Fedora CoreOS is an appliance OS. You do not install a desktop, you do not dnf install a pile of packages, and you should not SSH in after every reboot to start DNS by hand. This repo is the config I keep next to the ISO: Butane YAML that compiles to Ignition JSON, plus Podman Quadlet units so a container is a systemd service instead of a sticky-note podman run.

I use it the way the channel uses CoreOS: a VM or an old laptop whose only job is something like AdGuard Home or Pi-hole. The machine should come up, take an SSH key, bind port 53, and stay out of the way. If you want a GUI jumphost, that is Fedora Workstation, Fedora 44 XFCE, or Silverblue — not this repo.

Why it exists

CoreOS without Ignition is a live USB and a lot of hope. The installer wants a provision file. Writing that YAML from memory every time I spin a lab VM is how you forget to disable systemd-resolved’s stub listener, then wonder why AdGuard cannot bind :53. The templates in this repo are the versions I have already fought with on camera.

There are two starting points today:

  • Basic.bu — core user, SSH public key, nothing else. Use this when the appliance job is still undecided or you want to add Quadlets after first boot.
  • AdGuardHomeQuadlet.bu — data directories under /var, resolved stub disabled, AdGuard Home as a rootless Quadlet on the host network. First boot already has DNS if the Ignition file was served correctly.

I add configs as the videos need them. Pi-hole as a Quadlet is documented on the blog even when the matching .bu is not in the repo yet; copy the unit into Butane storage.files the same way the AdGuard example does.

How it fits the rest of the site

The long-form install is Beginner’s Guide to Fedora CoreOS (with Bitwarden SSH Keys): generate an SSH key in Bitwarden, write Butane, convert to Ignition, share it with the installer, deploy AdGuard. After the box is up, the narrow posts are AdGuard Home as a Quadlet and Pi-hole as a Quadlet. Nightly host reboots (optional, not a security strategy by themselves) are systemd timers on CoreOS.

This GitHub repo is the files. The blog is the why and the failure modes. Use both.

How to try it

  1. Clone the repo and pick a .bu file. Put your SSH public key in passwd.users — leave the example key in place and you will lock yourself out.
  2. Convert Butane to Ignition with the official container (do not invent a local butane binary unless you already maintain one):
git clone https://github.com/TheLinuxITGuy/CoreOS.git
cd CoreOS
podman run -i --rm quay.io/coreos/butane:release --strict < AdGuardHomeQuadlet.bu > adguard.ign
  1. Serve or attach that .ign the way the CoreOS installer expects for your path (HTTP on the LAN, coreos-installer with --ignition-url / --ignition-file, or whatever the current bare-metal docs say for your stream).
  2. Install Fedora CoreOS from the official bare-metal ISO. First boot: SSH as core. For AdGuard, confirm port 53 and the web UI before you point DHCP at the box.
  3. Give the appliance a static IP. DHCP that changes overnight makes every client’s DNS setting wrong. The blog examples use a LAN address; use yours.

Video companion: Fedora CoreOS + Bitwarden + AdGuard on YouTube.

What this is not

It is not a Kubernetes cluster, not OpenShift, and not a replacement for Rocky Scripts on a workstation. Do not put Hyprland on CoreOS. Do not run two resolvers (Pi-hole and AdGuard) on the same IP and port 53. If you need a WAF, that is a different machine and a different post (SafeLine).

Repo

Full templates and updates: github.com/TheLinuxITGuy/CoreOS.