Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

AgentOS

An Ubuntu-based operating system purpose-built for AI automation. Ships with OpenClaw as a first-class system service, hardened security defaults, and a setup wizard that gets you to a working AI agent in under 5 minutes.

What is this?

AgentOS is a pre-configured VM image (OVA/QCOW2) that turns any virtualization platform into a dedicated AI agent appliance. Boot it up, connect your LLM provider, pair a messaging channel, and you have an always-on AI assistant running in a secure, isolated environment.

This is not "Ubuntu with OpenClaw installed." It's an opinionated, security-hardened environment where:

  • The agent runs as a dedicated system user with no root access
  • Every agent action is logged to an audit trail
  • AppArmor profiles restrict what the agent process can touch
  • Credentials are stored in a vault the agent process cannot read directly
  • A setup wizard handles first-run configuration (model provider, channels, skills)

Target users

EditionWho it's forWhat ships
Lite (this repo)Anyone who wants an AI agent applianceGNOME desktop + OpenClaw + setup wizard
Server (this repo)Headless / cloud deploymentsMinimal + systemd gateway + cloud-init
Dev (planned)Agent developersCLI-first + SDK + local model runtime

Quick start

Option 1: VirtualBox / UTM / VMware (Lite edition)

# Download the latest OVA
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-lite.ova
# Import into VirtualBox
VBoxManage import agentos-lite.ova
VBoxManage startvm agentos-lite

Option 2: QEMU/KVM headless (Server edition)

# Download the server QCOW2
curl -LO https://github.com/SecureAgentOS/agentos/releases/latest/download/agentos-server.qcow2
# Configure the agent before first boot
cat > /tmp/setup.conf <<'EOF'AGENTOS_PROVIDER=anthropicAGENTOS_API_KEY=sk-ant-...AGENTOS_AGENT_NAME=AtlasAGENTOS_CHANNEL=skipEOF# Boot with serial console
qemu-system-x86_64 -hda agentos-server.qcow2 -m 2048 -enable-kvm \
-nographic -serial mon:stdio

Option 3: Build from scratch

git clone https://github.com/SecureAgentOS/agentos.git
cd agentos
make validate # Check config before building
make build # Build the Lite edition (requires Ubuntu 24.04 + sudo)
make build-server # Build the Server edition

The build script requires Ubuntu 24.04 as the host (or any Debian-based system with debootstrap).

Architecture

┌─────────────────────────────────────────────┐
│ Setup Wizard / Welcome App │
├─────────────────────────────────────────────┤
│ OpenClaw Gateway (systemd service) │
│ ├── Skill marketplace │
│ ├── MCP server hub │
│ └── Sandbox / permissions │
├─────────────────────────────────────────────┤
│ Security layer │
│ ├── AppArmor profiles │
│ ├── Credential vault │
│ └── Audit logging │
├─────────────────────────────────────────────┤
│ Ubuntu 24.04 LTS (Noble Numbat) │
│ Node.js 22 · Docker · GNOME (Lite only) │
└─────────────────────────────────────────────┘

Build requirements

  • Ubuntu 24.04 host (for debootstrap compatibility)
  • 20GB free disk space
  • sudo access
  • Internet connection (to pull packages)

Project structure

agentos/
├── scripts/
│ ├── build-vm.sh # Main build orchestrator
│ ├── 01-bootstrap.sh # debootstrap base system
│ ├── 02-install-deps.sh # Node.js, Docker, OpenClaw
│ ├── 03-configure.sh # systemd units, AppArmor, users
│ ├── 04-desktop.sh # GNOME + branding (Lite only)
│ ├── 05-wizard.sh # First-run setup wizard
│ ├── 06-package.sh # Export as OVA/QCOW2
│ ├── validate.sh # Pre-build validation checks
│ └── smoke-test.sh # Post-build rootfs verification
├── config/
│ ├── apparmor/
│ │ ├── agentos-openclaw # AppArmor profile for OpenClaw agent
│ │ └── agentos-broker # AppArmor profile for credential broker
│ ├── systemd/
│ │ ├── agentos-gateway.service
│ │ └── agentos-broker.service
│ ├── audit/
│ │ └── agentos.rules # auditd rules for agent activity
│ ├── logrotate/
│ │ └── agentos # Log rotation policy
│ ├── channels/
│ │ ├── telegram.example.json # Telegram channel template
│ │ ├── discord.example.json # Discord channel template
│ │ └── slack.example.json # Slack channel template
│ └── openclaw/
│ ├── openclaw.defaults.json # Default agent config
│ └── env.template # Environment variable template
├── Makefile # Build convenience targets
├── branding/
│ ├── plymouth/ # Boot splash theme + asset generator
│ ├── grub/ # Bootloader theme + asset generator
│ ├── wallpapers/ # Desktop wallpapers (light + dark SVG)
│ ├── icons/ # App icon, favicon (SVG)
│ └── welcome/ # HTML welcome app (getting started guide)
├── docs/ # User-facing documentation
└── README.md

Server edition

The Server edition is a headless, cloud-ready variant — no GNOME desktop, no Plymouth splash, no Chromium. It's designed for always-on deployments on VMs, VPS, or cloud instances.

Key differences from Lite:

FeatureLiteServer
Desktop (GNOME)YesNo
Gateway bind127.0.0.10.0.0.0
Execution policyaskauto
Setup wizardInteractive TUIConfig-file / cloud-init
Serial consoleNoYes (ttyS0,115200)
Cloud imageNo.raw.gz (AWS/GCP/Azure)
Health endpointNoPort 8080
ChromiumYesNo
cloud-initNoYes

Non-interactive setup: Place /etc/agentos/setup.conf on the VM before first boot (or via cloud-init user-data):

AGENTOS_PROVIDER=anthropic
AGENTOS_API_KEY=sk-ant-...
AGENTOS_AGENT_NAME=Atlas
AGENTOS_CHANNEL=skip

The setup service runs on first boot, reads the config, and marks setup complete. On subsequent boots it is a no-op.

Health check:curl http://<vm-ip>:8080 returns 200 OK when the gateway is running, 503 DOWN otherwise. Use this for load balancer health checks.

Security model

AgentOS follows the principle of least privilege for autonomous agents:

  1. Dedicated user: OpenClaw runs as agentos (uid 1100), not root
  2. AppArmor confinement: The agent process can only access its workspace, not system files
  3. Credential isolation: API keys live in /etc/agentos/vault/ owned by root; the agent requests tokens through a broker service
  4. Audit trail: Every shell command, file write, and network request is logged to /var/log/agentos/audit.log
  5. Docker sandboxing: Skills that need shell access run inside ephemeral containers

Roadmap

  • Project scaffold and build scripts
  • Phase 1: Bootable VM image with OpenClaw pre-configured
  • Phase 2: AppArmor + credential vault + audit logging
  • Phase 3: First-run setup wizard with channel pairing
  • Phase 4: Branding (Plymouth, GRUB, wallpaper, welcome app)
  • Phase 5: Server edition (headless, cloud-ready, non-interactive setup)
  • Phase 6: Dev edition (SDK, local model support)
  • Future: Bootable ISO for bare-metal installation

Contributing

This project is in early development. Issues and PRs welcome.

License

MIT

About

Ubuntu-based OS purpose-built for AI automation. Hardened security defaults, OpenClaw as a system service, and a setup wizard.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages