Hello, I am looking for a well-supported Linux / BSD distribution with focus on following features (in no particular order) -
- Systemd free (found some here)
- Security focused (meaning hardened, not security tools)
- Wayland (preferably without anything X11)
- Lightweight (as much as possible)
- Supports flatpak, containers and VMs (preferably libvirt)
- Atomic (more optional then other requirements)
This is expected to be run on real hardware on desktop (so alpine will not work).
Along with that, what are some good lightweight (but well-known / actively maintained) desktop environments for Wayland?
- I see some here but am looking for opinions or if some are missing.
- Especially ones that support stacking.
The most interesting ones I could find -
- Void Linux (has some X11 stuff, not security focused, will try installing Wayland)
- Kicksecure, OpenBSD, HardenedBSD (yet to explore more for these)
- MXLinux and Artix (seem very niche)?
I am looking for more recommendations/opinions for similar requirements, especially if there are better known ones.
Why not systemd? You seem to want futuristic and secure things like Wayland and flatpak, yet don’t want the security benefits of systemd?
Probably because of its compliance with age verification standardization.
You mean the change that was writen as an act of malicious compliance, by someone opposed to age verification laws, in such a way as to make an easy end run around them for all Linux developers, but then everyone went off half-cocked and started sending the author death threats? That compliance?
Dominik sees practical, non-surveillance uses for the field, like tailoring workshop laptops to age-appropriate defaults without restricting access to anything.
No one deserves death threats, but per the quote above, the existence of the setting still encourages distributions to ask for the user’s age at setup, as apps may require the setting to be enabled to know how to handle the user’s data and which experience is best suited for them.
While this may automate the parental control process for parents, many users don’t want their data used by software in ways they don’t consent to, even if it doesn’t leave the device.
Thats kinda the point of the malicious compliance though. It’s an optional field. By default, distros can choose to ignore it or auto fill in 1900-01-01. In places where it’s required by law, adduser can ask and it will accept anything. The same way adduser currently asks for your real name, phone numbers, and room number but does not give a fuck what they are or if you fill them out.
The parental controls issue is actually a bigger deal. I would love to give my kids a Linux laptop that could actually protect their privacy while also giving me good parental control tool, but such a thing does not exists. Yes, if you do a quick search for “Linux parental controls” you’ll find some things, but they are clearly half-assed attempts that don’t really work. This absolutely doesn’t either but maybe it’s a step in that direction. Instead, I do what most schools and parents do and give them a Chromebook because it has a good, though not great, parental control system.
Let me be clear, I am also opposed to age verification laws and have written, called and had meetings with my representatives to oppose them. It’s been somewhat successful, though not as much as I would like.
In the end, malicious compliance that allows FOSS developers plausible deniability is better than ignoring the laws and hoping that you’re not the one they decide to make an example of.
Or the other issues listed at the site posted by the OP: https://nosystemd.org/
Will we ever get to the point where we are too tired to explain why we hate systemd, and the point where we get respect for deciding to not use systemd? To me it’s about the same level of asking me “why be a lesbian” now.
“Ok grandpa let’s get you to bed”
OpenBSD
hardened
This is an important keyword but perhaps not sufficiently discussed. I’d reckon focusing on it will be pretty helpful.
So…, what is it you want? Is it
- A. Make a fortress out of a very decent starting point? To daily drive it afterwards*.
- Or B. Daily drive a fortress built by someone else?
- Or perhaps even C. Something else entirely?
By the rest of your post, I’d bet on B. Which, puts us into an interesting situation…
systemd free
Assuming[1] DistroWatch does a decent job at tagging/categorizing, there are only a handful of distros that are both systemd-free and tagged with “security”. Note that half of these don’t survive it upon closer inspection, which leaves us with Alpine, HardenedBSD and OpenBSD.
If you’re well-versed into hardened distros, you’ll note the absence of Linux’ finest in this category; namely Kicksecure and secureblue. Their absence is due to their (heavy) reliance on systemd for additional hardening.
Furthermore, note that DistroWatch doesn’t mention how well the likes of Artix, Gentoo and Void (among others) would function as excellent starting points to build your own fortress from.
To be honest, I don’t see any reason to not grant them the benefit of doubt. As far as I can tell, their lists look complete. ↩︎
Wtf so you mean Alpine will not work on real hardware on desktop? I run Alpine on real hardware for a desktop. The only issue you’ll run into is video games not playing nicely with musl, but there’s compatibility layers you can use for that.
Void works fine with Wayland. It isn’t security-focused. Same goes for Artix.
OpenBSD is security-focused, but has limited Wayland support. Sway works on it, but there isn’t much Wayland software, and it’s missing some crucial things like xdg-desktop-portal.
Gentoo might be what you’re looking for.
You might be able to build your own image with Universal Blue
Open BSD, except it doesn’t support flat pack. But it’s everything else you want
But, I wouldn’t recommend using it as a desktop. If you want real security and isolation, look at qubes for your desktop.
Qubes uses xen, a real microkernel, as the hypervisor, which reduces the risk surface of VM escapes tremendously, then you run your untrusted services in their own vms.
Artix is great if you don’t mind Arch. Devuan is great if you like lightweight Debian (server install). MXLinux is nice if you want Debian with a usability/UI focus. As for security focused, I don’t know what that means. A machine is either secure or it’s not. Chuck SELinux on there if it helps you sleep at night.
I’m using artix with cosmic desktop. It’s light enough for my 15 year old laptop. I haven’t tried it yet, but Chimera Linux seems to fit what you’re looking for.





