Skip to content

Releases

Downloads

Choose the release path that matches the job: a bootable hypervisor image or a root filesystem for bootstrapping from existing Linux.

Saphira, the royal-blue dragon mascot of Saphira Linux

Saphira-D

SOON TO BE RELEASEDx86-64-v3GCC C / C++

The systemd sibling of Saphira Linux Earlybird Beta: the same source-built musl distribution, with systemd out of the box. Saphira-D is the non-usr-merged edition, preserving the traditional Linux filesystem layout and proper FHS support. Separate disk and bootstrap images will be published when ready. Separate kernels will also be downloadable as APK installers, supporting the vast majority of Intel x86-64-v3 CPUs; AMD is expected to work but is not yet tested.

Release name
Saphira-D
Release date
ETA 2026-08-26
Compressed size
TBC
Architecture
x86-64-v3
Artifact
saphira-d.tar.xz
Format
Separate QCOW2 disk image and bootstrap image, distributed as an xz-compressed tar archive
Compiler
GCC 16.2.0 · C, C++
SHA-256
TBC
Checksum file
TBC
Packages
481 in saphira/main
Init / libc / packaging
systemd · musl · APK

This release is pending. The download will be available once it is published.

Saphira Linux Earlybird Beta

BetaPre-releaseGCC C / C++RUST / GO / CLANG / Emscripten

A bootable QCOW2 image for KVM/QEMU and other hypervisors. It starts at the guided first-boot setup.

Release name
Saphira Linux Earlybird Beta
Release date
2026-08-15
Compressed size
≈ 420 MB compressed
Architecture
x86-64-v3
Artifact
saphira.tar.xz
Format
QCOW2 disk image, distributed as an xz-compressed tar archive
Compiler
GCC 16.1.0 · C, C++
SHA-256
919728f474708c5100e81eb37e48650797d6e68e6161788812798898bc658f21
Checksum file
saphira.tar.xz.sha256
Packages
481 in saphira/main
Init / libc / packaging
OpenRC · musl · APK

Clicking Download requests a short-lived token from the release service. The archive itself is served statically by nginx once the token validates.

Checksum file: Download checksum file

Saphira Linux v0 Bootstrap

Bootstrapx86-64-v3GCC C / C++

A root filesystem and verified kernel-source bundle for installing Saphira from an existing Linux system.

How to bootstrap Saphira Linux →

Release name
Saphira Linux v0 Bootstrap
Release date
2026-08-19
Compressed size
≈ 285 MB compressed
Architecture
x86-64-v3
Artifact
saphira-linux-v0.bootstrap.tar.xz
Format
x86-64-v3 root filesystem and bootstrap documentation
Compiler
GCC 16.1.0 · C, C++
SHA-256
765b2833cbaa3ddebd71bbf01d4d24da290cc15c7ee20047444f25b3c5c37f42
Checksum file
saphira-linux-v0.bootstrap.tar.xz.sha256
Packages
481 in saphira/main
Init / libc / packaging
OpenRC · musl · APK

Clicking Download requests a short-lived token from the release service. The archive itself is served statically by nginx once the token validates.

Checksum file: Download checksum file

Saphira Linux Earlybird Beta 2

Beta 2MilestoneGCC 16.2Full compiler infra

A milestone rebuild from the SDK with GCC 16.2.0 supporting all major languages, alongside golang, rustc, clang and LLVM. Packages are already live on saphira/latest.

Release name
Saphira Linux Earlybird Beta 2
Release date
TBC
Compressed size
TBC
Architecture
x86-64-v3
Artifact
TBC
Format
Full SDK rebuild (Stage0 → Stage4) with complete compiler infrastructure
Compiler
GCC 16.2.0 · C, C++, Fortran, Ada, Obj-C, Obj-C++, D, Go, M2, Cobol, Algol68, JIT, LTO
SHA-256
TBC
Checksum file
TBC
Packages
528 in saphira/latest
Init / libc / packaging
OpenRC · musl · APK

This release is pending. The download will be available once it is published.

