brand",
"u": "wiki.html#gpu_brand",
"s": "Wiki",
"d": "AMD and Intel use the libre Mesa stack. For NVIDIA the generator installs the proprietary driver unless your software type is Libre or Open Source, in which case it falls back to n…"
},
{
"t": "Getting into firmware setup",
"u": "wiki.html#bios-enter",
"s": "Wiki",
"d": "Tap the key during POST, before any operating system loads. Common ones: Del and F2 on desktops, F1 / F2 / F10 / F12 / Esc on laptops. If the machine boots too fast to catch it, fr…"
},
{
"t": "Init System",
"u": "wiki.html#init_system",
"s": "Wiki",
"d": "systemd is the Arch default and enables the sd-encrypt initramfs hook plus UKI support. busybox/udev is the traditional path using the encrypt hook. Note that choosing busybox whil…"
},
{
"t": "Install Windows first",
"u": "wiki.html#dual-boot-order",
"s": "Wiki",
"d": "If you are starting from empty disks, install Windows before Arch. The Windows installer overwrites the EFI boot order and will happily remove a Linux entry it does not recognise.…"
},
{
"t": "JetBrains Terminal Themes",
"u": "wiki.html#advanced-config-themes",
"s": "Wiki",
"d": "If you selected to install JetBrains Mono and Terminal Themes, you can pick your preferred color palette (TokyoNight, Catppuccin, Rosé Pine, Dracula) here. The script will automati…"
},
{
"t": "Layer 1: Base Disk Encryption",
"u": "wiki.html#partitioning",
"s": "Wiki",
"d": "LUKS2 with Argon2id is the recommended default — memory-hard key derivation makes brute force expensive. LUKS1 exists only for legacy GRUB compatibility. LVM on LUKS2 puts a volume…"
},
{
"t": "Layer 2: Cipher Algorithm",
"u": "wiki.html#encryption_cipher",
"s": "Wiki",
"d": "AES-256-XTS is the standard and is hardware-accelerated on essentially all modern CPUs (check grep aes /proc/cpuinfo ). AES-256-GCM adds authentication but is unusual for full-disk…"
},
{
"t": "Layer 3: Post-Quantum Overlay",
"u": "wiki.html#encryption_pq",
"s": "Wiki",
"d": "Kyber-1024 is a NIST-selected post-quantum KEM. Support in the Linux boot path is experimental and may prevent the system booting at all. Leave this at None unless you are specific…"
},
{
"t": "Layer 4: LUKS Duress Password",
"u": "wiki.html#luks_duress_action",
"s": "Wiki",
"d": "See the full LUKS duress passphrase section. The erasing options are irreversible."
},
{
"t": "Libre-OTP Configuration",
"u": "wiki.html#advanced-config-libre-otp",
"s": "Wiki",
"d": "Libre-OTP allows you to integrate Time-Based One-Time Passwords (TOTP) natively into Linux Pluggable Authentication Modules (PAM). This enforces 2FA physically onto your machine."
},
{
"t": "Main Kernel",
"u": "wiki.html#kernel-main",
"s": "Wiki",
"d": "linux-hardened applies exploit-mitigation patches and stricter defaults at some performance cost. linux is the balanced mainline. linux-zen favours desktop latency. linux-lts favou…"
},
{
"t": "Measured boot: what coreboot, Heads and NitroPad actually do",
"u": "wiki.html#measured-boot",
"s": "Wiki",
"d": "Secure Boot checks a signature — it asks whether the thing about to run was signed by a trusted key. Measured boot instead hashes each stage into a TPM before running it. The TPM w…"
},
{
"t": "OTP Bypass Uses",
"u": "wiki.html#otp_bypass",
"s": "Wiki",
"d": "A limited-use password that skips OTP entirely. Every use is one fewer factor, so None is recommended."
},
{
"t": "OTP Enforcement Mode",
"u": "wiki.html#libre_otp_mode",
"s": "Wiki",
"d": "Where Libre OTP is enforced: at login only, in the initramfs before the kernel hands over, or both."
},
{
"t": "OTP Hash Algorithm",
"u": "wiki.html#otp_sha",
"s": "Wiki",
"d": "SHA-1 is what essentially every authenticator app supports and is not a weakness in the HMAC construction TOTP uses. SHA-256 and SHA-512 are stronger but far fewer apps implement t…"
},
{
"t": "OTP Recovery Codes",
"u": "wiki.html#otp_recovery",
"s": "Wiki",
"d": "Single-use codes for when you lose your authenticator. Print them and store them offline — not on the machine they unlock. Choosing None means a lost authenticator locks you out pe…"
},
{
"t": "Or need less of it",
"u": "wiki.html#aur-reduce",
"s": "Wiki",
"d": "The most effective AUR hardening is wanting fewer AUR packages. Check the official repositories and Flatpak first; prefer source-built AUR packages over -bin ones, since you can at…"
},
{
"t": "Post-Install Cleanup",
"u": "wiki.html#cleanup",
"s": "Wiki",
"d": "Clears the pacman cache and build dependencies after installation. Saves a few gigabytes; the trade-off is that downgrading a package later means re-downloading it."
},
{
"t": "Read it. Every time, including updates.",
"u": "wiki.html#aur-read",
"s": "Wiki",
"d": "git clone https://aur.archlinux.org/some-package.git cd some-package less PKGBUILD less *.install # these run as root, at install time makepkg -si # only after you have read both U…"
},
{
"t": "Root SSH Access",
"u": "wiki.html#root_ssh",
"s": "Wiki",
"d": "Leave at No . Root login over SSH is the single most attacked door on an internet-facing host; use a normal user with doas / sudo . If enabled, the generator sets PermitRootLogin p…"
},
{
"t": "Script Verbosity Level",
"u": "wiki.html#advanced-config-verbosity",
"s": "Wiki",
"d": "Instead of relying on the script to prompt you interactively during the build, you can pre-define the exact system usernames you want created directly in the generator. This ensure…"
},
{
"t": "Secure Password Handling",
"u": "wiki.html#advanced-config-passwords",
"s": "Wiki",
"d": "Passwords are never stored in the UI or inside the generated scripts for your security. Regardless of the Configuration Mode you choose:"
},
{
"t": "Snapper Timeline Mode",
"u": "wiki.html#advanced-config-snapper",
"s": "Wiki",
"d": "Passwords are never stored in the UI or inside the generated scripts for your security. Regardless of the Configuration Mode you choose:"
},
{
"t": "Software Type",
"u": "wiki.html#software_type",
"s": "Wiki",
"d": "Fully Libre avoids proprietary blobs entirely and prefers opendoas and pfetch . Open Source + Firmware permits redistributable firmware. Open Source + Proprietary allows closed dri…"
},
{
"t": "Step 0: lock down the firmware you already have",
"u": "wiki.html#lock-down-firmware",
"s": "Wiki",
"d": "Free, reversible, and by far the best value. Do this regardless of anything else:"
},
{
"t": "Suspend BitLocker first",
"u": "wiki.html#dual-boot-bitlocker",
"s": "Wiki",
"d": "BitLocker seals its key to TPM measurements that include the boot configuration. Installing a second bootloader changes those measurements, and the next Windows boot demands a 48-d…"
},
{
"t": "Swap Size",
"u": "wiki.html#swap_size",
"s": "Wiki",
"d": "Created as a swapfile (a BTRFS-native one on BTRFS). Hibernation needs swap at least the size of RAM; the generator blocks hibernation with no swap. 0GB is viable on a machine with…"
},
{
"t": "System Usernames",
"u": "wiki.html#advanced-config-usernames",
"s": "Wiki",
"d": "Instead of relying on the script to prompt you interactively during the build, you can pre-define the exact system usernames you want created directly in the generator. This ensure…"
},
{
"t": "Target Disk",
"u": "wiki.html#target-disk",
"s": "Wiki",
"d": "The whole device is wiped. Run lsblk -f and match on size and existing partitions before committing. In VMs this is usually /dev/sda ; on NVMe hardware, /dev/nvme0n1 ."
},
{
"t": "The auditor in this project",
"u": "wiki.html#aur-guard",
"s": "Wiki",
"d": "aur-guard statically checks a PKGBUILD and its .install files for the patterns above, before makepkg gets to run any of it."
