Setup that needs you
Based sets up everything it can from packages. What's left needs something only you can give: a
sign-in, a finger or a security key, or a choice about your own machine. Each one is a row in the
Omarchy menu, Super+Space on both editions or the tray icon on Workstation, and most can be undone
under Remove.
| what | where | what it does |
|---|---|---|
| fingerprint | Setup, then Security, then Fingerprint, where the machine has a reader | enrolls your finger for sudo, password prompts and the lock screen. With the lid shut it asks for the password instead |
| security key | Setup, then Security, then Fido2 | registers a FIDO2 key for sudo and password prompts. It can't unlock the screen |
| SSH server | Setup, then Security, then SSHD | installs and starts OpenSSH, opens port 22 in the firewall with a rate limit, and authorizes a key from GitHub or one you paste |
| Docker without sudo | Setup, then Security, then Sudoless Docker | adds you to docker after a warning, since that group is root without a password. It takes a reboot |
| passwordless sudo for a while | Setup, then Security, then Passwordless Sudo | sudo stops asking for 15 minutes, then asks again |
| web app | Install, then Web App | a launcher for a site, opened as its own window |
| organization | Setup, then Organization | join or leave your organization, see Accounts |
| device management | Setup, then Security, then Enroll in your organization's Fleet | lets your organization manage this computer |
| AI servers | Setup, then AI Tools | see AI agents |
Your accounts, including the VPN, are in GNOME Settings under Online Accounts. The git name and email your commits carry, and an SSH key, come from onboarding, see First boot.
Docker
The account the installer creates is already in docker, so on your own machine Docker works
without sudo from the start. An account made later isn't, and Sudoless Docker is how it joins.
An administrator can take an account out again with sudo gpasswd -d <account> docker.
Web apps
There are two ways to make one. Install, then Web App opens the site in your default browser's engine: with Zen as the default, each web app gets a Zen window and profile of its own. The Web Apps app makes Chromium windows. Either way the app gets its own launcher, and Remove, then Web App takes one away.
The firewall
Based turns ufw on. Incoming connections are refused, apart from the few services the edition ships that need them, such as LocalSend. KDE Connect and GSConnect open only on a network you've marked trusted, by setting its connection's firewall zone to home, work, internal or trusted in the network settings. Public Wi-Fi never sees them. Setting up the SSH server opens its own port.
sudo ufw status verbose