Maze Linux / Wiki

After Install

The first time you boot into your installed Maze Linux system, the Maze Welcome app opens automatically. It introduces key features and self-removes its autostart entry so it only appears once.


1. Maze Welcome App

The Welcome app launches on first boot and walks you through:

It will not appear again after you close it on first boot.


2. Update the System

sudo pacman -Syu

Maze uses Arch Linux's rolling release model. Updates are incremental and frequent — run this regularly.


3. Open Maze Control Center

The Maze Control Center is your central dashboard. Launch it from the application menu or run:

maze-control-center

It shows the live status of every security service, MAC randomization state, the Ollama AI runtime, and system maintenance info. Each action is displayed as a copyable terminal command — nothing runs without you explicitly executing it.


4. Check Security Services

All of the following are enabled and running from first boot. Confirm they are active:

systemctl status apparmor
systemctl status firewalld
systemctl status auditd

Maze Guard monitors the network you are connected to for MITM and ARP-spoofing attacks. It autostarts on the desktop.


5. Set Up Flatpak Apps (Optional)

Flathub is already configured as a Flatpak remote. Install additional apps from KDE Discover or the terminal:

flatpak install flathub <app-id>
flatpak update

6. AUR Access with paru

paru is the preinstalled AUR helper. Install any AUR package with:

paru -S <package-name>

paru searches both official repos and the AUR, compiles from source in an isolated environment, and installs the result.


7. Configure Firefox

Firefox ships with a hardened default profile:

No configuration needed — it is already private. To use a different DNS-over-HTTPS provider, go to Settings → Privacy & Security → DNS over HTTPS.


8. Set Up Ollama (Local AI)

Ollama is installed and starts on boot automatically. Pull your first model:

ollama pull llama3

Check the service status:

systemctl status ollama

See the AI & Development page for model recommendations and GPU acceleration details.


9. Encrypted DNS

Maze does not run a standalone DNSCrypt service. Encrypted DNS is one of the layers Entropy Shield turns on when you start it — together with its Tor transparent proxy and I2P options.

entropy-shield        # or launch it from the menu

Out of the box the resolver is systemd-resolved. See Privacy.


10. Firmware Updates

fwupd is preinstalled. Check for and install firmware updates:

fwupdmgr refresh
fwupdmgr update

11. Virtualization

Virtualization is not installed by default — this is deliberate, to keep the ISO lean. The whole KVM stack is one command away:

sudo pacman -S qemu-desktop libvirt virt-manager edk2-ovmf
sudo systemctl enable --now libvirtd
sudo usermod -aG libvirt,kvm "$USER"   # log out and back in

If you prefer VMware Workstation, Maze ships a helper that sets it up for you:

maze-install-vmware

12. Change the Default Shell (Optional)

Zsh with Oh My Zsh is the default shell. If you prefer bash:

chsh -s /bin/bash

Key Directories

PathPurpose
/etc/maze-installer/Installer config templates
/usr/local/bin/Maze custom scripts and tools
/usr/local/lib/maze/Maze Python libraries (maze_status, maze_ui)
/etc/sysctl.d/99-maze-hardening.confKernel hardening parameters
/etc/NetworkManager/conf.d/99-maze-cloak.confMaze Cloak NetworkManager rules