Skip to main content

High-trust metadata and verification gateway for major Linux distributions. Official sources only. No ISO binaries hosted on this channel.

DISCLAIMER: Independent gateway operated for operator convenience. Not affiliated with, nor an official mirror of, any Linux distribution project. Always download from official URLs and perform GPG verification of official checksum files when available. You remain responsible for validating media integrity.

Distribution Mirror Hub

20 / 20 CHANNELS · 3 LANES · AMD64 PRIMARY

General Purpose

Stable desktop, server, and enterprise baselines for everyday operations.

12 channels

AlmaLinux 10.2

x86_64 · RHEL · rhel-based

enterprise general rhel enterprise minimal rpm

AlmaLinux 10.2 minimal — free RHEL-compatible enterprise OS for production servers.

ISO AlmaLinux-10.2-x86_64-minimal.iso (~1.6G)
SHA256 1b532f534231da0d1cd0ccae622bea6cd588d8a0d7b259f1f131501a6eed41a4
Verify echo "1b532f534231da0d1cd0ccae622bea6cd588d8a0d7b259f1f131501a6eed41a4 *AlmaLinux-10.2-x86_64-minimal.iso" | sha256sum -c -

Alpine Linux 3.24.1

x86_64 · Alpine · alpine-based

stable general alpine container hardened minimal

Alpine Linux standard ISO — musl/busybox based, small footprint, popular for containers and hardened appliances.

ISO alpine-standard-3.24.1-x86_64.iso (~350M)
SHA256 f4dd613206676c62949144c8ad75fc64582099f444dd1485bae104a60f51dd26
Verify echo "f4dd613206676c62949144c8ad75fc64582099f444dd1485bae104a60f51dd26 *alpine-standard-3.24.1-x86_64.iso" | sha256sum -c -

Arch Linux 2026.08.01

x86_64 · Arch · arch-based

rolling general arch minimal rolling

Monthly Arch Linux bootstrap ISO for the rolling-release model. Install once; keep rolling.

ISO archlinux-2026.08.01-x86_64.iso (~1.2G)
SHA256 4e82dced1c4fd3e498b22a853f8db2a4d262d32b97e7e07d97390d9e425ffe5e
Verify echo "4e82dced1c4fd3e498b22a853f8db2a4d262d32b97e7e07d97390d9e425ffe5e *archlinux-2026.08.01-x86_64.iso" | sha256sum -c -

Debian 13.6.0

Trixie · amd64 · debian-based

stable general debian netinst server stable

Debian Stable netinst ISO — minimal network installer for production-grade deployments.

ISO debian-13.6.0-amd64-netinst.iso (~755M)
SHA256 65273beed27b2df543b68b65630ba525cfbad8df2b12035732b2dff87d6664e7
Verify echo "65273beed27b2df543b68b65630ba525cfbad8df2b12035732b2dff87d6664e7 *debian-13.6.0-amd64-netinst.iso" | sha256sum -c -

Fedora 44

x86_64 · Fedora · fedora-based

current general fedora current desktop live

Fedora Workstation 44 Live — cutting-edge desktop stack with a fixed-release cadence (~6 months).

ISO Fedora-Workstation-Live-44-1.7.x86_64.iso (~2.7G)
SHA256 1620295f6a00c27c3208f0c00b8ece4eab1ec69b9002152d97488bf26a426ddf
Verify echo "1620295f6a00c27c3208f0c00b8ece4eab1ec69b9002152d97488bf26a426ddf *Fedora-Workstation-Live-44-1.7.x86_64.iso" | sha256sum -c -

Linux Mint 22.3

64bit · Debian/Ubuntu · debian-based

LTS general debian desktop lts

Linux Mint 22.3 Cinnamon — polished LTS desktop based on Ubuntu LTS foundations.

ISO linuxmint-22.3-cinnamon-64bit.iso (~2.8G)
SHA256 a081ab202cfda17f6924128dbd2de8b63518ac0531bcfe3f1a1b88097c459bd4
Verify echo "a081ab202cfda17f6924128dbd2de8b63518ac0531bcfe3f1a1b88097c459bd4 *linuxmint-22.3-cinnamon-64bit.iso" | sha256sum -c -

Manjaro 26.0.4

x86_64 · Arch · arch-based

stable general arch desktop stable

Manjaro KDE — user-friendly Arch-based desktop with curated stable branches.

