Install
A new machine: one download and a USB stick. A machine on Silverblue, Kinoite or another atomic Fedora: one command.
A fresh install
A weekly installer ISO for each variant, built from the published image itself: the same Anaconda installer stock Silverblue uses, landing directly in Pulsar. Checksummed, and signed with Pulsar's release key.
- standard pulsar-latest-x86_64.iso .sha256.sha256.sig.json
- nvidia pulsar-nvidia-latest-x86_64.iso .sha256.sha256.sig.json
Write it to a USB stick with GNOME Disks or dd, boot, install.
The .json sidecar records exactly which image digest the installer carries.
Signed with the release key, which never leaves the signing host.
cosign verify-blob pulsar-latest-x86_64.iso.sha256 \
--key https://lighthouse.arclight.digital/pulsar/iso/cosign.pub \
--signature pulsar-latest-x86_64.iso.sha256.sig \
--insecure-ignore-tlog=true \
&& sha256sum -c pulsar-latest-x86_64.iso.sha256
The public half of that key is published beside the ISOs and committed to the repo as
keys/cosign.pub; the build verifies every signature against the committed copy
before publishing.
--insecure-ignore-tlog skips Rekor, Sigstore’s public transparency log. The ISOs’ signatures aren’t logged there yet (the images’ are), so this check rests on the published key alone.
From Windows or a Mac, and keeping Windows: From Windows or macOS.
Boot from the stick and start the installer.
- You choose the disk and partitioning. Nothing is erased until you confirm; back up first.
- Account and Wi-Fi: the installer’s accounts step, or GNOME’s setup on first boot.
- It waits on its last screen. Remove the stick and restart.
Use the current ISO, not an old download
-latest links above are always the current, safe build.
NVIDIA: enroll the key, once
The NVIDIA driver is signed with Pulsar’s key, so Secure Boot stays on. Enroll the key once, through MokManager on the next boot. The standard image doesn’t need this.
Two ways to get there. Enroll it right away with the steps below, and the NVIDIA driver loads from the next boot. Or just log in: until the key is enrolled the desktop runs on the open-source driver, and a moment after you log in GNOME Software offers to enroll the key for you. Follow its prompts, restart, answer MokManager as in step 2, and you’re on NVIDIA.
-
Import the certificate
mokutilasks for a one-time password you retype at the next boot.enroll bashsudo mokutil --import /etc/pki/pulsar/MOK.der sudo systemctl reboot -
Answer MokManager
The next boot stops in a blue firmware screen. The sequence is:
Enroll MOK View key 0 Continue Yes password reboot Missed it? Nothing breaks; run the import again.
-
Switching, not installing? Take the NVIDIA image
Installed from the NVIDIA ISO? Skip this. Otherwise, once the key is in:
switch bashmokutil --test-key /etc/pki/pulsar/MOK.der # ...is already enrolled sudo bootc switch ghcr.io/arclight-digital/pulsar-nvidia:latest sudo systemctl reboot -
Check the driver loaded
check bashmodinfo -F signer nvidia nvidia-smi
Lost the key later?
/etc/pki/akmods/certs/public_key.der, which Pulsar keeps identical to
MOK.der. Or run the import above again.
Switch from an atomic Fedora
From Silverblue, Kinoite or another atomic Fedora 44+, switch in place. Files and accounts are kept; the old image stays in the boot menu until the next update.
sudo bootc switch \
ghcr.io/arclight-digital/pulsar:latest
sudo systemctl reboot
sudo bootc switch \
ghcr.io/arclight-digital/pulsar-nvidia:latest
sudo systemctl reboot
NVIDIA with Secure Boot on: switch to the standard image first, enroll the key it ships, then switch to NVIDIA.
When you log in
New accounts start in Pulsar’s theme with a welcome window: pick a look, learn the basics, optionally add a coding agent. Reopen it from Welcome to Pulsar in the app grid. A customized account you switched keeps its look.
Default apps (Steam, Heroic, video and music players, the GNOME set and more) install on the
first boot with a network. sudo pulsar setup apps reinstalls any that are missing.
If something looks wrong:
pulsar doctor
Troubleshooting · Where things go
Updates
New builds download in the background (on AC power and an unmetered connection) and apply at your
next restart; a notification offers a Restart button. sudo pulsar update downloads
on demand; sudo pulsar rollback returns to the previous build.
Updates and rollback.
Written with help from AI and reviewed by a person before publishing. Spotted a mistake? Let us know.