APEX-OS v2.0.0Before the rename

One image, encrypted by default

The installer for APEX-OS as it is today: one image for every machine, disk encryption on by default, and an installer that was installed and booted end to end from this exact ISO before it was published. Machines already running APEX-OS do not need it; sudo apex update keeps them current.

Released
Channel
installer
OS revision
5b1de3367
Shell revision
17eec38a

Highlights

SystemImproved

One image for every machine

The Daily and Gaming editions became one. The ISO installs ghcr.io/andrenijman/apex-os:apex and the machine updates from that tag.

rime-os v2.0.0rime-os #58

SecurityNew

Whole-disk encryption is on by default

Installs use LUKS2 whole-disk encryption. A recovery key is shown at the end, and Reboot stays locked until you tick that you have written it down.

The unlock prompt names your keyboard layout, and the recovery key works at that prompt too.

rime-os v2.0.0rime-os #58

SecuritySecurity

ERASE means this disk

The confirm page records each disk's serial, size and partition IDs, and the installer checks them again just before its first write. A USB drive that is unplugged or swapped during the download cannot be erased in its place.

rime-os v2.0.0rime-os #58

SecuritySecurity

The ISO installs the exact build it was tested with

The ISO downloads one pinned image, and the ISO build refuses it unless it carries the signature of APEX's own build pipeline. The first sudo apex update after installing brings the system current.

Pinned image: sha256:a754443eb15460c58e81de9198e952490c7ca55242e129b5b5952bdd05f5bcdd.

rime-os v2.0.0rime-os #58

System

  • ImprovedKeyboard and time zone come first

    You pick them before setting passwords, so passwords are typed on the layout you will use. Both carry into the installed system.

    rime-os v2.0.0rime-os #58

Security

  • ImprovedSecure Boot key enrolment is offered again

    The installer offers to enrol the Secure Boot key, so Secure Boot can be switched on later without reinstalling.

    rime-os v2.0.0rime-os #58

Fixed

  • SystemSingle-disk laptops can be installed

    With no second drive, the download is staged on the disk being installed to, never in RAM.

    rime-os v2.0.0rime-os #58

  • SystemNetwork installs no longer fail at 'Preparing the installer runtime'

    A network install could download the OS and then fail because the USB session's scratch space filled up, with no error shown. Found by installing from this ISO in a VM, fixed and re-verified before release.

    rime-os v2.0.0rime-os #58

Known issues

  • Switching to a text console restarts the installer

    Don't press Ctrl+Alt+F2 while the installer window is open: it restarts the installer from the first page. Fixed in v2.1.0.

    rime-os v2.0.0rime-os v2.1.0

  • The boot splash may not show the passphrase box

    On an encrypted install, type your passphrase and press Enter anyway, or press Esc to see the text prompt. The fix reaches installed machines through apex update.

    rime-os v2.0.0rime-os #60

  • Some networks and adapters don't work in the installer

    Captive-portal Wi-Fi and USB Wi-Fi adapters that need out-of-tree drivers don't work in the installer.

    rime-os v2.0.0

  • Tablets without a keyboard cannot finish the account page

    There is no way to complete the account page without a keyboard.

    rime-os v2.0.0

Requirements

  • A 64-bit PC with UEFI (legacy BIOS can boot the stick).
  • At least 16 GB of disk. If the target disk is the machine's only drive, it needs about 53 GB, because the download is staged on it; otherwise a second drive or USB stick with 32 GB free is used as scratch and is not erased.
  • Network during the install: Ethernet, Wi-Fi, or phone tethering.

Provenance

Release
apex-v2.0.0
Image digest
sha256:a754443eb15460c58e81de9198e952490c7ca55242e129b5b5952bdd05f5bcdd
Installer
apex-os-netinstall-x86_64.iso · 1,901,017,088 bytes
ISO SHA-256
eafe2722a568dc34af6df718402f275f39e19af46b4dab0075447537ac902dcd
Channel
installer
Released
2026-09-25T23:38:00.000Z

Published as an installer ISO on GitHub. This page explains the release; it is never consulted by an update. What a machine installs is decided by the registry and the image signature (see Security). Machine-readable: apex-v2.0.0.json.

If something is wrong

This release is an installer. If an install goes wrong, see Install and Recovery.