ISO manjaro-kde-26.0.4-260327-linux618.iso (~4G)
SHA256 9d9e5f6b1558a8850bf19ca21af9c71cf3810c69a77ab860130281d09f6a33b9
Verify echo "9d9e5f6b1558a8850bf19ca21af9c71cf3810c69a77ab860130281d09f6a33b9 *manjaro-kde-26.0.4-260327-linux618.iso" | sha256sum -c -

NixOS 25.05

x86_64 · Nix · nix-based

stable general nix declarative minimal reproducible

NixOS 25.05 minimal ISO — declarative, reproducible Linux for infrastructure and secure hermetic builds.

ISO nixos-minimal-25.05.813814.ac62194c3917-x86_64-linux.iso (~1.6G)
SHA256 38dee38fd5b5f2429c35aef7d9cc039a21cafbd93809adf061d29149e3583c94
Verify echo "38dee38fd5b5f2429c35aef7d9cc039a21cafbd93809adf061d29149e3583c94 *nixos-minimal-25.05.813814.ac62194c3917-x86_64-linux.iso" | sha256sum -c -

openSUSE Leap 16.0

x86_64 · SUSE · suse-based

stable general suse enterprise-aligned stable

openSUSE Leap 16.0 online installer — stable, enterprise-aligned fixed release.

ISO Leap-16.0-online-installer-x86_64.install.iso (online)
SHA512 47241c708de25e18cf2d58fb592aa4b4ad9120e1c26b020350e3dc9c8e68efafaeaaf31ddd989825b5bbbfe3f95fbbb72afc8ee34ceb7d7de664536dd49cd441
Verify echo "47241c708de25e18cf2d58fb592aa4b4ad9120e1c26b020350e3dc9c8e68efafaeaaf31ddd989825b5bbbfe3f95fbbb72afc8ee34ceb7d7de664536dd49cd441 *Leap-16.0-online-installer-x86_64.install.iso" | sha512sum -c -

openSUSE Tumbleweed Snapshot20260805

x86_64 · SUSE · suse-based

rolling general suse netinst rolling

openSUSE Tumbleweed NET ISO — continuous rolling release with automated openQA gating.

ISO openSUSE-Tumbleweed-NET-x86_64-Current.iso (netinst)
SHA256 08eaf4d81faf43c278bb82c81807ef3957127cd900bacee7482b267fc9ac1990
Verify echo "08eaf4d81faf43c278bb82c81807ef3957127cd900bacee7482b267fc9ac1990 *openSUSE-Tumbleweed-NET-x86_64-Current.iso" | sha256sum -c -

Rocky Linux 10.2

x86_64 · RHEL · rhel-based

enterprise general rhel enterprise minimal rhel-compatible

Rocky Linux 10.2 minimal ISO — community enterprise OS, RHEL-compatible rebuild.

ISO Rocky-10.2-x86_64-minimal.iso (~2.0G)
SHA256 aac6ac3ce781b91a91ce78463405f66c611a5dca4b3840c79e5e01d97302f6c8
Verify echo "aac6ac3ce781b91a91ce78463405f66c611a5dca4b3840c79e5e01d97302f6c8 *Rocky-10.2-x86_64-minimal.iso" | sha256sum -c -

Ubuntu 26.04

Resolute Raccoon · amd64 · debian-based

LTS general debian desktop hybrid lts

Latest Ubuntu LTS desktop image. Five years of free security maintenance; enterprise option via Ubuntu Pro.

ISO ubuntu-26.04-desktop-amd64.iso (~6.1G)
SHA256 487f87faaf547ea30e0aba4d5b53346292571256b25333a978db1692bcee9dd2
Verify echo "487f87faaf547ea30e0aba4d5b53346292571256b25333a978db1692bcee9dd2 *ubuntu-26.04-desktop-amd64.iso" | sha256sum -c -

IT-Security & Privacy

Pentest, forensics, privacy, and hardened workstation media. Authorized use only.

