Skip to content
SCBuergelPublic

About

Seb's QubesOS scripts

Resources

Stars

6 stars

Watchers

1 watching

Forks

Repository files navigation

Seb's QubesOS Scripts (SEQS)

SEQS turns a Qubes OS installation into a configurable set of purpose-specific security domains for browsing, chat, wallets, development, offline storage, and controlled data transfer. It creates a separate Z-* TemplateVM and A-* AppVM for each selected workload, keeping unrelated tools and data out of the same qube while making the resulting layout reproducible from one reviewed configuration.

Warning: SEQS installs Qubes Salt code that runs as root in dom0. A malicious checkout can compromise the whole machine. Install only a commit published through an independent channel by a reviewer you trust. The commit-bound export prevents working-tree drift, but dom0 does not verify Git: the repository qube remains trusted. See TRUST.md.

Install (for users)

  1. Install and verify Qubes OS, update it, and reboot.

  2. In a fresh networked Debian DisposableVM, clone SEQS:

    git clone https://github.com/SCBuergel/SEQS.git

    Before installing, follow the checkout and commit verification in the full first-install walkthrough.

  3. Copy the checked-out runner into dom0 and install in one step. Replace both disp1234 occurrences with the disposable's name, and pick the qubes you want:

    qvm-run -p disp1234 'cd SEQS && git show HEAD:setup-qubes.sh' > ~/s.sh && chmod 700 ~/s.sh
    ~/s.sh --repo-vm disp1234 --qubes brave,signal,keepass

    Use --all instead of --qubes for the full catalogue.

Do not put secrets into the resulting qubes until completing the post-install checks in VERIFY-HUMAN.md. Already installed SEQS? Use docs/upgrading.md; do not reinstall Qubes.

Reviewers

If you are the one auditing SEQS and publishing an authoritative commit hash for others (or you want to audit before trusting anyone else's), do not stop at the hash — read the code that will run as root in dom0: VERIFY-HUMAN.md is the structured review walkthrough (including the rules for using an LLM to assist the audit), and TRUST.md explains what remains trusted. The full first-install walkthrough covers the fetch → stage → build stages in detail and the separate --fetch-only / --stage-only / --build-only commands for pausing between them.

Documentation

Need Read
Full first-install walkthrough docs/first-install.md
Verify Qubes ISO and install Qubes docs/install-qubes.md
Review what SEQS runs VERIFY-HUMAN.md
Understand trust and residual risk TRUST.md
Understand the runner and dom0 data flow docs/architecture.md
Select available qubes or customize their definitions docs/configuration.md
Configure and use the WireGuard NetVM docs/wireguard.md
Configure and verify the GnosisVPN NetVM docs/gnosisvpn.md
Upgrade an existing installation docs/upgrading.md
Delete or rebuild managed qubes docs/deleting-vms.md
Configure secure QR transfer docs/secure-qr-transfer.md
Use additional recipes docs/recipes.md
Run repository tests test/README.md

About

Seb's QubesOS scripts

Resources

Stars

6 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages