kodachi@faq:~$ cat /tools/faq

Case Files

265 investigated questions across eight dossiers: install, boot, editions, dashboard, AI, network, and security. Search every folder at once, jump to the most common issues, open a case for the full finding, and follow the cross-references. Verify anything against the documentation, ISO, and source before changing privacy settings.

249 total cases 8 dossiers verified vs docs / ISO / source Applies to the Kodachi line - Desktop / Terminal / Binary Pack Last updated 24 June 2026
[ 0.000000 ] mounting case archive ... [ ok ] [ 0.000041 ] indexed 265 answers across 8 folders ... [ ok ]
Verify ISOOpen the integrity answer before installing. LUKS nukeUse the correct installer path for boot-time nuke. DNS repairFix resolver issues without blindly dropping tunnels. Threat modelNo tool guarantees absolute anonymity by itself.
triage
// pinned dossier

Most common issues

surfaced by the cases people open most
01Getting Started26 cases
What Kodachi is, the threat model, trust, and which edition to pick

On first boot you reach the Kodachi-branded LightDM login (default credentials kodachi / Security4All; use the greeter's keyboard/language selector first if needed), then the dark XFCE desktop loads with the Conky real-time system monitor. The Kodachi Dashboard then auto-launches and shows a welcome screen for terms acceptance, dashboard mode selection (Circle, Lite Classic, Vitals, SOC or ColonyOps), optional startup privacy settings and network detection, and it offers AutoShield as the guided first-boot setup route. Automatic first-boot operations include binary deployment verification, DNSCrypt auto-configuration, online authentication, system status collection and Conky initialization. AutoShield is the Dashboard's countdown-driven setup wizard, not a separately launched program.

Yes. Every Kodachi security service is a standalone CLI-first Rust binary, so the full suite works headless with no dashboard. The Kodachi Terminal Server edition is terminal-only by design (no GUI at all), built for hardened servers and headless deployments, and exposes the same binaries (health-control, tor-switch, dns-switch, routing-switch, workflow-manager, and more) directly from the command line.

Yes. On the desktop edition the "Kodachi Rofi Actions" menu gives keyboard-driven access to security operations, network controls, services, and utilities without using the mouse. The launcher is bound to Ctrl+K (it runs /usr/local/bin/kodachi-rofi-actions). The broader application/rofi launcher is also bound to Super+R, Alt+F1, Alt+F3, Ctrl+Escape, and a tap of the left Super key. On the Terminal edition everything is driven from the shell.

It is a set of keyboard-driven Rofi menus installed to /usr/local/lib/kodachi-rofi/. The Actions menu is the primary dispatcher and opens sub-menus: Favorites (quick-launch tools), Network (VPN connect/disconnect, Tor toggle, DNS switching, routing mode), Services (start/stop/status for Tor, DNSCrypt, firewall), and Utilities (cleanup, MAC randomization, hostname change, panic triggers). Launch it with Ctrl+K.

Yes. On first login the AutoShield welcome script detects whether DNSCrypt has been configured (via a marker file), and if not it auto-configures encrypted DNS, retrying up to 3 times with short delays. It writes a marker so it does not reconfigure on later logins, and it auto-recovers if systemd-resolved hijacks DNS. You can force reconfiguration with:

sudo kodachi-autoshield.sh --force-dns-setup

Yes. Kodachi delivers a fully prepared, hardened environment with built-in privacy tools ready from the very first boot. On the Desktop edition the Kodachi Dashboard auto-launches at login and presents AutoShield, its guided first-boot wizard, which runs a multi-step security hardening sequence; you can re-open it any time from the dashboard header. The overview describes Kodachi as providing out of the box what would take most users months of setup to build correctly.

Yes. Kodachi ships KAICS (an 8-binary plain-English CLI) and an ai-gateway for policy-firewalled agent execution. It exposes 9 named engine paths: TF-IDF, ONNX intent classifier, ONNX semantic, Mistral.rs, GenAI/Ollama, legacy local LLM, Claude CLI, Codex CLI, and OpenCode. Local engines run on-device; a configured external provider can receive prompts and context even when its traffic uses VPN or Tor. On Desktop, the AI Chat button is available in the Circle and Lite Classic dashboards to explain commands or suggest sequences without leaving your tab.