4 channels

Kali Linux 2026.2

amd64 · Debian · debian-based

rolling security debian forensics live offensive

Kali Linux 2026.2 installer — industry-standard penetration testing and digital forensics distribution (Debian-based).

ISO kali-linux-2026.2-installer-amd64.iso (installer)
SHA256 6dbefacc95e3b556c19c48e8bae39b8b505e2d3a1aba0bfb7ab62b036c3d2ba3
Verify echo "6dbefacc95e3b556c19c48e8bae39b8b505e2d3a1aba0bfb7ab62b036c3d2ba3 *kali-linux-2026.2-installer-amd64.iso" | sha256sum -c -

Parrot Security 7.3

amd64 · Debian · debian-based

stable security debian offensive pentest privacy

Parrot Security 7.3 — Debian-based security suite for pentest, privacy, and development workflows.

ISO Parrot-security-7.3_amd64.iso (security)
SHA256 fe8ec64f92d8d629b1fcae85d9fab81c87e3ff30584201e82b7c453a740cefbc
Verify echo "fe8ec64f92d8d629b1fcae85d9fab81c87e3ff30584201e82b7c453a740cefbc *Parrot-security-7.3_amd64.iso" | sha256sum -c -

Qubes OS 4.3.1

x86_64 · Xen/Fedora · independent-based

stable security independent desktop hardened isolation

Qubes OS 4.3.1 — security-oriented desktop OS using Xen isolation (security by compartmentalization).

ISO Qubes-R4.3.1-x86_64.iso (~7.8G)
SHA256 6ab99dee2c7a7b2c32053d3531084aaf3af703815842b67f90a87ba324527db6
Verify echo "6ab99dee2c7a7b2c32053d3531084aaf3af703815842b67f90a87ba324527db6 *Qubes-R4.3.1-x86_64.iso" | sha256sum -c -

Tails 7.10.1

amd64 · Debian · debian-based

stable security debian amnesic anonymity live

Tails 7.10.1 — amnesic live system focused on privacy and anonymity (Tor-by-default, Debian-based).

ISO tails-amd64-7.10.1.iso (~1.7G)
SHA256 0a6bc953f870bab062d738c2a29ec8c9c0143e3b211c2d182afcf9b288053c71
Verify echo "0a6bc953f870bab062d738c2a29ec8c9c0143e3b211c2d182afcf9b288053c71 *tails-amd64-7.10.1.iso" | sha256sum -c -

Kubernetes & Immutable Node OS

Container-optimized and Kubernetes-first operating systems (Talos / talosctl, Flatcar, FCOS, Kairos).

4 channels

Fedora CoreOS 44.20260720.3.1

x86_64 · Fedora · fedora-based

stable kubernetes fedora immutable container-os ignition

Fedora CoreOS stable stream — automatically updating, minimal OS for containers and Kubernetes nodes. Provisioned with Ignition.

ISO fedora-coreos-44.20260720.3.1-live-iso.x86_64.iso (stable stream)
SHA256 ea684ab15e9c1fb2deca28a8f062dc0be824d0e0094816f1167e0d811b33dded
Verify echo "ea684ab15e9c1fb2deca28a8f062dc0be824d0e0094816f1167e0d811b33dded *fedora-coreos-44.20260720.3.1-live-iso.x86_64.iso" | sha256sum -c -

Flatcar Container Linux 4593.2.4

amd64 · Flatcar · independent-based

stable kubernetes independent immutable container-os ignition

Flatcar Container Linux stable 4593.2.4 — CoreOS successor, immutable container host OS. Common Kubernetes node base (CNCF incubator).

ISO flatcar_production_iso_image.iso (stable channel)
SHA512 8eb3bab6d5ff893277a0cb1fbd71132f23d6a30bc85b2f058ebb4c7b66849622c6eff760ea87782ea27ec3729460024da9f04887692d77d56da10f556a203a6a
Verify echo "8eb3bab6d5ff893277a0cb1fbd71132f23d6a30bc85b2f058ebb4c7b66849622c6eff760ea87782ea27ec3729460024da9f04887692d77d56da10f556a203a6a *flatcar_production_iso_image.iso" | sha512sum -c -

Kairos 4.1.2

amd64 · Kairos · independent-based

stable kubernetes independent immutable container-os k3s

Kairos v4.1.2 — immutable cloud-native OS for Kubernetes at scale (edge + cluster). Standard image ships with K3s; core image for custom stacks.

ISO kairos-hadron-v0.4.0-standard-amd64-generic-v4.1.2-k3sv1.35.5+k3s1.iso (k3s bundled)
SHA256 d1be4624ecb7ab06ae1acf3fba07e7dabf0eeb6221c0976e13256155c9088f6a
Verify echo "d1be4624ecb7ab06ae1acf3fba07e7dabf0eeb6221c0976e13256155c9088f6a *kairos-hadron-v0.4.0-standard-amd64-generic-v4.1.2-k3sv1.35.5+k3s1.iso" | sha256sum -c -

Talos Linux 1.13.8

amd64 · Talos · independent-based

stable kubernetes independent immutable container-os bare-metal

Talos Linux v1.13.8 — immutable OS built only for Kubernetes. Managed via talosctl API (no SSH). Metal ISO for bare-metal bootstrap.

ISO metal-amd64.iso (~320M)
SHA256 138138bb8a8b52cea250d53120b708dafc29a70ce2f7145789d9a05cf40bb2d9
Verify echo "138138bb8a8b52cea250d53120b708dafc29a70ce2f7145789d9a05cf40bb2d9 *metal-amd64.iso" | sha256sum -c -

CLI Service Bridge

COMMAND: osdl · LINUX · v1.2.1

Install — Linux / macOS

Auditable bash client + air-gap helper. Fetches live metadata from /api/v1/latest.json. Never proxies ISOs — only official URLs and published hashes.

$ curl -fsSL https://os.webservice.digital/cli/ | bash

Windows / PowerShell tooling is currently not offered publicly. Use the Linux installer above.

osdl list List curated distributions and current versions.
osdl info <distro> Show version, official URL, hash, and verification command.
osdl get <distro> [--verify] [--print] Download from official URL; optional SHA verify. --print shows commands only.
osdl verify <file> <distro> Verify a local ISO against gateway-published digests.
osdl push --host … --iso … Air-gap corridor: SCP ISO + checksum/key bundle to an isolated host (optional bastion jump).

Air-gap corridor (jumphost → isolated host)

$ osdl get rocky --verify -o /var/tmp/rocky.iso
$ osdl push --host ops@10.10.50.20 --iso /var/tmp/rocky.iso --distro rocky
$ osdl push --host airgap@192.168.99.10 --jump bastion@edge \
    --iso ./image.iso --checksum ./SHA256SUMS --sig ./SHA256SUMS.gpg --key ./project.gpg

Bundle includes ISO, digest/checksum file, optional GPG signature & keys, and MANIFEST.txt with remote verification steps. Use --print to rehearse.

WARNING: Hash verification confirms bit-identity with the published digest. Operators should still GPG-verify the upstream checksum files themselves.

Changelog · tooling train v1.3.2

Verification Workflow

DEFENSIVE PROTOCOL
  1. Obtain the ISO only from the official URL published on this gateway (or the distribution’s own site) — typically on a connected jumphost.
  2. Run the displayed sha256sum -c / sha512sum -c (or PowerShell Get-FileHash) against the local file.
  3. Download the official SHA256SUMS / CHECKSUM file and its GPG signature from the distribution project.
  4. Import the project’s signing key from a trusted path; run gpg --verify on the signature.
  5. Air-gap: use osdl push to SCP the ISO + checksum/key bundle to the isolated host; re-verify on arrival via MANIFEST.txt.
  6. Only then write the media (USB/hybrid) or boot the image.

FAQ

22 / 22 TOPICS · TOOLING v1.2.0

Operator briefing for the mirror gateway, hub lanes, CLI (Linux + Windows), air-gap push corridor, and verification. Use search or category filters to jump quickly.

About & scope

Mission · boundaries · non-goals
What is this gateway, and what is it not?

