Fedora CoreOS is an appliance OS. You do not install a desktop, you do not dnf install a pile of packages, and you should not SSH in after every reboot to start DNS by hand. This repo is the config I keep next to the ISO: Butane YAML that compiles to Ignition JSON, plus Podman Quadlet units so a container is a systemd service instead of a sticky-note podman run.
I use it the way the channel uses CoreOS: a VM or an old laptop whose only job is something like AdGuard Home or Pi-hole. The machine should come up, take an SSH key, bind port 53, and stay out of the way. If you want a GUI jumphost, that is Fedora Workstation, Fedora 44 XFCE, or Silverblue — not this repo.
Why it exists
CoreOS without Ignition is a live USB and a lot of hope. The installer wants a provision file. Writing that YAML from memory every time I spin a lab VM is how you forget to disable systemd-resolved’s stub listener, then wonder why AdGuard cannot bind :53. The templates in this repo are the versions I have already fought with on camera.
There are two starting points today:
Basic.bu—coreuser, SSH public key, nothing else. Use this when the appliance job is still undecided or you want to add Quadlets after first boot.AdGuardHomeQuadlet.bu— data directories under/var, resolved stub disabled, AdGuard Home as a rootless Quadlet on the host network. First boot already has DNS if the Ignition file was served correctly.
I add configs as the videos need them. Pi-hole as a Quadlet is documented on the blog even when the matching .bu is not in the repo yet; copy the unit into Butane storage.files the same way the AdGuard example does.
How it fits the rest of the site
The long-form install is Beginner’s Guide to Fedora CoreOS (with Bitwarden SSH Keys): generate an SSH key in Bitwarden, write Butane, convert to Ignition, share it with the installer, deploy AdGuard. After the box is up, the narrow posts are AdGuard Home as a Quadlet and Pi-hole as a Quadlet. Nightly host reboots (optional, not a security strategy by themselves) are systemd timers on CoreOS.
This GitHub repo is the files. The blog is the why and the failure modes. Use both.
How to try it
- Clone the repo and pick a
.bufile. Put your SSH public key inpasswd.users— leave the example key in place and you will lock yourself out. - Convert Butane to Ignition with the official container (do not invent a local
butanebinary unless you already maintain one):
git clone https://github.com/TheLinuxITGuy/CoreOS.git
cd CoreOS
podman run -i --rm quay.io/coreos/butane:release --strict < AdGuardHomeQuadlet.bu > adguard.ign
- Serve or attach that
.ignthe way the CoreOS installer expects for your path (HTTP on the LAN,coreos-installerwith--ignition-url/--ignition-file, or whatever the current bare-metal docs say for your stream). - Install Fedora CoreOS from the official bare-metal ISO. First boot: SSH as
core. For AdGuard, confirm port 53 and the web UI before you point DHCP at the box. - Give the appliance a static IP. DHCP that changes overnight makes every client’s DNS setting wrong. The blog examples use a LAN address; use yours.
Video companion: Fedora CoreOS + Bitwarden + AdGuard on YouTube.
What this is not
It is not a Kubernetes cluster, not OpenShift, and not a replacement for Rocky Scripts on a workstation. Do not put Hyprland on CoreOS. Do not run two resolvers (Pi-hole and AdGuard) on the same IP and port 53. If you need a WAF, that is a different machine and a different post (SafeLine).
Repo
Full templates and updates: github.com/TheLinuxITGuy/CoreOS.