Kodachi provides 25 auto-documented, command-bearing Rust binaries registered as 26 CLI services, plus bundled companion runtimes, covering routing, Tor, DNS, integrity, host security monitoring, health/emergency control, authentication and a local AI stack. On Desktop the Kodachi dashboard orchestrates 575 generated commands with no GUI freezing. The Terminal edition ships the same 29 signed binary files in /opt/kodachi/dashboard/hooks/ (21 core + 8 AI); with the signed host-exposure-defaults.json policy file, the trust set contains 30 signed artifacts. The Conky telemetry display itself is a Desktop add-on.

No. Kodachi is a hardened privacy and security operating system, not a standalone VPN provider. A VPN is only one component; Kodachi also bundles Tor routing, DNS leak protection, anti-forensics tools, multiple tunneling protocols, and hardened defaults. The docs explicitly say it should not be compared to a normal VPN subscription because it is an integrated OS-level stack rather than a single tunnel service.

Kodachi is a Debian 13-based distribution shipping multiple VPN protocols and explicit route recovery controls, Tor routing, DNS protection, encrypted crypto wallets, full-disk encryption utilities, a hardened browser, and an integrated dashboard, all working from first boot. The stated value is delivering out of the box what would otherwise take most users months of manual setup and trial-and-error to assemble and harden correctly.

Choose Desktop (full XFCE on Debian 13, ~5GB) for daily privacy-focused computing with a GUI. Choose Terminal (minimal live ISO, 2.4GB, Debian 13) for testing the toolchain, headless privacy deployments, or running a dedicated SOCKS proxy gateway on old hardware or a VM. Choose the Binary Suite to run the signed Rust binaries on an existing Debian-based system. All are free for personal use and share the same underlying privacy stack.

Use a non-persistent live USB or a VM such as VMware, VirtualBox, or QEMU. Live mode does not save session changes to the live medium by default, and local disks are not intentionally mounted or written unless you or a tool does so. A VM adds an isolation boundary but is not zero-risk, especially with shared folders, passed-through devices, or bridged networking. Take a VM snapshot before experimenting so you can roll back.

If you are new, start inside a virtual machine rather than on bare metal. Boot one VM from the live ISO and, if useful, install another into its own virtual disk. Take a VM snapshot before experimenting so you can roll back. This reduces risk to the host, but it is not zero-risk: hypervisor defects and enabled shared folders, device passthrough, clipboard integration, or bridged networking can cross the isolation boundary. Install on a physical drive only if you need Kodachi as a daily-driver OS. See safe testing boundaries and supported run methods.

Kodachi's system scripts and configuration are published under the Kodachi Source-Available Noncommercial License v1.1 (KSAN-1.1) and can be read and audited subject to that license; the Kodachi-authored binaries are closed and ship as signed builds. The 29 signed binary files, ISO, and binary tarball are cryptographically signed with a published public key. The currently published signed warrant canary is dated 2025-02-21. Kodachi is built by a named maintainer, Warith Al Maawali (digi77.com), the same person since 2013, and is independently tracked on DistroWatch.

Kodachi is provided for legitimate privacy protection, security research, and educational purposes only and must not be used for illegal or criminal activities. Users are solely responsible for compliance with all applicable laws in their jurisdiction, and the developers disclaim all liability for misuse. Anyone intending unlawful use is told to discontinue use immediately.

No tool guarantees absolute anonymity. Kodachi gives a strong integrated stack (VPN, Tor, proxies, DNS controls, anti-leak enforcement) and hardened defaults from first boot, but real anonymity still depends on your configuration and behavior - which routing mode you select and your OPSEC. The docs frame it as giving real control and protection and teaching better habits, not as automatic, absolute anonymity.

No. The free tier uses the same binaries, the same OS-level hardened stack, and the same updates as the paid plans. The only differences are backend infrastructure quality, commercial usage rights, and priority support - not the software or its security capabilities.

Kodachi does not require conventional account fields such as your name, email, or phone number for authentication. That is different from collecting no data. Service operation processes a derived device identifier, session and client-version data, and network metadata such as current or previous IP addresses for authentication and security events. Web requests also reach Apache access logs, which the current operations code documents as rotating within hours, while service-delivery records can persist for operational purposes. These limits reduce directly identifying account data, but they do not make the service metadata-free. See also the authentication privacy boundary.

