Debian · mkosi · bootc or A/B root

Keep the system
boring. Make the work interesting.

Frostyard images are atomic, updateable operating systems for desktops and servers. A known-good base stays put; your tools arrive as deliberate layers.

01

Atomic by default

Update the whole operating system as a coherent image. Reboot into the new deployment; keep the previous one available.

02

Mutable where it counts

Your data, configuration, containers, and projects live in persistent writable storage. The operating system does not get in their way.

03

Tools without drift

Add capabilities as system extensions, containers, or user-space package environments instead of turning the base into a snowball.

Three base images

Choose the terrain.
The foundation is shared.

Each image starts from the same reproducible Debian base and takes a clear role from there.

How the images relateOne shared base. One desktop variation. Optional layers for every image.
Frostyard image compositionThe shared base image branches to the Cayo server and Snow desktop. Snow leads to the Snowfield Surface desktop. System extensions add optional capabilities to each image. SHARED FOUNDATIONshared basesystem · boot · tools SERVER IMAGEcayoheadless · containers DESKTOP IMAGEsnowGNOME · backports kernel SURFACE DESKTOPsnowfieldSnow · linux-surface kernel SYSEXT LAYERoptional capabilities for any image · Incus · Docker · Podman · dev tools · apps
Desktop01

snow

A GNOME workstation that stays composed.

A daily desktop built on Debian Trixie with a current backports kernel, atomic OS updates, and room for real work.

GNOMEBackports kernelAtomic updates
Surface02

snowfield

Snow, tuned for Surface hardware.

The Snow desktop with linux-surface and the hardware support that makes a tablet or laptop feel like a first-class machine.

GNOMElinux-surfaceTouch-ready
Server03

cayo

A quiet base for services and containers.

A headless image for servers, labs, and small infrastructure. Podman is ready; the host stays deliberately uninteresting.

HeadlessContainersVirtualization

System extensions

More capability.
No base-image sprawl.

Sysexts are versioned, removable overlays for the parts of your system that deserve their own lifecycle.

20

published extensions
in the live catalog

View repository index ↗

Workstation

1Password desktopv8.12.28Bitwardenv2026.6.1Claude Desktopv1.22209.0Microsoft Edgev150.0.4078.83-1+r1Visual Studio Codev1.129.1-1784303641

Development

Development toolsv12.12Debian developmentv1.0.141Nixv2.26.3+dfsg-1Podman + Distroboxv5.4.2+ds1-2+b2Docker CEv5+29.3.0-1~debian.13~trixie

Infrastructure

Tailscalev1.98.9Azure VPNv3.0.0Incusv1+6.22-debian13-202602280500Coderv2.35.1-1code-serverv4.121.0Lemonadev10.10.0~13

Also published

1Password CLIv2.33.1-1Emdashv0.4.39Himmelblauv4.0.0-debian13pilothousev0.5.1

The practical model

Install software
at the right altitude.

Immutability is not a prohibition. It is a boundary that makes each choice easier to reverse and reason about.

01

System extension

For a tool that belongs close to the OS: VPNs, IDEs, container runtimes, and services.

02

Container or Distrobox

For development stacks and workloads that should bring their own userspace.

03

User-space environment

For personal tooling with Nix, Homebrew, Flatpak, or a project-local runtime.

No magic, just composition

Built in the open
with mkosi.

Cayo, Snow, and Snowfield share one definition, then branch only where purpose demands: packages, kernel, and configuration.

Inspect snosi