Kodachi Cairo Dock
The dock combines normal application launchers, live running applications, and Kodachi-specific control surfaces. Use it as a visual map: hover for a name, open a sub-dock for a category, then read live state inside the window that opens.
Use the dock without guessing
- Move the pointer over an icon. Read its label before clicking. Custom art distinguishes tasks, but the label is the authority.
- Hover over a category for about half a second. Browsers, Terminals, Security, Encryption, Net Tools, Utilities, Files, Containers, and More then expand into sub-docks. The shipped dock is configured for hover, not click-to-expand.
- Click a launcher. A normal application opens directly. A Kodachi control icon opens a native GTK window or a terminal that keeps its result visible.
- Use the running-application area. An already open window may appear there instead of opening a duplicate. Click its live icon to bring it forward.
- Use Show Desktop and Trash as applets. Trash can display empty or full state. Some tray utilities, such as Firetools or Redshift, may start without a normal window.
Quick Browser is a folder chooser
The Quick Browser applet opens a compact folder menu from the dock. It is separate from the Browsers sub-dock, which launches web browsers.
What is generated and what is live
The custom layout is generated from one reviewed action manifest. The dock also adds live application icons while programs run. That means a running icon is temporary, while Dashboard, Quick, category icons, separators, Application Menu, Show Desktop, Quick Browser, and Trash are stable parts of the layout.
Current left-to-right layout
Show Desktop starts the bar, followed by Dashboard, Quick, Containers, and More. A Running Applications separator comes next, then temporary taskbar icons. After the Applications separator come Application Menu, Browsers, Terminals, Security, Encryption, Net Tools, Utilities, and Files. The Quick Commands separator leads to Quick Browser and Trash. If the main dock is hidden, move the pointer to the bottom edge so it reappears. Then hover over a category icon for about half a second to open its sub-dock.
Complete current group map
The counts below are cells in the current reviewed manifest, not a count of windows on screen. Separators are cells because they define the main and More regions.
| Group | Cells | Purpose |
|---|---|---|
| Main dock | 5 | Dashboard, the grouped Quick window, and three layout separators. |
| More | 15 | Eleven grouped control windows, Repository Manager, Quick Actions, Rofi Apps, and one divider. |
| Browsers | 6 | Kodachi, Tor, Oniux, proxychains, disposable, and separate-window browser launches. |
| Terminals | 16 | Normal, Torified, Oniux, root, monitoring, editing, and specialist terminal tools. |
| Security | 12 | Firewall, cleaning, audit, logs, Tor circuits, scanning, and traffic inspection tools. |
| Encryption | 9 | Volumes, passwords, OTP, hashing, certificates, and GnuPG tools. |
| Net Tools | 12 | Wallets, VPN, OnionShare, sync, remote access, transfer, and connection editing. |
| Utilities | 22 | Monitoring, packages, snapshots, editors, media, accessibility, sensors, and desktop helpers. |
| Files | 21 | File managers, disks, search, capture, archive, backup, office, image, scan, and disc tools. |
| Containers | 9 | Isolation Manager plus eight direct Podman and Firejail shortcuts. |
Root and network tools can change the host
Launchers marked as root use PolicyKit and can modify disks, firewall rules, packages, or system configuration. A terminal title or application dialog becomes the next source of truth after the dock hands control over.
All nine Containers controls
This sub-dock keeps the direct shortcuts users asked for and puts Isolation Manager first. Podman containers and Firejail sandboxes are different mechanisms: Podman provides a rootless container workspace, while Firejail restricts a host application.
Isolation Manager
Choose an application and then Native, Firejail, or Podman. Also inspect running sandboxes, containers, images, and profiles.
Podman Disposable Shell
Starts a temporary offline shell. Treat everything inside as disposable because the container is removed when the session ends.
Podman Persistent Workbench
Opens the managed workbench whose files and installed tools survive later sessions.
Podman Status
Shows the managed containers and their state in a terminal that stays open.
Start All Kodachi Containers
Starts every container carrying the Kodachi management label. It does not adopt unrelated Podman containers.
Stop All Kodachi Containers
Stops persistent managed containers but deliberately spares disposable shells. Exit a disposable shell from inside it. Save open work first.