Authentication unlocks Kodachi's service-backed features: the built-in VPN nodes, proxy pool, encrypted DNS, and other cloud-assisted tools. You do not log in by hand; the dashboard signs in automatically as it loads, with no username or password to type.

It separates free from premium access and limits abuse so shared nodes remain usable. It requires no Kodachi account fields such as email, phone number, or name. That reduces directly identifying account data, but the service still processes a derived device identifier and can observe request, session, and network metadata. Authentication therefore controls access without a conventional personal account; it does not by itself prove anonymity (see is authentication tracking me).

Authentication distinguishes paid from free users, limits abuse, and protects shared infrastructure. It asks for no Kodachi account fields such as email or phone. That reduces directly identifying account data, but it does not prove anonymity: the authentication endpoint can still observe request, session, and network metadata. The OS itself runs without authorizing, but service-backed features will not fully work until authentication succeeds; it is an anti-abuse access gate, not a guarantee that no metadata exists.

In part. The system scripts and configuration are published under the Kodachi Source-Available Noncommercial License v1.1 (KSAN-1.1), rather than an OSI-approved open-source license; the Kodachi-authored binaries are closed and ship as signed builds. Published code is available at https://github.com/WMAL/kodachios. The full source of versions prior to v9 is public, including Kodachi 8.27 and the full dashboard source, and the Kodachi Bash scripts shipped in the ISO are hosted in the same repository.

Study the published code and its history on GitHub at https://github.com/WMAL/kodachios. The full source of pre-v9 releases such as Kodachi 8.27 and the complete dashboard source are there, and the project publishes source after major changes so you can trace how the system evolved across versions. The Kodachi bash scripts bundled in the ISO are also hosted in that repository, so you can read exactly what runs at boot and during setup.

Kodachi is created and maintained by Warith Al Maawali, an independent security engineer who has developed it as a one-person project under the same name since 2013. He builds it openly under his real identity rather than as an anonymous team, and also runs digi77.com. You can see who he is and follow the work directly on LinkedIn at https://om.linkedin.com/in/warith1977 and on X (Twitter) at https://x.com/warith2020, and the full project history is on GitHub at https://github.com/WMAL/kodachios.

Yes. Kodachi publishes a signed warrant canary at /tools/warrant.html. The currently published signed statement is dated 2025-02-21; it has not been refreshed since that date. Verify its OpenPGP signature and treat its age, any wording change, or a missing update as information when assessing the canary. It is part of Kodachi's transparency model alongside the KSAN-1.1 published scripts and configuration and cryptographically signed releases.

It is a short, plain-language agreement, not data collection and not registration. Nothing is sent anywhere; accepting it only writes a local acceptance file. Its real purpose is to protect the developer, and that protection matters precisely because Kodachi is not run by an anonymous team. Most privacy projects hide behind pseudonyms. Kodachi is built openly by Warith Al Maawali under his real identity, which is exactly what lets you verify and trust who is behind it. The trade-off of using a real name is real exposure: if someone uses Kodachi to commit a crime, the author could be wrongly dragged into it. The terms make the boundary explicit. They state that Kodachi's purpose is to protect privacy, that it must not be used for illegal activity, that you should stop immediately if your intent is unlawful, that the developer disclaims all liability for any illegal actions committed by users, that you agree to use it responsibly and legally, that your own data security remains your responsibility, that the software is provided as-is with no warranties, and that the terms may be updated so you should review them. In short, the acknowledgement exists so every user understands that responsibility for how Kodachi is used rests with the user, not with the person who chose to put his real name on a privacy tool.

Linux Kodachi is now known as Kodachi OS. Older documentation, downloads, and archived material may still use the previous name, so both names still appear across older pages, articles, file names and forum posts. They refer to the same project.

Only the presentation changed. It is the same maintainer and the same project, developed continuously since 2013. Files already published, such as linux-kodachi-xfce-9.0.1-amd64.iso, keep their original names so existing checksums, signatures and download links stay valid; the new naming applies to future releases.

No matching case files

Try a different keyword, or browse the full documentation.

Before reporting a bug

Please include all of the following so the issue can actually be reproduced:

Didn't find your answer?

The full per-tool guides and CLI reference cover every command in depth.