github Start9Labs/start-technologies start-os/v0.4.0.1
start-os v0.4.0.1

3 hours ago

StartOS v0.4.0.1

v0.4.0 is a complete rewrite of StartOS. After six years of building, we believe we have arrived at the correct architecture and foundation to deliver on the promise of sovereign computing.

⚠️ Before You Update

0.4.0 is finally out of public beta! However, the only way to update is by following the 0.4.0 Update Guide precisely. This is a sensitive update between two essentially distinct operating systems — skipping steps or improvising can result in data loss.

👉 Read the full update guide before proceeding

If anything goes wrong, stop and contact support — do not attempt to troubleshoot on your own.

Highlights

  • Redesigned UI — faster, more intuitive, mobile-friendly, with a real-time system metrics dashboard
  • Completely new networking stack — LAN port forwarding, Wireguard VPN gateways, private and public domains (clearnet), Let's Encrypt, built-in DNS, and Tor as an optional plugin
  • StartTunnel — free, open-source reverse tunnel to expose services on a public domain without revealing your home IP
  • LXC container runtime — replacing Docker/Podman with a reliable, nested container architecture supporting hardware acceleration and multi-container setups
  • Improved backups — differential backups, cross-server restore, and a new FUSE module for cross-platform reliability
  • Internationalization — multiple languages and keyboard layouts for StartOS and services
  • TypeScript SDK — build and ship a StartOS package in minutes
  • New S9PK format — signature verification, partial downloads, and multi-architecture support
  • SMTP notifications — email alerts from StartOS and services via Gmail, SES, or any SMTP provider

Important

Previous backups are incompatible with v0.4.0. After updating, immediately update all services and create a fresh backup.

What's Changed

Changed

  • A service that serves its own TLS certificate now reports its external port
    as an SSL port, and StartOS serves it like one.
    Every interface whose
    external port speaks TLS — whether StartOS terminates it or the service
    presents its own certificate — now carries that port in assignedSslPort,
    and assignedPort means a plaintext port. A self-TLS port is now answered by
    the StartOS SNI router, which pipes the raw TLS stream to the service with
    the client's address preserved, instead of a kernel port-forward — so every
    TLS-carrying port behaves uniformly, and a self-TLS service's domains are
    advertised on its preferred port (e.g. 443) exactly as when StartOS
    terminates TLS. This also means such a port accepts TLS connections only,
    and no longer relays UDP. The port number itself is
    unchanged, so existing addresses, bookmarks and router port-forwards keep
    working. Packages resolve a dependency's address with
    sdk.host.getBridgeAddress, which is correct under either arrangement; see
    Service-to-Service Networking.

  • The StartOS web interface holds ports 80 and 443. StartOS runs as root, so
    its own interface is the one binding that may claim the privileged range, and
    it now does so through the same port allocator every service uses. HTTPS was
    already served on 443; the plaintext address — offered only over loopback and
    the service bridge — moves from a random high port to 80.

Fixed

  • Updating from 0.3.5.1 starts the Tor service it installs. Your existing
    onion addresses come across with it and answer as soon as the update
    finishes, with nothing to start by hand.

  • A service that fails to convert while migrating from 0.3.5.1 reports the
    reason.
    The v1→v2 package conversion raises a notification against that
    service carrying the error that stopped it, in the same form as an install
    failure — alongside the summary notification listing every service to
    re-install.

  • A service that is renamed during migration is recorded as migrated. Ghost,
    Synapse, Monero, Nostr and Fedimint are installed under new ids on 0.4.0
    (ghost-legacy, synapse-legacy, monerod-legacy, nostr-rs-relay and
    fedimint-guardian), and the migration looks each one up under the id it was
    installed as. These services complete their migration without appearing among
    the failures, and the failure list names services by ids that exist in the
    marketplace.

  • The over-the-air update to 0.4.0 boots on the Server Pure. The Server
    Pure's PureBoot firmware reads the boot configuration itself rather than
    running GRUB, and it takes the kernel and initramfs paths literally. The
    update now writes those paths in the plain form PureBoot expects, so the
    server boots into 0.4.0 on the restart that applies the update.

  • A Server Pure applies its PureBoot firmware update. StartOS installs the
    firmware image at the path it reads it from, so a Server Pure on an older
    PureBoot release updates its firmware on the next start.

  • Installing onto a pre-installed Raspberry Pi keeps the data pool you pick.
    Selecting the data pool by partition path now preserves that choice through
    installation.

Image Downloads

OS Images Checksums

SHA-256

bdf95acaab3f8a31a8b497883bf6addb8c38d240a6e4b59e353dc279e8da5351  startos-0.4.0.1-fdb27c7_aarch64.iso
4de00f435b2f2efbf9934fd6a3fe792e45cfea55b12cb2085dbed17d157a0373  startos-0.4.0.1-fdb27c7_aarch64-nonfree.iso
4d4ae6ffe130667ad673f5e63f742d8ae97fb58086d4368013f3a393d03dc23e  startos-0.4.0.1-fdb27c7_aarch64-nvidia.iso
dc58a015435a5220d709f6f7a16dcae13aa4607ebc9a933fab8b8ccde47aa5d2  startos-0.4.0.1-fdb27c7_riscv64.iso
9d615ccda0716beb483dc107a6e08f5e3cb63d61d8d3ebfc6ea3d6513c09f270  startos-0.4.0.1-fdb27c7_riscv64-nonfree.iso
9f4f5ad4ece2dc349b0a7b6221b542b26112fe753657024487fc26ef6cf08072  startos-0.4.0.1-fdb27c7_x86_64.iso
37b63c86197150866809d34b5824ae22c5fc705d4f8dc9e9750b8fa23485441a  startos-0.4.0.1-fdb27c7_x86_64-nonfree.iso
894398ec7d99ee833290c0bc9998c6023af9e39b79a07bfe8ba26c519ba5bd1f  startos-0.4.0.1-fdb27c7_x86_64-nvidia.iso
e8c2521290c3c6acba14bc11e2c0ae66d7884af28947034efcd6d9129a7b52f1  startos-0.4.0.1-fdb27c7_raspberrypi.img
55ceb1891801e76419705d1f97d5bc5e4b00cb6c76b31a005876c5580e5dc8ee  startos-0.4.0.1-fdb27c7_raspberrypi.img.gz
ba0f41cd4c5652a7792a0e0d26112edd0c9aa7fefa27060d1325ffedbf2fb963  startos-0.4.0.1-fdb27c7_aarch64-nonfree.squashfs
1a445e9b37a4cbb751300903c975e09e2aa02116c6a1be3940931a1237ac7d4b  startos-0.4.0.1-fdb27c7_aarch64-nvidia.squashfs
f7d7444b3015f0e72661cea15ba705fce755ecb357d2337efb206e3c7adf4bea  startos-0.4.0.1-fdb27c7_aarch64.squashfs
e438f1865f83a212e6549dd75801f7064af2ebd730c729980f78277849452569  startos-0.4.0.1-fdb27c7_raspberrypi.squashfs
ec89c2327b12b74b906a3d9a9451f06891d6e7191dad913a18fd2fc08f8b9ab8  startos-0.4.0.1-fdb27c7_riscv64-nonfree.squashfs
d11489d83e0eec80be10db27e0ac900e07be3561c08196fce9682e8721179383  startos-0.4.0.1-fdb27c7_riscv64.squashfs
0e8f8188a2c9c0c1dd28027358990b368156ace8ef006ca145726b15790c8385  startos-0.4.0.1-fdb27c7_x86_64-nonfree.squashfs
d877249ad396c575a88f0d50a6c47ab98d37de7727264724f408fb4644e62441  startos-0.4.0.1-fdb27c7_x86_64-nvidia.squashfs
8bce91c20fa7a438bd088d3d3f40c84948addfca98df47e1a1d3bb5ce5e14ec5  startos-0.4.0.1-fdb27c7_x86_64.squashfs

BLAKE-3

1ad23c274420ef918c1a6ee3026c8cf4c35e91a818d8f1ec67a49adcd45af72e  startos-0.4.0.1-fdb27c7_aarch64.iso
7f7aba41fa9bef65132724d58adb5bf0c25618faaf8f6e183bcee1804850daa2  startos-0.4.0.1-fdb27c7_aarch64-nonfree.iso
4ef639cc8e50afe191944ee6998e9ff7199905d24c505950a01235401b50a1c1  startos-0.4.0.1-fdb27c7_aarch64-nvidia.iso
83d29a6276843551313138269daee46a08803fc271e269a58064821a8da652c0  startos-0.4.0.1-fdb27c7_riscv64.iso
8ca3b2b2199da244ecf076f648b859981c1e9e10b04e58c6d8861f2e3ec5c071  startos-0.4.0.1-fdb27c7_riscv64-nonfree.iso
7d9e158bed0f5da296a4f0e7c5152c24b215c4847671408541903e0a3a2095e9  startos-0.4.0.1-fdb27c7_x86_64.iso
8ca4b2cd15c1bf0b260cf1dc7ff806385c56a122810f0182559a52fa8968df24  startos-0.4.0.1-fdb27c7_x86_64-nonfree.iso
c65f77618003c3d70d4b62182e2534b3b47dcee3150d31a35bbd732f83c39f5e  startos-0.4.0.1-fdb27c7_x86_64-nvidia.iso
6eacb5e312d8fbafe7fc34957ba526031c07fec54fe6eeeddfe6e2fab0117adb  startos-0.4.0.1-fdb27c7_raspberrypi.img
e217ffa95f2ebede5892a8fc84d7f886844d2c4b2f5071d0a40c8b18dbfcf450  startos-0.4.0.1-fdb27c7_raspberrypi.img.gz
1efe2be91ceb4ee394d3b9df4dd6faaab9c40f5ba4bb560b10ce0b9bef4aff81  startos-0.4.0.1-fdb27c7_aarch64-nonfree.squashfs
69ae8d34413ae88423ee4921c50a5588ec64e166ef5723f4c43cbce2336015ba  startos-0.4.0.1-fdb27c7_aarch64-nvidia.squashfs
5a82ded54de85b2605470f8efbd9e8030db6f82316c80782a89f14582c3bff35  startos-0.4.0.1-fdb27c7_aarch64.squashfs
1c4ea9e1f47becc8c2053105116669a03c025db75b1335ce70264f2f6b0cbc9a  startos-0.4.0.1-fdb27c7_raspberrypi.squashfs
60a18e2cc8e9e21de3edd43ffb02fcbb36bff99d133fe7c4da9cf71d9d45c858  startos-0.4.0.1-fdb27c7_riscv64-nonfree.squashfs
b59ab11bd93a206cf827e7187cb63aedd0df571535fe35caf3904c54e4ff6787  startos-0.4.0.1-fdb27c7_riscv64.squashfs
c30f0292fd5a08325be32daed1d5160557d772b25051848dcacd3c37986e0cd3  startos-0.4.0.1-fdb27c7_x86_64-nonfree.squashfs
8e441703fa92983d4a5e7ca888f9ebdd29fc818bcaf46cd41febf1906fce190a  startos-0.4.0.1-fdb27c7_x86_64-nvidia.squashfs
346b93ee88685891be04d7a880bf08f4d9d31d023cd228674c194ecb1c11e97b  startos-0.4.0.1-fdb27c7_x86_64.squashfs

Don't miss a new start-technologies release

NewReleases is sending notifications on new releases.