DocsGetting Started
Download and verify.
Signed releases are on GitHub. Check the signature before you write the stick.
Signed releases
Signed releases are on the Releases page. Each one is built by CI from a version tag and carries:
| File | What it is |
|---|---|
agi-os-…-x86_64.iso | The Live image |
….iso.sig | OpenPGP signature of the ISO |
SHA256SUMS | Checksums, with its own .sig |
agios-release-key.asc | The public signing key |
build-info.json | Build inputs: commit, Arch snapshot, container |
Writing the stick or booting a VM is covered on the install page.
Verify before writing the stick
From a checkout of the repository:
python3 scripts/release/verify-iso.py agi-os-*.isoIt uses a temporary keyring, accepts only signatures made by the release key and compares the ISO with SHA256SUMS.
Plain gpg steps for Linux, macOS and Windows are in download and verification.
Untested builds from main
Untested builds from main are attached to Live ISO workflow runs as the agi-os-iso artifact. Downloading needs a GitHub sign-in, and artifacts are kept for 7 days. Their checksum detects a damaged download but is not a signature.