},
{
"t": "The clock will disagree",
"u": "wiki.html#dual-boot-time",
"s": "Wiki",
"d": "Linux keeps the hardware clock in UTC; Windows expects local time. Fix it on the Linux side, which is the standards-compliant one:"
},
{
"t": "The recommended settings, and why each one",
"u": "wiki.html#bios-recommended",
"s": "Wiki",
"d": "\"Highest security\" is the right default here. Each of these closes a path an attacker with physical access would otherwise take, and the cost to you is a few seconds at boot."
},
{
"t": "Turn off Fast Startup before you touch NTFS",
"u": "wiki.html#dual-boot-faststartup",
"s": "Wiki",
"d": "Windows Fast Startup is hibernation wearing a shutdown costume. The NTFS filesystem is left in a dirty, in-use state. Resizing it or mounting it read-write from Linux in that state…"
},
{
"t": "USB Kill Switch",
"u": "wiki.html#usb_kill",
"s": "Wiki",
"d": "See the full USB kill switch section. Start with \"lock session\"; the shutdown actions fire without confirmation."
},
{
"t": "USB Kill Trigger",
"u": "wiki.html#usb_kill_trigger",
"s": "Wiki",
"d": "Whether to react to an unlisted device being connected, an allowlisted device being removed, or both."
},
{
"t": "VM Guest Setup",
"u": "wiki.html#vm_guest",
"s": "Wiki",
"d": "Installs and enables the matching guest agent for clipboard sharing, display resizing and clean shutdown: VirtualBox, VMware (open-vm-tools), or QEMU/KVM (qemu-guest-agent)."
},
{
"t": "What firmware lockdown does not do",
"u": "wiki.html#bios-limits",
"s": "Wiki",
"d": "It raises the cost of an attack that needs the machine in front of it. It does not stop an attacker who can desolder the SPI flash chip and reprogram it, and on most consumer hardw…"
},
{
"t": "What to look for",
"u": "wiki.html#aur-flags",
"s": "Wiki",
"d": "aur-guard statically checks a PKGBUILD and its .install files for the patterns above, before makepkg gets to run any of it."
},
{
"t": "Where the suite keeps its state",
"u": "wiki.html#suite-state",
"s": "Wiki",
"d": "Every tool stores its configuration and baselines under /etc/arch-security/<tool>/ — kernel-watcher/tamper.hash , kernel-watcher/evil_maid.hash , anti-evil-maid/boot.hash , anti-du…"
},
{
"t": "Which one am I on?",
"u": "wiki.html#arch-which",
"s": "Wiki",
"d": "uname -m # x86_64 → Intel or AMD desktop/laptop. Use plain Arch Linux. # aarch64 → 64-bit ARM. Raspberry Pi 3/4/5, Pinebook, Apple Silicon under a VM, # most ARM servers. Use Arch…"
},
{
"t": "aarch64 — what actually changes",
"u": "wiki.html#arch-arm",
"s": "Wiki",
"d": "ARM is not \"x86 with a different compiler flag\". These differences are structural, and the generated guide branches on all of them:"
},
{
"t": "coreboot vs libreboot — DIY route",
"u": "wiki.html#coreboot-vs-libreboot",
"s": "Wiki",
"d": "Both replace your proprietary firmware. They are not the same thing:"
},
{
"t": "x86_64",
"u": "wiki.html#arch-x86",
"s": "Wiki",
"d": "The path everything else in this wiki assumes. UEFI firmware, an EFI system partition, a bootloader you choose ( UKI, systemd-boot or GRUB ), CPU microcode from intel-ucode or amd-…"
},
{
"t": "⌨️ Manual Install — Choose Your Own Path",
"u": "wiki.html#manual-install",
"s": "Wiki",
"d": "The generator writes this script for you. This section is the same install done by hand, with the decision points called out, so you can do it without the generator or check what t…"
},
{
"t": "⏳ Endlessh (SSH Tarpit)",
"u": "wiki.html#endlessh",
"s": "Wiki",
"d": "Endlessh is an SSH tarpit that slowly sends an endless, random SSH banner to clients. This ties up automated SSH scanners and botnets for hours or even weeks, preventing them from…"
},
{
"t": "⚙️ Advanced App Configuration",
"u": "wiki.html#advanced-config",
"s": "Wiki",
"d": "This section details the advanced configuration choices available in the generator when selecting Ask all questions in generator now toggle enabled or when prompted via the interac…"
},
{
"t": "⚙️ Generator Configuration Steps",
"u": "wiki.html#generator-steps",
"s": "Wiki",
"d": "This section explains every dropdown option available in the Arch Guides Dynamic generator."
},
{
"t": "🐧 100% Libre Software Policy",
"u": "wiki.html#libre-policy",
"s": "Wiki",
"d": "Enabling Enforce 100% Libre Software Policy in the generator highlights any proprietary selection in red and writes an explicit conflict notice into the generated guide, so you can…"
},
{
"t": "👁️ Kernel Watcher",
"u": "wiki.html#kernel-watcher",
"s": "Wiki",
"d": "Asynchronous filesystem monitor that flags infostealers touching browser profiles, SSH keys and wallet files, and detects userland rootkit behaviour. A lightweight semi-EDR that ru…"
},
{
"t": "📋 Cheatsheets",
"u": "wiki.html#cheatsheets",
"s": "Wiki",
"d": "Quick references, kept outside the generator so you can reach them any time."
},
{
"t": "📦 Installing the Suite in One Step",
"u": "wiki.html#suite-installer",
"s": "Wiki",
"d": "scripts/install-security-suite.sh installs all five tools at once, so you do not have to fetch and verify each one by hand."
},
{
"t": "📦 The AUR, and How Not to Get Owned by It",
"u": "wiki.html#aur-safety",
"s": "Wiki",
"d": "The Arch User Repository is not a package repository. It is a collection of build scripts that strangers wrote and that makepkg executes on your machine, as you, with your permissi…"
},
{
"t": "🔌 BusKill — recommended, cheap, reversible",
"u": "wiki.html#buskill",
"s": "Wiki",
"d": "BusKill is a magnetically-separating USB cable: one end plugs into your laptop, the other clips to your belt. Walk away — or have the laptop taken — and the magnet releases, which…"
},
{
"t": "🔌 USB Kill Switch",
"u": "wiki.html#usb-kill",
"s": "Wiki",
"d": "Modelled on the usbkill project. At install time the generator snapshots the USB devices currently attached into an allowlist at /etc/arch-security/usb-allowlist , and installs a u…"
},
{
"t": "🔍 Build Integrity & Reproducible Builds",
"u": "wiki.html#reproducible-builds",
"s": "Wiki",
"d": "In the Generator, every post-install application displays an information tooltip with its Build Integrity . Here is what those terms mean for your security and trust model:"
},
{
"t": "🔎 Security Audit of These Tools",
"u": "wiki.html#audit",
"s": "Wiki",
"d": "A tool you are asked to trust with your boot chain should be able to show its own review. docs/security-audit.md is a source-level audit of all five crates, including what it found…"
},
{
"t": "🔐 Firmware Setup and Lockdown",
"u": "wiki.html#bios-lockdown",
"s": "Wiki",
"d": "Tap the key during POST, before any operating system loads. Common ones: Del and F2 on desktops, F1 / F2 / F10 / F12 / Esc on laptops. If the machine boots too fast to catch it, fr…"
},
{
"t": "🔐 Libre OTP",
"u": "wiki.html#libre-otp",
"s": "Wiki",
"d": "Native Rust TOTP/HOTP two-factor authentication for boot, login and SSH. Configurable SHA-1/256/512, optional double-OTP, single-use recovery codes and a limited-use bypass passwor…"
},
{
"t": "🔑 Hardware Security Key (FIDO2 / U2F)",
"u": "wiki.html#yubikey",
"s": "Wiki",
"d": "The generator supports integrating physical FIDO2/U2F tokens (like YubiKeys) directly into the Linux PAM stack via pam_u2f ."