It is: a high-trust metadata and verification gateway for major Linux distributions — official download URLs, published digests, verify commands, lane-organized hub, public JSON API, and the osdl CLI (Linux + Windows), including air-gap push helpers.

It is not: an official project mirror, a CDN, a proxy, or a host of ISO binaries. It does not claim affiliation with Ubuntu, Debian, Fedora, Arch, SUSE, Mint, Rocky, Alma, Kali, Parrot, Tails, Qubes, Talos, Flatcar, Kairos, or any other distribution project.

Does this site host or proxy Linux ISO files?

No. The gateway publishes metadata, official download URLs, and checksums only. Binary transfers always go from your client (or jumphost) directly to the distribution’s official infrastructure or designated mirrors. Air-gap osdl push only SCPs files you already hold — it does not pull ISOs through this site.

Is this an official mirror for any distribution?

No. os.webservice.digital is an independent operational gateway. It does not claim official mirror status for any Linux distribution project. Treat each project’s own download and signing infrastructure as the root of trust for authenticity.

Hub & lanes

Layout · search · general catalog
How is the hub organized (lanes)?

Channels are split into three lanes for operational clarity:

  • General Purpose — desktop, server, and enterprise baselines (Ubuntu, Debian, Fedora, Arch, openSUSE, Mint, Rocky, AlmaLinux, Alpine, NixOS, Manjaro, …).
  • IT-Security & Privacy — Kali, Parrot Security, Tails, Qubes OS (authorized assessment and privacy workflows only).
  • Kubernetes & Immutable Node OS — Talos (talosctl), Flatcar Container Linux, Fedora CoreOS, Kairos.

Use the lane jump links under the hub title, the primary nav (Security / Kubernetes), or the filter chips.

How does the hub search / filter work?

Type free text or activate chips. Queries use multi-token AND matching with synonym expansion and whole-token boundaries (so enterprise does not false-match enterprise-aligned).

Useful queries: debian-based, redhat-based / rhel, security / pentest, privacy, kubernetes / k8s, immutable, talosctl, lts, minimal.

Deep-link with ?q=kubernetes on the hub URL. Empty lanes hide while a filter is active; the result counter shows visible vs total channels.

Which architectures are covered?

Primary focus is x86_64 / amd64. Some projects also publish arm64 or other arches on their official pages; this hub curates the mainstream 64-bit PC images most operators need. Always confirm arch on the project download page before deployment.

What does the operational status banner mean?

OPERATIONAL — metadata channels are considered healthy and current. DEGRADED — partial issues (stale entries or known upstream problems); double-check digests at the source. MAINTENANCE — planned update window; treat published hashes as possibly in flux. The banner also shows the last metadata sync time (UTC) and the channel id os.webservice.digital.

IT-Security & Privacy

Pentest · privacy · authorized use
What is in the IT-Security & Privacy lane?

Kali Linux — industry-standard pentest/forensics media (Debian-based). Parrot Security — security suite with home/security editions. Tails — amnesic live system, Tor-oriented privacy. Qubes OS — security-by-compartmentalization desktop (Xen isolation).

These tools are for authorized testing, training, and defensive research. Misuse may be illegal. Always re-verify official checksums and signatures before use.

Kubernetes & Immutable Node OS

Talos · Flatcar · FCOS · Kairos
What is in the Kubernetes & Immutable Node OS lane?

Talos Linux — OS built only for Kubernetes; day-2 ops via talosctl (no SSH/package manager on the node). Flatcar Container Linux — CoreOS successor, container host (CNCF incubator). Fedora CoreOS — auto-updating atomic host with Ignition. Kairos — immutable cloud-native OS; standard images may bundle K3s.

These are node/host operating systems, not Kubernetes distributions like kubeadm charts. Filter chips: Kubernetes, Immutable.

What is special about Talos Linux and talosctl?

Talos is a Kubernetes-only immutable OS. There is no SSH shell or traditional package manager on the node. Lifecycle and machine configuration are driven by the Talos API and the talosctl client (same release train as the metal ISO). Obtain the metal ISO from official Sidero releases (linked on this hub), install per Talos docs, then manage the cluster with talosctl. Custom boot assets can be built via the Talos Image Factory when required.

CLI tooling

Linux · Windows · osdl commands
How do I install the CLI on Linux or macOS?

One-liner (installs osdl and the air-gap helper osdl-push into ~/.local/bin by default):

curl -fsSL https://os.webservice.digital/cli/ | bash

Override install location with OSDL_INSTALL_DIR. Prefer inspecting the installer first: curl -fsSL https://os.webservice.digital/cli/ (and /cli/osdl, /cli/osdl-push) before piping to bash in high-security environments.

Core commands: osdl list, info <distro>, get <distro> [--verify] [--print], verify <file> <distro>, push …, status, version.

Is there a Windows / PowerShell CLI?

Windows PowerShell tooling is not offered publicly at this time. Use the Linux/macOS installer: curl -fsSL https://os.webservice.digital/cli/ | bash.

What does each osdl command do?
  • list — curated distro ids, names, versions, codenames.
  • info <distro> — official page, primary ISO URL, digests, verify command, checksum/GPG URLs, lane.
  • get <distro> — download from the official URL only; --verify / -Verify checks SHA; --print / -Print shows commands without executing.
  • verify <file> <distro> — compare a local file to gateway-published digests (supports variants).
  • push — SCP an ISO + verification bundle to an air-gapped host (see Air-gap corridor).
  • status — channel status and last metadata sync from the public API.

Metadata is cached locally (TTL default 300s); use --refresh / -Refresh to force a live fetch. Override API URL with OSDL_API or --api.

Air-gap corridor

Jumphost · bastion · SCP bundle
How do I deliver an ISO into an air-gapped network?

Pattern: connected jumphost/bastion obtains and verifies media → controlled SCP into the isolated segment.

  1. On the jumphost (online): osdl get <distro> --verify -o /path/file.iso (or Windows -Verify -Output).
  2. Optionally fetch official checksum + GPG material (or pass --distro so push can attach published listings while online).
  3. Push: osdl push --host user@airgap-ip --iso /path/file.iso --distro <id>.
  4. Via bastion: add --jump user@bastion (SSH ProxyJump).
  5. On the air-gapped host: follow MANIFEST.txt — typically sha256sum -c … / sha512sum -c …, then GPG-verify when keys/signatures were included.

Windows: osdl push -Iso .\file.iso -TargetHost user@host -Distro <id> -Jump bastion@edge. Rehearse with --print / -Print before first production transfer.

The transfer bundle may include: ISO, checksum/digest file, optional detached signature, optional public keys under keys/, and MANIFEST.txt.

What files should I push with the ISO for air-gap verification?

Minimum: the ISO plus a digest file (official SHA256SUMS / CHECKSUM / *.sha256, or a generated HASH *filename line). Strongly recommended: detached GPG signature of the checksum file and the project’s public signing key. Use --checksum, --sig, and repeatable --key (PowerShell: -Checksum, -Sig, -Key). With --distro, push can auto-attach official checksum/signature URLs while the jumphost still has network access.

Verification

SHA · GPG · workflow
Does osdl get --verify replace GPG verification?

No. Automatic SHA256/SHA512 verification only proves bit-identity with the digest published by this gateway (or a local digest file you supply). It does not by itself prove that the digest originated from the distribution project. You remain responsible for GPG-verifying official checksum files with the project’s signing keys when your threat model requires authenticity, not just integrity.

What is the full verification workflow?
  1. Download only from the official URL shown on this hub (or the project site).
  2. Check digest: sha256sum -c / sha512sum -c, osdl verify, or PowerShell Get-FileHash.
  3. Obtain the official checksum listing and its GPG signature from the project.
  4. Import the project key from a trusted channel; gpg --verify the signature.
  5. Air-gap: push the verified bundle; re-check digests on the isolated host before imaging media.
  6. Only then write USB/hybrid media or boot the image.

API, ops & policy

JSON · audit · privacy · liability
How do I use the public JSON API?

