Skip to main content

SynapseOS

Applies to SynapseOS builds from 2026-10-09 (20261009-141152 and later). See What changed.

The operating system your appliance arrived with.

SynapseOS is the Linux that runs on a Gen0Sec appliance, whether that is a Cerebrum Max, a Cerebrum Edge, a server or virtual machine of your own, or an NVIDIA BlueField-3 card. It exists to run Synapse and nothing else. Your unit arrives with it installed and signed; these pages start at the login prompt.

How it differs from a general-purpose Linux​

On SynapseOS
The system itself (/usr)Read-only, and checked block by block on every boot. An edit there does not persist and makes the next boot fail verification
Your configuration (/etc, /var, /root)Writable, and kept across updates
UpdatesOne signed update replaces the whole system and its kernel together. The previous system stays on disk, and the appliance returns to it by itself if the new one does not come up
SoftwareThere is no package manager. What is on the unit is what the image was built with; new software arrives through an update
Network exposureInbound traffic is dropped by default, except SSH
AccessSSH accepts root with a key only. A password, where one is set, works on the console only

The read-only system is the reason the rest holds: the kernel, Synapse and every library are verified against a hash that is sealed into the signed kernel image, so a changed file cannot be run, and an update either verifies completely or is not booted.

What you see after logging in​

The login banner names the build the unit was delivered with (the running one, after an update, is in synapseos-ab-update status):

SynapseOS 20261009-141152-1bf85f2 (hardened ab) | kernel 6.18.54-synapseos
A/B slots | /usr sealed with dm-verity

and lists the three commands you will use most:

CommandWhat it does
synapseos-synapse listThe Synapse versions on the unit, and which one runs
synapseos-ab-updateCheck for, install and roll back OS updates
systemctl status synapse-agent synapseos-firewallThe data plane and the base firewall

Where to go next​

The command line voids nothing by itself

The banner carries the usual warning about the CLI. Everything on these pages is a supported way to operate the appliance. What is not supported is changing the system itself, and the unit refuses that on its own.