Skip to content

DocsGetting Started

Download and verify.

Signed releases are on GitHub. Check the signature before you write the stick.

Signed releases

Signed releases are on the Releases page. Each one is built by CI from a version tag and carries:

FileWhat it is
agi-os-…-x86_64.isoThe Live image
….iso.sigOpenPGP signature of the ISO
SHA256SUMSChecksums, with its own .sig
agios-release-key.ascThe public signing key
build-info.jsonBuild inputs: commit, Arch snapshot, container

Writing the stick or booting a VM is covered on the install page.

Verify before writing the stick

From a checkout of the repository:

python3 scripts/release/verify-iso.py agi-os-*.iso

It uses a temporary keyring, accepts only signatures made by the release key and compares the ISO with SHA256SUMS.

Plain gpg steps for Linux, macOS and Windows are in download and verification.

Untested builds from main

Untested builds from main are attached to Live ISO workflow runs as the agi-os-iso artifact. Downloading needs a GitHub sign-in, and artifacts are kept for 7 days. Their checksum detects a damaged download but is not a signature.