fungOS
Download Markdown

Profiles and deployment boundaries

Profiles derive Debian package sets from named capability declarations. They describe runtime prerequisites, not an application bundle, a placement grant or a complete bootable image.

Profile matrix

ProfileDeclared capabilitiesIntended useDoes not include
baseCore, networkd, SSH, first contact, signed-update verificationSmall provisionable nodeApplication executables, identity or board firmware
edgeBase plus edge runtime and Canvas display dependenciesNative visual edgeAutomatically authorized devices or a preconfigured production seat
headless-edgeBase plus edge runtimeMessaging/services without a local desktopCanvas display runtime
cloudBase plus cloud runtimeWorkload substrate prerequisitesEdge display packages or a required GPU

Both amd64 and arm64 are declared targets. Architecture support for a rootfs does not prove that a particular board boots or that an application supports its accelerator.

Selecting and inspecting

./base/scripts/check.sh
sudo ./base/scripts/build.sh amd64 edge
sudo ./base/scripts/inspect.sh base/out/fungos-edge-amd64.tar

Inspect the resolved package list and manifest before provisioning. The current source-of-truth files are base/profiles/*.capabilities and base/capabilities/*.packages. A derived website table is a reviewed explanation of those files, not a second installer.

Runtime dependencies versus applications

Canvas, Unibus, Mycelium and UMIE remain independent owners. A profile can supply their runtime libraries; their signed executables, trust configuration, data and service policy arrive separately. GPU observation may inform eligibility but cannot grant a workload role or permission to execute.

Keep one activation owner per executable. APT and native package activation must not race to manage the same application. Choose the owner explicitly and retain its recovery path.

Security boundaries

  • First-contact and update-verifier adapters use an exact single-adapter contract.
  • Enrollment claims are private, short-lived and machine-specific; generic images must not carry them.
  • Discovery establishes facts about available resources, not authority to place workloads or control peripherals.
  • A role or signed placement policy is separate from the machine's hardware capabilities.
  • Generated distributions contain separately licensed software; the complete image is not uniformly MIT/Apache.

Current qualification

The public owner documents persistent amd64 QEMU edge operation and isolated visual rollback. The generic builder itself is not an installer. Pi, cloud disk assembly, encrypted-root unlock, whole-set atomic updates and accelerator-specific model qualification have independent evidence requirements.

Follow installation, Pi status or update qualification. Reviewed sources: public fungOS README.md, base/profiles/, base/capabilities/, THIRD-PARTY.md.