SEQS turns a
Qubes OS installation into a configurable set of
purpose-specific security domains for browsing, chat, wallets, development,
offline storage, and controlled data transfer. It creates a separate Z-*
TemplateVM and A-* AppVM for each selected workload, keeping unrelated tools
and data out of the same qube while making the resulting layout reproducible
from one reviewed configuration.
Warning: SEQS installs Qubes Salt code that runs as root in dom0. A malicious checkout can compromise the whole machine. Install only a commit published through an independent channel by a reviewer you trust. The commit-bound export prevents working-tree drift, but dom0 does not verify Git: the repository qube remains trusted. See TRUST.md.
-
Install and verify Qubes OS, update it, and reboot.
-
In a fresh networked Debian DisposableVM, clone SEQS:
git clone https://github.com/SCBuergel/SEQS.git
Before installing, follow the checkout and commit verification in the full first-install walkthrough.
-
Copy the checked-out runner into dom0 and install in one step. Replace both
disp1234occurrences with the disposable's name, and pick the qubes you want:qvm-run -p disp1234 'cd SEQS && git show HEAD:setup-qubes.sh' > ~/s.sh && chmod 700 ~/s.sh ~/s.sh --repo-vm disp1234 --qubes brave,signal,keepass
Use
--allinstead of--qubesfor the full catalogue.
Do not put secrets into the resulting qubes until completing the post-install checks in VERIFY-HUMAN.md. Already installed SEQS? Use docs/upgrading.md; do not reinstall Qubes.
If you are the one auditing SEQS and publishing an authoritative commit hash
for others (or you want to audit before trusting anyone else's), do not stop at
the hash — read the code that will run as root in dom0:
VERIFY-HUMAN.md is the structured review walkthrough
(including the rules for using an LLM to assist the audit), and
TRUST.md explains what remains trusted. The
full first-install walkthrough covers the fetch → stage
→ build stages in detail and the separate --fetch-only / --stage-only /
--build-only commands for pausing between them.
| Need | Read |
|---|---|
| Full first-install walkthrough | docs/first-install.md |
| Verify Qubes ISO and install Qubes | docs/install-qubes.md |
| Review what SEQS runs | VERIFY-HUMAN.md |
| Understand trust and residual risk | TRUST.md |
| Understand the runner and dom0 data flow | docs/architecture.md |
| Select available qubes or customize their definitions | docs/configuration.md |
| Configure and use the WireGuard NetVM | docs/wireguard.md |
| Configure and verify the GnosisVPN NetVM | docs/gnosisvpn.md |
| Upgrade an existing installation | docs/upgrading.md |
| Delete or rebuild managed qubes | docs/deleting-vms.md |
| Configure secure QR transfer | docs/secure-qr-transfer.md |
| Use additional recipes | docs/recipes.md |
| Run repository tests | test/README.md |