NextRedOS is a Debian-based Linux distribution created as a practical experiment in system hardening, self-hosting and European-oriented open technologies. The project started from a simple need: deploying a secure and reliable operating system for a home server running Home Assistant and other self-hosted services.
This talk presents the ideas behind NextRedOS and the concrete security measures adopted to reduce the attack surface: full-disk encryption with LUKS, Secure Boot with custom MOK enrollment, USBGuard and PAM hardening, kernel module blacklisting, and a multi-layer ransomware protection approach combining auditd rules, Timeshift snapshots and filesystem restrictions on temporary directories. It will also cover how self-hosted services such as Home Assistant and Vaultwarden are integrated through Podman, keeping containers isolated from the base system.
Through the development of this distribution, NextRedOS became both a learning platform for cybersecurity and networking and a real-world operating system designed for everyday use, with a GPG-signed, SHA256-verified release already published on GitHub and Codeberg. The session will share lessons learned, challenges encountered during the hardening process, and future goals, offering attendees a perspective on building secure Linux systems with open technologies.
