bootc Architecture & Read-Only Root
Technical deep-dive into OCI container-based OS delivery and OSTree transactional commits
bootc Container Architecture
bootc (Bootable Containers) unifies desktop and edge workstation deployment with cloud-native infrastructure tooling. The complete base operating system is built, signed, and distributed as an OCI container image.
┌────────────────────────────────────────────────────────┐
│ Enterprise Desktop Layer (KDE Plasma) │
├────────────────────────────────────────────────────────┤
│ Application Runtimes (Flatpak / Distrobox / Waydroid) │
├────────────────────────────────────────────────────────┤
│ Immutable Read-Only Root (/usr, /lib) │
├────────────────────────────────────────────────────────┤
│ OSTree / bootc Transactional Deployments │
├────────────────────────────────────────────────────────┤
│ Linux Kernel & Base Hardware │
└────────────────────────────────────────────────────────┘
How the Read-Only Filesystem Works
- Sensitive system directories (
/usr,/lib,/bin) are read-only mounts. - Host configuration in
/etcis managed with a 3-way merge during upgrades, preserving local administrator customizations. - Persistent user data is stored safely in
/home, and application databases/containers reside in/var.
Basic bootc Administration Commands
# Check current boot status and deployment queue
sudo bootc status
# Check for new image updates in the upstream registry
sudo bootc upgrade --check
# Stage and apply an update
sudo bootc upgrade