},
{
"t": "🔒 Verifying Downloads (GPG & Hashes)",
"u": "wiki.html#verification",
"s": "Wiki",
"d": "Every binary published by this project is SHA-512 hashed and, when the CI signing key is configured, GPG-signed. Verify before running anything."
},
{
"t": "🔗 Generator Option Reference",
"u": "wiki.html#option-reference",
"s": "Wiki",
"d": "Right-clicking any dropdown in the generator jumps straight to its entry here. Each one explains what the setting does and how to configure it by hand if you would rather not use t…"
},
{
"t": "🔧 Hardware & Firmware Security",
"u": "wiki.html#hardware-security",
"s": "Wiki",
"d": "Everything the generator does happens after your firmware has already run. If someone can modify the firmware, none of it helps — they can capture your passphrase before the kernel…"
},
{
"t": "🔴 LUKS Duress Passphrase",
"u": "wiki.html#luks-duress",
"s": "Wiki",
"d": "A duress passphrase is a second valid passphrase on the LUKS header. Your real passphrase keeps working unchanged; entering the duress one at the boot prompt runs a chosen response…"
},
{
"t": "🕵️ Anti-Evil Maid",
"u": "wiki.html#anti-evil-maid",
"s": "Wiki",
"d": "Verifies boot integrity by hashing the boot chain and comparing it across boots, and generates generic decoy kernel entries so the real encrypted target is not obvious. Supports a…"
},
{
"t": "🚫 Fail2ban Intrusion Prevention",
"u": "wiki.html#fail2ban",
"s": "Wiki",
"d": "Fail2ban monitors system logs (like /var/log/auth.log ) for automated attacks and brute-force attempts. When it detects multiple failed login attempts from a single IP address, it…"
},
{
"t": "🛡️ Third-Party Security Tools",
"u": "wiki.html#other-sec",
"s": "Wiki",
"d": "Well-established tools from the Arch repositories, selectable in the generator and on the Security Tools page."
},
{
"t": "🛡️ UFW Firewall Profiles",
"u": "wiki.html#firewall-profiles",
"s": "Wiki",
"d": "The Generator allows you to configure Uncomplicated Firewall (UFW) dynamically during installation."
},
{
"t": "🦀 Security Suite & Live Releases",
"u": "wiki.html#security-suite",
"s": "Wiki",
"d": "All tools can be compiled directly via Cargo or downloaded from the GitHub releases page below. Ensure you have the Rust toolchain installed ( pacman -S rust ) for compiling."
},
{
"t": "🦅 Scarecrow",
"u": "wiki.html#scarecrow",
"s": "Wiki",
"d": "Plants canary tokens and spoofs sandbox/VM artefacts, so malware that checks whether it is being analysed decides to stay dormant. Includes an optional kernel module. Detection-ori…"
},
{
"t": "🦆 Input Guard (Anti-Ducky)",
"u": "wiki.html#anti-ducky",
"s": "Wiki",
"d": "Monitors USB HID keystroke timing and sandboxes unknown input devices, blocking Rubber Ducky / BadUSB style automated keystroke injection before the payload can type. Requires appr…"
},
{
"t": "🧠 Memory Integrity Checker",
"u": "wiki.html#memory-integrity",
"s": "Wiki",
"d": "If an advanced rootkit attempts to patch syscall tables in live memory or hide malicious kernel modules (Direct Kernel Object Manipulation - DKOM), the integrity checker will detec…"
},
{
"t": "🧩 CPU Architecture: x86_64 or aarch64",
"u": "wiki.html#architecture",
"s": "Wiki",
"d": "This is the first question the generator asks, because almost everything downstream depends on it. Getting it wrong does not produce a subtly worse install — it produces a script t…"
},
{
"t": "🧭 Choose Your Own Path",
"u": "wiki.html#choose-your-path",
"s": "Wiki",
"d": "The options below are not a checklist to complete — several of them can destroy your data or lock you out permanently. Start from the threat you actually have and follow that branc…"
},
{
"t": "🪟 Dual Booting with Windows",
"u": "wiki.html#dual-boot",
"s": "Wiki",
"d": "Dual booting is the single most common way people lose data during an Arch install, and almost always for one of five reasons. Each has a preventable cause."
}
]