README.md
July 7, 2026 ยท View on GitHub
stereOS ๐ง
A Linux based operating system hardened and purpose-built for AI agents.
Download
|
Documentation
Mixtapes
stereOS produces machine images - called mixtapes - that bundle a hardened, minimal Linux system with specific AI agent harnesses.
| Mixtape | Agent binary | API key |
|---|---|---|
opencode-mixtape | opencode | ANTHROPIC_API_KEY or OPENAI_API_KEY |
Each mixtape appends its agent package to stereos.agent.extraPackages, which
adds the binary to the agent user's restricted PATH. The -dev variant of
each mixtape includes profiles/dev.nix for local SSH key injection.
System
The stereOS system is minimal in nature with several orchestration daemons handling agent lifecycle and acting as a control plane for agent operators:
adminuser and group for administrative operations:/home/adminagentuser and group for agent to assume:/home/agent/workspacestereosd- stereOS system daemonagentd- agent management daemon
Image formats
| Format | Build attribute | Output | Use case |
|---|---|---|---|
| Raw EFI | system.build.raw | stereos.img | Canonical artifact. Apple Virt Framework bootable |
| QCOW2 | system.build.qcow2 | stereos.qcow2 | Derived from raw via qemu-img convert. QEMU/KVM |
| Kernel artifacts | system.build.kernelArtifacts | bzImage, initrd, cmdline, init | Direct-kernel boot (bypasses UEFI/GRUB) |
| Lambda MicroVM source | packages.<system>.<mixtape>-lambda-microvm-source | Dockerfile source zip | AWS Lambda MicroVM image creation |
The Lambda MicroVM source bundle is not a full stereOS VM image. It packages stereOS userspace into a Dockerfile-based rootfs bundle because AWS Lambda MicroVM images are created from Dockerfile application sources, not custom kernel or disk artifacts.
Distribution (mkDist)
lib/dist.nix:mkDist assembles all formats into a publish-ready directory
with zstd-compressed variants (-19 -T0) and a mixtape.toml manifest
containing SHA-256 checksums and file sizes for every artifact:
result/
โโโ stereos.img # Raw EFI disk
โโโ stereos.img.zst # Zstd-compressed raw
โโโ stereos.qcow2 # QCOW2 disk
โโโ stereos.qcow2.zst # Zstd-compressed QCOW2
โโโ bzImage # Kernel
โโโ initrd # Init RAM
โโโ cmdline # Kernel command line
โโโ init # NixOS stage-2 init path
โโโ mixtape.toml # Build manifest with checksums
NixOS options
stereOS declares two custom options:
| Option | Type | Default | Description |
|---|---|---|---|
stereos.ssh.authorizedKeys | listOf str | [] | SSH public keys for admin and agent users. Useful for development purposes. |
stereos.agent.extraPackages | listOf package | [] | Packages added to the agent's restricted PATH |
External dependencies
| Flake input | Repository | Provides |
|---|---|---|
agentd | github:papercomputeco/agentd | services.agentd NixOS module + overlay |
stereosd | github:papercomputeco/stereosd | services.stereosd NixOS module + overlay |
nixpkgs | nixos-26.05 | Base packages |
dagger | github:dagger/nix | CI engine |