Reset Podman Workbench
Confirms, then removes only the persistent workbench. Its files are lost. A clean workbench is created the next time you open Persistent Workbench.
Kodachi Browser (Firejail)
Starts LibreWolf through Kodachi's validated Firejail wrapper rather than a bare firejail command.
Firejail Terminal
Starts an intentionally offline XFCE terminal with private temporary and device views, dropped capabilities, seccomp, no-new-privileges, and no root escalation.
Which shortcut should I use?
| Need | Use |
|---|---|
| A guided choice for an application | Isolation Manager |
| A clean command-line session that can be discarded | Podman Disposable Shell |
| A reusable isolated command-line workspace | Podman Persistent Workbench |
| A sandboxed graphical browser or terminal | The matching Firejail shortcut |
| Diagnose container prerequisites | Podman Status, then Isolation Manager -> Containers or Images |
Main and More controls
| Visible label | Type | What opens |
|---|---|---|
| Dashboard | Launcher | The Kodachi Dashboard. |
| Quick | GTK window | A grouped set of frequent Kodachi actions. |
| Status | GTK window | Read-only machine, privacy, and service status. |
| Network | GTK window | VPN, Tor, kill switch, DNS, and tuning pages. |
| Identity | GTK window | MAC, hostname, timezone, IPv6, and decoy-traffic controls. |
| Devices | GTK window | Radio, sensor, storage-status, and USB controls. |
| Harden | GTK window | Protection profiles and individual defenses. |
| Verify | GTK window | Integrity and security verification reports. |
| Services | GTK window | Remote access, peer-to-peer, logging, exposure, and maintenance controls. |
| Account | GTK window | Authentication and account status actions. |
| System | GTK window | Desktop, power, system, and maintenance actions. |
| Recipes | GTK window | Reviewed multi-step Kodachi workflows. |
| Emergency | GTK window | Panic, network containment, recovery, key destruction, and session-ending controls. |
| Kodachi Repository Manager | GTK application | The package and APT source storefront. |
| Kodachi Quick Actions | Rofi menu | The full searchable command registry. |
| Rofi Apps | Rofi menu | A searchable application launcher. |
Browser choices are not interchangeable
- Kodachi Browser: the standard Kodachi browser launch.
- Tor Browser: Tor Browser's own isolated browsing environment.
- Kodachi Browser (Oniux): launches only that browser through an Oniux network namespace.
- Proxychains Browser: uses a dedicated profile and remote DNS. It refuses missing, credentialed, or multi-hop proxy configurations instead of falling back to a direct launch.
- Kodachi Browser (Disposable): creates a fresh temporary LibreWolf profile and does not reuse the normal profile. It does not promise secure deletion when the browser closes.
- Kodachi Browser (New Window): opens a new window with the normal profile. It is not a new privacy identity.
Terminal choices that change isolation
- Torified Shell routes commands launched inside that shell. It does not reroute the whole system.
- Oniux Terminal, Oniux Tilix, and Oniux Kitty isolate only the selected terminal application in an Oniux namespace.
- Root Terminal and Root Terminator create privileged sessions. Commands inside them can change the whole system.
Common dock symptoms
| Symptom | What to check |
|---|---|
| Sub-dock did not stay open | Move deliberately onto the category and then into its child row. Avoid crossing another icon first. |
| A click opened no normal window | Look in the notification area for Firetools, Redshift, or another tray application. Check the running-application area too. |
| Podman shortcut reports missing data | Open Isolation Manager -> Containers and Images. It names missing Podman, archive, or metadata prerequisites. |
| Direct action says Already running | The same action still owns its single-flight slot. Bring its terminal or result window forward or wait for it to finish. |
| GTK control reads unknown | Use its Show or refresh control. Unknown means the state producer did not provide a trustworthy answer. |
| Root tool did not open | Look for a PolicyKit prompt behind the active window and verify the account can authorize administrative actions. |
| Dock configuration looks different | Use the shipped Kodachi layout. Do not delete generated launchers individually because the next synchronization can restore the reviewed manifest. |
Continue to the GTK Control Center guide or return to Desktop Controls.