A small, auditable Linux distribution and software ecosystem, built around native, self-hosted infrastructure.
Website · Downloads · Packages · Why Saphira? · Roadmap · Status
![]() Saphira — musl + OpenRC. The release line people run. |
![]() Saphira-d — musl + systemd. In development. |
A from-scratch Linux distribution. Not a respin of Debian, Ubuntu, Alpine or Arch.
| musl libc | A small, strict, standards-focused C library. Predictable behaviour, small binaries. |
| OpenRC | Dependency-based init and service management written in shell. Scripts and dependencies, no hidden state machine. |
| APK | Fast, atomic package management with signed indexes and strong package boundaries. |
| Linux + GRUB | An ordinary upstream kernel and an ordinary, inspectable bootloader. |
| x86-64-v3 | The modern default baseline: CPUs from roughly 2015 onwards, AVX2 class. Not for every ancient x86-64 chip. |
It is built in stages from source, so you can follow it from toolchain to boot to service startup without the machine disappearing behind layers of machinery:
Stage0 bootstrap toolchain → Stage1 native toolchain → Stage2 root filesystem → Stage3 base build image → Stage4 packages and image generation. Every input is pinned and hash-verified. No floating upstream tarballs. Images are booted and exercised before publication.
We build software to run because it is useful, understandable and under your control.
Saphira Linux Earlybird Beta — a real beta, marked pre-release. Not the full release.
- Released 15 August 2026, shipped with GCC 16.1.0
- The development tree is migrating to GCC 16.2.0 before a clean full rebuild
- 481 APK packages in the release repository, signed indexes, served over TLS
- QCOW2 disk image for KVM/QEMU, distributed as an xz-compressed tar archive with a published SHA-256
- Live numbers are on the status page — we do not put vanity counters on this page
# /etc/apk/repositories
https://packages.akadata.ltd/saphira/mainapk update
apk search nginx
apk add nginxKVM/QEMU with VirtIO disk and network is the primary tested target. Xen, VMware and VirtualBox are expected to work where VirtIO devices are available. None are certified.
https://saphira.vm2.uk/ is not a demonstration environment. It is the
distribution doing a real job — a real Node.js SSR application on musl, managed
by OpenRC, installed from the same APK repository you can use.
$ curl -sI https://saphira.vm2.uk/ | grep -iE '^(server|x-(powered|saved|hosted|designed)-by)'
Server: Saphira Linux
X-Powered-By: Saphira the Dragon
X-Saved-By: Grace
X-Hosted-By: AKADATA LIMITED
X-Designed-By: AKADATA LIMITEDEverything below is public and clonable today.
| Repository | Language | What it is |
|---|---|---|
recipes |
Shell | Every Saphira-written package publishes its recipe.sh in the open. No hidden sources, no archives. |
saphira-llm |
C | Native C11 CPU inference runtime for BitNet b1.58 GGUF models. MIT licensed. |
saphira-tokenizer |
C, Rust | Exact, portable LLM tokenization with cross-checked Rust and C implementations and deterministic token IDs. |
saphira-sjev-c |
C | Native implementation of the SJEV decision and reranking model, with trainer, runtime and reproducible experiments. |
The Saphira Linux distribution source itself is not public yet. We would rather say so here than imply otherwise.
Feature families for software running on infrastructure you control.
| mailDragon | Self-hosted Postfix, Dovecot, Rspamd, ClamAV and Roundcube. Operated from the shell, not a dashboard. |
| webDragon | The nginx, PHP-FPM and Node.js layout, plus site and TLS certificate workflows. |
| dnsDragon | Authoritative BIND 9 and DNSSEC: zones, records and the delegation chain of trust. |
| vpnDragon | WireGuard on your own infrastructure, from one client to routed IPv6 networks. |
| aiDragon | An agent-friendly Saphira workspace: OpenCode, Codex, Claude Code, MCP tools and persistent project context. |
| databaseDragon | SQLite, MariaDB and PostgreSQL, with SQL permissions and nftables exposure explained together. |
Not a replacement, a question. A musl + systemd sibling with its own build tree, so an init experiment cannot silently redefine the distribution people already run. It is the non-usr-merged edition, keeping the traditional filesystem layout and proper FHS support.
It booted systemd 261.2 under systemd-nspawn on 24 August 2026 and reached
graphical.target. systemd-logind failed on that first boot and the systemd
packages are still awaiting signing. It is not a complete distribution. The
systemd packages and their musl dependency chain — Linux-PAM, libxcrypt,
libucontext, Jinja2, MarkupSafe, libmnl, libbpf — are built from source.
- Open protocols
- Self-hosted where practical
- Minimal dependencies
- Evidence before claims
- IPv6 first-class
- Native software rather than SaaS dependency
We publish SVE (Saphira Vulnerability Entry) records for defects with security, reliability or operational significance in Saphira-developed software. An SVE is not a CVE — it is our own public record, and the first entry, SVE-2026-0001, is the proxyto idle-child defect: what was observed, what it affected, how it was reproduced, how it was fixed.
- Website — https://saphira.vm2.uk/
- Package repository — https://packages.akadata.ltd/saphira/main/
- Checksums — https://saphira.vm2.uk/checksums
- Gopher —
gopher://saphira.vm2.uk/— no pictures, no noise, just the words - Brand assets —
SaphiraLinux/brand— logo and dragon artwork, CC BY 4.0 - Vendor — AKADATA
Made in England. British software. Free software.
Saphira remains free, including commercial use. No subscription, no rental licence, no compulsory SaaS. Run a business on it, host customers on it, sell services that run on it — none of that costs a licence fee.
Code AKADATA wrote specifically for Saphira is BSL-1.1, with each released version transitioning to GPL-2.0-or-later four years after release, so it cannot be lifted out and rebadged into somebody else's commercial product without talking to us first. Previously released MIT versions remain MIT, and upstream software keeps its upstream licence.

