1. Build the ISO
Writes dist/hos-install.iso.
git clone https://github.com/Jonathan-R-Anderson/anonymOS
cd anonymOS
./build-in-docker.sh
rabbiit.io
Decentralized · Onion-routed · Community-run
Route · Store · Resolve · Earn
An overlay network for anonymous routing, content-addressed distributed storage and cryptographically owned names — run by independent nodes that no single party owns. Contribute storage and bandwidth, earn credits, and help hold up infrastructure that cannot be quietly switched off.
Earn tokens
The network pays for verified infrastructure contribution, measured by Proof of Facilitation.
Kernel written
from scratch in D
Runs unmodified
Alpine Linux binaries
No root user.
Capabilities only.
Qubes-style domains,
without VMs
x86_64 with UEFI. Developed and tested in QEMU and VirtualBox.
Experimental. anonymOS is under heavy development. It has no ASLR yet, has not been verified on real hardware, and is not meant for daily use.
Docker is the only host requirement: the whole build runs inside an image and hands back the installer ISO. Expect hours on the first run.
anonymOS in action
Features
Underneath the Linux surface there are no Unix uids and no file inodes. Processes, files, windows, users, services and devices are all objects, joined by typed edges in an Object-Reference-Graph that the kernel validates and garbage collects.
Access is a capability: a set of 19 rights bits on a live object. A derived
capability can only be a subset of its parent, revoking one revokes everything
derived from it, and capabilities cannot be forged. There is no god-capability
and no uid 0; administration is split into distinct typed
capabilities.
Every process belongs to a named, coloured identity, inherited at fork and fixed from then on: System, Personal, Work, Banking, Development, Untrusted and Disposable come built in. Each sees its own object namespace, and cross-domain IPC is denied unless a rule allows it.
A window's border colour is stamped by the kernel from the process that owns it, so an application cannot dress itself up as your banking domain. The Domain Manager clones domains, gives each a deny-by-default filesystem, gates the GPU, camera, microphone and USB per domain, and exports signed templates.
anonymOS is not a Linux distribution. Its kernel implements the Linux system-call interface as a personality on top of its own object model, so unmodified musl programs run: BusyBox, the Z shell, GTK applications, the Hyprland desktop and Firefox, which loads HTTPS sites over the kernel's own TCP/IP stack.
The Software Center searches 73,191 packages from Alpine, Debian, Ubuntu, Fedora, Arch, openSUSE and Flathub, with the catalog shipped in the image so it works offline. It is honest about what will run: Alpine packages share this system's libc and install, and glibc entries say why they can't.
Work in progress
An optional install step puts anonymOS in a deeper encryption layer behind a decoy. A VeraCrypt-derived pre-boot loader asks for one password: one answer boots an ordinary Alpine Linux desktop, the other boots the hidden system, and a typo unlocks the decoy.
The decoy is made to look lived in. Its log history is generated from Perlin noise seeded by the password, so it is never stored and comes out the same on every boot. The loader and encrypted layout are proven end to end in firmware; the full-disk illusion is still to do.
One JSON file, system.json, declares the whole running system, and the
installer collects your choices into an install.json that is read at
every boot. The system image is immutable: on an installed machine
/usr refuses writes, the store is verity-checked, and updates deploy
as new generations that roll back.
Update bundles are verified against a pinned Ed25519 key. For now that is a development key, and the boot loader still loads its modules unsigned.
When a workload needs a real kernel of its own, anonymOS runs one. Its in-kernel hypervisor exposes a KVM-compatible interface, and Cloud Hypervisor running on top of it boots Alpine Linux and the OPNsense firewall.
A VirtualBox-style Virtual Machines app creates, snapshots and restores guests. Intel VT-x is the validated path; AMD SVM is written but not yet tested on hardware.
Work in progress
rabbiit-node, the network's node, is developed inside the
anonymOS tree and builds as a static binary for it. Go programs now run correctly
on the kernel, and bringing the node up as the system's native anonymizing layer is
the work in progress.
