Back to Freedom.Tech Back
All StartOS releasesAll versions
Release Mon, Jul 27, 2026 4 min read

StartOS start-os/v0.4.0.1

Original release notes

Release notes

# StartOS v0.4.0.1

v0.4.0 is a complete rewrite of StartOS. After six years of building, we believe we have arrived at the correct architecture and foundation to deliver on the promise of sovereign computing.

⚠️ Before You Update

0.4.0 is finally out of public beta! However, the only way to update is by following the 0.4.0 Update Guide precisely. This is a sensitive update between two essentially distinct operating systems — skipping steps or improvising can result in data loss.

👉 Read the full update guide before proceeding

If anything goes wrong, stop and contact support — do not attempt to troubleshoot on your own.

Highlights

  • Redesigned UI — faster, more intuitive, mobile-friendly, with a real-time system metrics dashboard
  • Completely new networking stack — LAN port forwarding, Wireguard VPN gateways, private and public domains (clearnet), Let's Encrypt, built-in DNS, and Tor as an optional plugin
  • StartTunnel — free, open-source reverse tunnel to expose services on a public domain without revealing your home IP
  • LXC container runtime — replacing Docker/Podman with a reliable, nested container architecture supporting hardware acceleration and multi-container setups
  • Improved backups — differential backups, cross-server restore, and a new FUSE module for cross-platform reliability
  • Internationalization — multiple languages and keyboard layouts for StartOS and services
  • TypeScript SDK — build and ship a StartOS package in minutes
  • New S9PK format — signature verification, partial downloads, and multi-architecture support
  • SMTP notifications — email alerts from StartOS and services via Gmail, SES, or any SMTP provider

Important

Previous backups are incompatible with v0.4.0. After updating, immediately update all services and create a fresh backup.

What's Changed

Changed

  • **A service that serves its own TLS certificate now reports its external port

as an SSL port, and StartOS serves it like one.** Every interface whose external port speaks TLS — whether StartOS terminates it or the service presents its own certificate — now carries that port in assignedSslPort, and assignedPort means a plaintext port. A self-TLS port is now answered by the StartOS SNI router, which pipes the raw TLS stream to the service with the client's address preserved, instead of a kernel port-forward — so every TLS-carrying port behaves uniformly, and a self-TLS service's domains are advertised on its preferred port (e.g. 443) exactly as when StartOS terminates TLS. This also means such a port accepts TLS connections only, and no longer relays UDP. The port number itself is unchanged, so existing addresses, bookmarks and router port-forwards keep working. Packages resolve a dependency's address with sdk.host.getBridgeAddress, which is correct under either arrangement; see Service-to-Service Networking.

  • The StartOS web interface holds ports 80 and 443. StartOS runs as root, so

its own interface is the one binding that may claim the privileged range, and it now does so through the same port allocator every service uses. HTTPS was already served on 443; the plaintext address — offered only over loopback and the service bridge — moves from a random high port to 80.

Fixed

  • Updating from 0.3.5.1 starts the Tor service it installs. Your existing

onion addresses come across with it and answer as soon as the update finishes, with nothing to start by hand.

  • **A service that fails to convert while migrating from 0.3.5.1 reports the

reason.** The v1→v2 package conversion raises a notification against that service carrying the error that stopped it, in the same form as an install failure — alongside the summary notification listing every service to re-install.

  • A service that is renamed during migration is recorded as migrated. Ghost,

Synapse, Monero, Nostr and Fedimint are installed under new ids on 0.4.0 (ghost-legacy, synapse-legacy, monerod-legacy, nostr-rs-relay and fedimint-guardian), and the migration looks each one up under the id it was installed as. These services complete their migration without appearing among the failures, and the failure list names services by ids that exist in the marketplace.

  • The over-the-air update to 0.4.0 boots on the Server Pure. The Server

Pure's PureBoot firmware reads the boot configuration itself rather than running GRUB, and it takes the kernel and initramfs paths literally. The update now writes those paths in the plain form PureBoot expects, so the server boots into 0.4.0 on the restart that applies the update.

  • A Server Pure applies its PureBoot firmware update. StartOS installs the

firmware image at the path it reads it from, so a Server Pure on an older PureBoot release updates its firmware on the next start.

  • Installing onto a pre-installed Raspberry Pi keeps the data pool you pick.

Selecting the data pool by partition path now preserves that choice through installation.

Image Downloads

OS Images Checksums

SHA-256

bdf95acaab3f8a31a8b497883bf6addb8c38d240a6e4b59e353dc279e8da5351  startos-0.4.0.1-fdb27c7_aarch64.iso
4de00f435b2f2efbf9934fd6a3fe792e45cfea55b12cb2085dbed17d157a0373  startos-0.4.0.1-fdb27c7_aarch64-nonfree.iso
4d4ae6ffe130667ad673f5e63f742d8ae97fb58086d4368013f3a393d03dc23e  startos-0.4.0.1-fdb27c7_aarch64-nvidia.iso
dc58a015435a5220d709f6f7a16dcae13aa4607ebc9a933fab8b8ccde47aa5d2  startos-0.4.0.1-fdb27c7_riscv64.iso
9d615ccda0716beb483dc107a6e08f5e3cb63d61d8d3ebfc6ea3d6513c09f270  startos-0.4.0.1-fdb27c7_riscv64-nonfree.iso
9f4f5ad4ece2dc349b0a7b6221b542b26112fe753657024487fc26ef6cf08072  startos-0.4.0.1-fdb27c7_x86_64.iso
37b63c86197150866809d34b5824ae22c5fc705d4f8dc9e9750b8fa23485441a  startos-0.4.0.1-fdb27c7_x86_64-nonfree.iso
894398ec7d99ee833290c0bc9998c6023af9e39b79a07bfe8ba26c519ba5bd1f  startos-0.4.0.1-fdb27c7_x86_64-nvidia.iso
e8c2521290c3c6acba14bc11e2c0ae66d7884af28947034efcd6d9129a7b52f1  startos-0.4.0.1-fdb27c7_raspberrypi.img
55ceb1891801e76419705d1f97d5bc5e4b00cb6c76b31a005876c5580e5dc8ee  startos-0.4.0.1-fdb27c7_raspberrypi.img.gz
ba0f41cd4c5652a7792a0e0d26112edd0c9aa7fefa27060d1325ffedbf2fb963  startos-0.4.0.1-fdb27c7_aarch64-nonfree.squashfs
1a445e9b37a4cbb751300903c975e09e2aa02116c6a1be3940931a1237ac