APEX-OS v2.0.0Before the rename
One image, encrypted by default
The installer for APEX-OS as it is today: one image for every machine, disk encryption on by default, and an installer that was installed and booted end to end from this exact ISO before it was published. Machines already running APEX-OS do not need it; sudo apex update keeps them current.
Highlights
One image for every machine
The Daily and Gaming editions became one. The ISO installs ghcr.io/andrenijman/apex-os:apex and the machine updates from that tag.
Whole-disk encryption is on by default
Installs use LUKS2 whole-disk encryption. A recovery key is shown at the end, and Reboot stays locked until you tick that you have written it down.
The unlock prompt names your keyboard layout, and the recovery key works at that prompt too.
ERASE means this disk
The confirm page records each disk's serial, size and partition IDs, and the installer checks them again just before its first write. A USB drive that is unplugged or swapped during the download cannot be erased in its place.
The ISO installs the exact build it was tested with
The ISO downloads one pinned image, and the ISO build refuses it unless it carries the signature of APEX's own build pipeline. The first sudo apex update after installing brings the system current.
Pinned image: sha256:a754443eb15460c58e81de9198e952490c7ca55242e129b5b5952bdd05f5bcdd.
System
ImprovedKeyboard and time zone come first
You pick them before setting passwords, so passwords are typed on the layout you will use. Both carry into the installed system.
Security
ImprovedSecure Boot key enrolment is offered again
The installer offers to enrol the Secure Boot key, so Secure Boot can be switched on later without reinstalling.
Fixed
SystemSingle-disk laptops can be installed
With no second drive, the download is staged on the disk being installed to, never in RAM.
SystemNetwork installs no longer fail at 'Preparing the installer runtime'
A network install could download the OS and then fail because the USB session's scratch space filled up, with no error shown. Found by installing from this ISO in a VM, fixed and re-verified before release.
Known issues
Switching to a text console restarts the installer
Don't press Ctrl+Alt+F2 while the installer window is open: it restarts the installer from the first page. Fixed in v2.1.0.
The boot splash may not show the passphrase box
On an encrypted install, type your passphrase and press Enter anyway, or press Esc to see the text prompt. The fix reaches installed machines through
apex update.Some networks and adapters don't work in the installer
Captive-portal Wi-Fi and USB Wi-Fi adapters that need out-of-tree drivers don't work in the installer.
Tablets without a keyboard cannot finish the account page
There is no way to complete the account page without a keyboard.
Requirements
- A 64-bit PC with UEFI (legacy BIOS can boot the stick).
- At least 16 GB of disk. If the target disk is the machine's only drive, it needs about 53 GB, because the download is staged on it; otherwise a second drive or USB stick with 32 GB free is used as scratch and is not erased.
- Network during the install: Ethernet, Wi-Fi, or phone tethering.
Provenance
- Release
- apex-v2.0.0
- OS revision
- 5b1de336765929f926af51151c78ba1e695ec9c1
- Shell revision
- 17eec38acd4823785329060b98f51ee605da2c2d
- Image digest
- sha256:a754443eb15460c58e81de9198e952490c7ca55242e129b5b5952bdd05f5bcdd
- Installer
- apex-os-netinstall-x86_64.iso · 1,901,017,088 bytes
- ISO SHA-256
- eafe2722a568dc34af6df718402f275f39e19af46b4dab0075447537ac902dcd
- Channel
- installer
- Released
- 2026-09-25T23:38:00.000Z
Published as an installer ISO on GitHub. This page explains the release; it is never consulted by an update. What a machine installs is decided by the registry and the image signature (see Security). Machine-readable: apex-v2.0.0.json.
If something is wrong
This release is an installer. If an install goes wrong, see Install and Recovery.