BasedBased

Docs

Setup that needs you

Based sets up everything it can from packages. What's left needs something only you can give: a sign-in, a finger or a security key, or a choice about your own machine. Each one is a row in the Omarchy menu, Super+Space on both editions or the tray icon on Workstation, and most can be undone under Remove.

what where what it does
fingerprint Setup, then Security, then Fingerprint, where the machine has a reader enrolls your finger for sudo, password prompts and the lock screen. With the lid shut it asks for the password instead
security key Setup, then Security, then Fido2 registers a FIDO2 key for sudo and password prompts. It can't unlock the screen
SSH server Setup, then Security, then SSHD installs and starts OpenSSH, opens port 22 in the firewall with a rate limit, and authorizes a key from GitHub or one you paste
Docker without sudo Setup, then Security, then Sudoless Docker adds you to docker after a warning, since that group is root without a password. It takes a reboot
passwordless sudo for a while Setup, then Security, then Passwordless Sudo sudo stops asking for 15 minutes, then asks again
web app Install, then Web App a launcher for a site, opened as its own window
organization Setup, then Organization join or leave your organization, see Accounts
device management Setup, then Security, then Enroll in your organization's Fleet lets your organization manage this computer
AI servers Setup, then AI Tools see AI agents

Your accounts, including the VPN, are in GNOME Settings under Online Accounts. The git name and email your commits carry, and an SSH key, come from onboarding, see First boot.

Docker

The account the installer creates is already in docker, so on your own machine Docker works without sudo from the start. An account made later isn't, and Sudoless Docker is how it joins. An administrator can take an account out again with sudo gpasswd -d <account> docker.

Web apps

There are two ways to make one. Install, then Web App opens the site in your default browser's engine: with Zen as the default, each web app gets a Zen window and profile of its own. The Web Apps app makes Chromium windows. Either way the app gets its own launcher, and Remove, then Web App takes one away.

The firewall

Based turns ufw on. Incoming connections are refused, apart from the few services the edition ships that need them, such as LocalSend. KDE Connect and GSConnect open only on a network you've marked trusted, by setting its connection's firewall zone to home, work, internal or trusted in the network settings. Public Wi-Fi never sees them. Setting up the SSH server opens its own port.

sudo ufw status verbose