Download

Get Rime.

A network installer for 64-bit PCs. It downloads the signed system image while it installs. The first update afterwards needs one manual step, below.

RecommendedAPEX-OS v2.1.0 · published 26 September 2026

apex-os-netinstall-x86_64.iso

Architecture
x86_64
Size
1.90 GB (1,902,344,192 bytes)
Kind
Network installer (needs a connection)

SHA-256

7208b6fd5c2641e3e1bb035eac0d1c642f4f7eda85b1ba3295993b8ec0227248

From GitHub's own record of the file, and it matches the published .sha256.

Known issue · worked out from the source, not yet reproduced on a fresh install

The first update after installing needs a manual step.

This installer predates the rename. The update tool it installs trusts only images signed by the old apex-os build, and new images are signed by rime-os, so its first update is expected to stop at the signature check. The way through is to verify the current image yourself with cosign, switch to it once with bootc, check what was staged, and reboot. After that, sudo rime update checks every image itself.

Don't use --allow-unverified or turn the signature check off to get past it: both run parts of the old tool you don't want, or leave the check off for good. Machines already on 2026.09.28.3 or later are not affected.

Requirements

Computer
A 64-bit PC with UEFI. Legacy BIOS can also boot the stick.
Disk
At least 16 GB. If the target is the machine's only drive, about 53 GB, because the download is staged on it. Otherwise a second drive or USB stick with 32 GB free is used as scratch space and is not erased.
Network
A connection during the install.
USB stick
One that holds 1.90 GB. It is overwritten.
Secure Boot
Optional. The installer offers to enrol Rime's Secure Boot key; with Secure Boot on, the Rime kernel boots only after that key is enrolled. You can skip it and leave Secure Boot off.

Known hardware notes

  • Wi-Fi networks with a captive portal (sign-in page) don't work in the installer. Use a normal network or Ethernet.
  • USB Wi-Fi adapters that need out-of-tree drivers don't work in the installer.
  • Tablets without a keyboard can't complete the account page.
  • NVIDIA's driver is part of the image and signed with Rime's key, so it loads with Secure Boot on once that key is enrolled.
  • Xbox wireless dongles need their firmware fetched once after install; it can't be redistributed.

Check the download

Put the ISO and its checksum file in one folder and run:

sha256sum -c apex-os-netinstall-x86_64.iso.sha256

It prints apex-os-netinstall-x86_64.iso: OK. Or compare the file's SHA-256 with the one above by eye. The ISO itself carries no signature. The system image it downloads is signed, and rime update checks that signature on every update. How verification works

Install

  1. Write the ISO to a USB stick with a USB image writer. Everything on the stick is replaced.
  2. Boot from the stick from your firmware's boot menu.
  3. Follow the installer. Keyboard and time zone come first. The disk you pick is erased only after you type ERASE for that exact disk. Whole-disk encryption is on by default; write down the recovery key it shows you.
  4. Reboot, then take the first update (above).

Full install guide

Installing beside Windows: shrink Windows yourself first, then choose the installer's option to install into an existing partition. The installer does not shrink Windows for you. There is no Windows-based installer yet.

Previous installer

For recovery only. APEX-OS v2.0.0 — one image, encrypted by default, published 26 September 2026.

apex-os-netinstall-x86_64.iso · 1,901,017,088 bytes · sha256 eafe2722a568dc34af6df718402f275f39e19af46b4dab0075447537ac902dcd