Skip to content PULSAR
Docs Install
DocsThemesReleases Install Source on GitHub
Docs Where things go

Where things go

The system is one image that updates as a whole. Software goes in one of four places, by what it is.

Where does it go?

You wantIt goes inHow
An app with a windowFlatpakGNOME Software, or flatpak install --user
A compiler, SDK, language runtimeA toolboxtoolbox create, then dnf inside it
A per-project toolchainmise and direnvon the host already, installing into $HOME
A server or background serviceA quadletpulsar setup quadlet
A local model, anything CUDAA GPU containerpodman run --device nvidia.com/gpu=all
A kernel module, udev rule, host daemonLayered on the hostsudo rpm-ostree install, as a last resort

Apps: Flatpak

Desktop apps come as Flatpaks. GNOME Software can reach all of Flathub, unfiltered, plus Fedora’s own collection. First boot installs Steam, Heroic, Faugus, Bottles, ProtonPlus, protontricks, OBS Studio, Discord, EasyEffects, virt-manager, Flatseal, the Showtime video player, the Decibels music player and the GNOME set. An app you remove stays removed.

--user installs for your account only and needs no password. A system install (GNOME Software’s default) is shared by all accounts.

Dev tools: a toolbox

Compilers, SDKs and runtimes go in a toolbox, a Fedora container that shares your home folder. sudo dnf install inside it changes only the box.

A ready box with git, gcc, cmake, gdb, make, ripgrep, jq and Python headers:

It is a distrobox, so toolbox list doesn’t show it. The recipe is /usr/share/pulsar/distrobox.ini.

For per-project toolchains, mise and direnv are on the host and install into $HOME:

bpftrace, bcc-tools, perf and sysstat are on the host because they probe its kernel.

Services: quadlets

A long-running container is a quadlet, a unit file systemd runs as a rootless service. The template:

  • myapp.container becomes myapp.service.
  • podman-auto-update.timer updates containers labeled AutoUpdate=. The template is labeled.
  • Mount host paths with :Z. Without it, SELinux denies them.

Containers that need the GPU: GPU containers.

Layering, the last resort

Layer a package onto the host only when it can’t run in a container, such as a kernel module, udev rule or host daemon:

A layered package applies at the next boot and stays through updates. Those then take minutes instead of seconds. pulsar update handles it, and pulsar doctor counts your layers. Never layer dev tools.

What not to do

  • Installing anything into /usr/local or /opt (sudo make install, a vendor’s install.sh). It shadows the image on PATH and survives every update and rollback. rpm-ostree status doesn’t list it. Use a toolbox, mise or ~/.local/bin.
  • sudo pip install or sudo npm install -g on the host. It either fails, because /usr is read-only, or lands in /usr/local, where no update or rollback will ever touch it. Use a venv or a toolbox.
  • Editing /etc to fix something the image ships. The edit outlives updates and hides the real fix. If you must, take a checkpoint first.

The filesystem

PathWhat it is
/usrThe OS image. Read-only, even for root. Every update replaces it whole.
/etcWritable and local to this machine. Each deployment keeps its own copy. Updates merge your edits forward.
/varWritable, persistent, shared by every deployment. /home is /var/home.
/usr/local, /optLinks into /var. Not part of the image. No update or rollback ever cleans them.
$HOMEYours. Nothing on the system rolls it back.

Written with help from AI and reviewed by a person before publishing. Spotted a mistake? Let us know.

PULSAR

Your lighthouse in the sky.

Site

Machine

Arclight

Theme

Dark only Light only

Recolors the whole site, like pulsar theme set does your desktop.

Light and dark

One look picks light or dark for you

Saved in this browser Back to Pulsar