The rabbiit.io network
The rabbiit.io network is a network of independent volunteer computers that holds up this site. They store its content as encrypted, erasure-coded shards, serve it through volunteer HTTPS gateways, and are paid in credits for work that has been checked. Peers reach each other over I2P, so volunteers never learn one another's IP addresses.
Where it is going: AXON, an overlay for anonymous routing, content-addressed storage and cryptographically owned names, run by independent nodes that no single party owns.
Live
Content is encrypted with XChaCha20-Poly1305 before any node receives it, then split into Reed-Solomon shards, 6 data plus 3 parity, each addressed by its SHA-256 hash. Any three of the nine can be lost. Nodes hold shards they cannot read.
Live
Nodes advertise only I2P addresses, with no direct-network fallback, so a volunteer sees other volunteers' I2P destinations and never their IPs. I2P does not hide traffic timing or shard sizes.
Live
A gateway reads only the TLS server name, then splices the encrypted bytes through to
the origin without terminating TLS. Each one is checked by the gateway controller
before its gw-<id>.rabbiit.io name goes into DNS.
Partly wired
Hour-long epochs. Nodes answer Merkle-proof audits, audit each other, and collect receipts signed by randomly chosen witnesses; receipt roots settle on-chain with a challenge window. The contracts are deployed; settlement is being switched on.
In development
The network's own onion transport: relays, circuits and hidden services, so no single relay sees both ends of a connection. Tested in-process; live traffic still runs over I2P.
A node donates disk and uptime to the network and is paid in credits for the work that gets checked.
Fetches a prebuilt binary, checks its SHA-256, installs an I2P router if one isn't running, and leaves the node running as a non-root service. It shows the plan and asks before changing anything.
# print the plan and stop
curl -fsSL https://rabbiit.io/install.sh | sh -s -- --check
# install
curl -fsSL https://rabbiit.io/install.sh | sh
Then open the dashboard at http://127.0.0.1:9090.
Read the script first, or get
other platforms and builds.
Why this exists
Reading about a diagnosis. A search term that is evidence where you live. A source who needs your silence to be worth something.
Unrelated operators, unrelated places. No company to subpoena, no server to seize, no one who can be leaned on for the whole picture.
Anonymity used by a few is a spotlight. It only protects you when it is ordinary, which takes people, not cryptography.
FAQ
No. The kernel is written from scratch in D, without a garbage collector. It implements the Linux system-call interface as a personality on top of its own object-capability core, so unmodified musl programs run, but nothing underneath is Linux.
Programs built against musl, which in practice means Alpine Linux packages, install
and run. glibc-based packages from other distributions don't. Windows, macOS and
Android software is meant to run through compatibility runtimes (Wine, Darling and
Waydroid) delegated to a domain. Android is furthest along: the ART runtime starts
and preloads, but no .apk runs yet.
An x86_64 virtual machine with UEFI firmware, x2APIC turned on, 4 vCPUs and 4 GB of RAM (6 GB is recommended for installing). anonymOS is developed and tested in QEMU and VirtualBox; booting on physical hardware hasn't been verified yet.
Not yet. The capability model, domains and signed updates are in place, but memory hardening is the headline remaining work: there is no ASLR and no NX stack, and W^X is only partial. Update bundles are signed with a development key, and the boot loader still loads its modules unsigned.
Disk space (20 GiB by default) and uptime, plus any optional roles you turn on. A node stores encrypted shards it cannot decrypt and talks to other volunteers only over I2P, so volunteers never see one another's IP addresses. rabbiit.io itself does see your IP, through the node's heartbeat: the privacy guarantee is between volunteers.
No. A gateway reads only the TLS server name to decide where a connection goes, then passes the encrypted bytes through. TLS runs end to end to the origin.
Not yet. AXON's identity layer is built and its circuits, DHT and sessions are tested in-process, but traffic between nodes still runs over I2P.
In credits, for storage and audit work that Proof of Facilitation has checked, once you set a payout address. Being offline isn't punished; it just isn't paid. On-chain settlement is still being switched on.