Read-only GET endpoints (CORS allowed for GET):

  • /api/v1/latest.json — full payload: status, disclaimer, CLI hints, all distributions (including lane, digests, verify commands).
  • /api/v1/distros.json — distributions only.
  • /api/v1/status.json — banner fields (channel, status, last sync).

The CLI always consumes live metadata from these endpoints (with a short local cache). Stable fields include id, aliases, name, version, lane, primary_iso.{filename,url,sha256,sha512,verify_command}, checksums.*.

How are hashes and versions kept current?

Gateway operators refresh the configuration-driven catalog after validating digests against each project’s official checksum files (and signatures where practical). The banner field LAST MIRROR METADATA SYNC is the UTC timestamp of that refresh. Consumers should still treat the distribution project as the root of trust for authenticity. Public release notes for the gateway and tooling are on the Changelog page.

Where can I inspect the CLI source and release history?

Public operator scripts are served as plain text for audit:

Current public tooling train: v1.3.2 (Linux CLI + air-gap push + presentation layer).

Is there tracking, advertising, or third-party scripts?

No. No analytics, advertising, or non-essential third-party scripts or fonts. Content Security Policy is restricted to same-origin assets. External download links use rel="noopener noreferrer".

Who is responsible if a download fails or a hash mismatches?

You are. This gateway is provided without warranty. Upstream mirrors can fail; digests can lag a project point-release by a short window; network paths can corrupt transfers. On mismatch: re-download from the official URL, re-check the project’s own checksum file and GPG signature, and only then escalate. Never boot untrusted media into production.

Codeword Glossary

TERSE LEXICON
LTS
Long-Term Support release. Extended security maintenance window; preferred for production fleets.
ISO
Optical/disk image of an installer or live system. Usually hybrid (USB-writable) on modern distros.
SHA256
256-bit cryptographic hash. Confirms file bit-identity; does not prove authenticity alone without signed checksums.
SHA512
512-bit hash variant. Used by some projects (e.g. Debian, openSUSE Leap 16) alongside or instead of SHA256.
GPG
OpenPGP tooling for cryptographic signatures. Use to authenticate official checksum files from the project.
Mirror
Replica of official package/ISO content. This gateway is not a binary mirror — metadata only.
Netinst
Network installer image. Small local payload; packages fetched from online repositories during install.
Verify
Confirm a local ISO matches a published digest (and, ideally, that the digest file is GPG-authentic).
Hybrid
ISO constructed to boot from both optical media and USB mass storage without conversion.
Rolling
Continuously updated release model (Arch, Tumbleweed). No traditional “point” freeze for the base system.
Stable
Fixed-release train with controlled updates (Debian stable, Leap). Predictable for ops baselines.
Gateway
This service: curated links, hashes, status, and CLI — not a CDN for ISO bytes.
Channel
Logical feed identity for this site: os.webservice.digital.
osdl
Operator Shell Download Link — the CLI bridge command installed from /cli.
Debian-based
Family filter: Debian and derivatives (Ubuntu, Mint, Kali, Parrot, Tails, …).
RHEL-based
Family filter: Red Hat Enterprise Linux rebuilds/compatibles (Rocky, AlmaLinux, …).
Pentest
Penetration-testing oriented media (Kali, Parrot Security) for authorized assessments only.
Amnesic
Live system that leaves minimal forensic residue on host storage (e.g. Tails).
Talos / talosctl
Kubernetes-only immutable OS; nodes managed via the talosctl API (no SSH).
Immutable
Image-based OS with atomic updates and minimal mutable surface (Talos, Flatcar, FCOS, Kairos).
Container OS
Host OS optimized to run containers / Kubernetes rather than general desktop workloads.
Lane
Hub grouping: General · IT-Security & Privacy · Kubernetes & Immutable Node OS.
Air-gap
Network segment without general Internet egress. Media is introduced via controlled transfer (e.g. jumphost SCP).
Jumphost / Bastion
Hardened host that can reach both the public network (or mirror path) and the isolated segment; used to stage and push ISOs.
ProxyJump
SSH multi-hop (-J) through a bastion to the final air-gapped host.
Bundle
Transfer package: ISO + checksum/digest file + optional GPG sig/keys + MANIFEST.txt.