Minimum requirements

Minimum to run

This is a functional minimum, not a production recommendation.

  • CPU supporting x86-64-v3 (roughly Haswell/Excavator onwards, with AVX2).
  • 1 vCPU.
  • 512 MiB RAM.
  • 8 GiB disk.
  • A VirtIO-capable hypervisor; KVM/QEMU is the primary tested target.
  • Network access to the Saphira APK repository.

Recommended small server baseline

For a light nginx, PHP or Node-style server, start with:

  • 2 vCPU.
  • 2 GiB RAM.
  • 8 GiB or more disk.

Database-backed server baseline

For nginx, application services and MariaDB, add roughly 2 vCPU and use at least 4 GiB RAM. This is a practical baseline, not a hard law.

Mail workload allowance

For Postfix, Dovecot and supporting mail services, allow roughly one additional vCPU and at least 1 GiB additional RAM. Mailbox count, scanning, indexing, concurrency and retention can require more.

Complete small infrastructure server

For nginx, PHP/application services, MariaDB, Postfix and Dovecot together, a practical starting point is around 4 vCPU and 8 GiB RAM. This is a baseline for a small combined workload, not a universal production guarantee.

For more workload-specific guidance, see the Saphira sizing guide.

Real Saphira numbers

The Saphira VM serving this website runs with 2 vCPU and 2 GiB RAM. During normal operation it typically uses around 200–240 MiB of memory with no swap.

VM
2 vCPU / 2 GiB RAM
Memory
~200–240 MiB used
Swap
0
Static test
~1,336 requests/sec

In a static nginx benchmark of 100,000 HTTPS requests at concurrency 1,000, all requests completed successfully at roughly 1,336 requests per second. This measured static nginx delivery, not Node SSR, PHP, database, mail or other dynamic workloads.

Protected download path

  1. 01Click Download: the browser obtains a one-time AIE transport challenge.
  2. 02The browser encrypts the artifact request with ephemeral ECDH P-256 and AES-GCM.
  3. 03The application validates the envelope and issues a short-lived, one-time download token.
  4. 04The token authorises the exact release archive and increments the download counter.
  5. 05The authorised archive is returned from the private release directory.

The archive is not publicly addressable by its filesystem path. AIE protects the request, the token is scoped to this release, and replaying the token is rejected.

Verify what you downloaded

sha256sum -c saphira.tar.xz.sha256
sha256sum -c saphira-linux-v0.bootstrap.tar.xz.sha256

A checksum tells you the bytes you received are the bytes that were published. It catches truncated transfers, mirror mistakes and tampering. If the checksum does not match, do not boot the image.

Checksums for every release →

Getting started

The six steps

  1. 1. Import the image into your hypervisor and boot the VM.
  2. 2. Set the root password in the guided first-boot setup.
  3. 3. Create your normal user and set its password.
  4. 4. Configure IPv4 and IPv6.
  5. 5. Choose DNS and confirm the package repository.
  6. 6. Finish setup and continue from the shell.

The first-boot setup guides you through

  • Root password and confirmation.
  • Normal user creation, including login name and full name.
  • User password and confirmation.
  • IPv4 address and CIDR, then the IPv4 gateway.
  • IPv6 address and CIDR, then the IPv6 gateway.
  • DNS provider: Quad9, Cloudflare, OpenDNS / Cisco Umbrella, or custom DNS servers.
  • Optional DNS search domain.
  • APK repository configuration and confirmation before applying the setup.

The Saphira repository is suggested automatically:

https://packages.akadata.ltd/saphira/main/

When setup completes, the repository configuration is ready for normal APK commands:

apk update
apk search nginx
apk add nginx

The setup then drops you into a normal shell. The default files from /etc/skel are copied into both the root account and the new user's home directory, so the supplied .bashrc and .profile are ready immediately.