back
Vale Linux
Rust · musl libc · Linux 6.12 · Firecracker · QEMU
status:active
ref:SYS-01
source:—
size:—

Custom Linux distribution built from scratch for running network services on homelab and small business hardware. DNS, DHCP, firewalling, monitoring, all running under per-service security sandboxing on minimal hardware.

The kernel is Linux 6.12, compiled with LLVM/clang, stripped to around 700 symbols. vale-init is a from-scratch Rust init system running as PID 1 with signal propagation and process reaping. v-man is the Rust service manager that provides supervision. It reads service definitions with metadata headers for retries, dependencies, and permissions, then manages the full lifecycle: fork, sandbox, exec, supervise.

secv is the security layer. It wraps seccomp, Landlock, and Linux namespaces behind an OpenBSD-style pledge/unveil API. Services declare their permissions in run script headers. v-man enforces them between fork and exec, so a service process never runs unrestricted. A DNS service gets network and DNS syscalls. A log collector gets filesystem read. Nothing more.

The home network design uses Vale as the router OS with physical segmentation across isolated services. Trusted LAN, guest wifi, IoT, and DMZ on separate interfaces with per-segment policy.

The distribution also targets Firecracker microVMs for edge compute workloads. Boot time drops from 1.24s under QEMU to 60ms under Firecracker, and 1,000 instances fit in 10GB of RAM. Dual boot support: bzImage for QEMU development, vmlinux for Firecracker production. Makefile-driven build with reproducible initramfs packing across both targets.

— —