Maze Linux is a security- and privacy-focused Linux distribution built on Arch Linux. It ships a complete, hardened KDE Plasma 6 desktop on Wayland that works immediately after installation — with security tools, privacy software, and a local AI runtime already configured and enabled.
Maze targets users who want the power of Arch Linux without the manual setup required to harden and configure it. Basic Linux familiarity (terminal usage, understanding of packages) is helpful, but you do not need to know how to configure AppArmor or write firewall rules — everything is done for you.
If you are brand new to Linux, Maze is more approachable than vanilla Arch, but less hand-holding than Ubuntu or Fedora. The After Install page walks you through the first steps.
Yes. Maze uses the official Arch Linux package repositories and the rolling release model. Every package from the standard Arch repos is available. The AUR is accessible via paru.
No. Maze uses pacman (Arch's package manager) and paru (AUR helper). You can also use Flatpak for sandboxed apps. There is no separate Maze package manager.
Yes. Unlike many distributions that ship a stripped-down live environment, the Maze live ISO runs the full desktop with all apps and services. You can try everything — including Ollama, Maze Guard, and the security tools — before committing to an install.
Mostly. The core system installs offline — everything it needs is on the ISO.
Two things do reach out during installation: paru (built from source) and
ONLYOFFICE (~350 MB from the AUR). Without a connection the install still
completes; run maze-aur-setup after first boot to finish them.
Broadcom Wi-Fi cards require the broadcom-wl driver. It is included on the ISO. Open Konsole and run:
sudo modprobe wl
For Intel Wi-Fi, the firmware is included via linux-firmware. If your card is still not detected, run lspci | grep -i net to identify your hardware.
Maze is designed to run with Secure Boot enabled — you should not need to turn it off.
Maze generates a signing key unique to your machine and seals the kernel, initramfs and command line into a signed Unified Kernel Image. On the first reboot after installation, your firmware asks you to approve that key once, on a blue MOK Management screen. That screen is expected — see First Boot / MOK.
If the installed system still will not start with Secure Boot on, run
sudo maze-boot-check (from the recovery kernel if necessary); it
checks the whole chain and --repair fixes what it finds.
Check the installer log:
cat /var/log/Calamares.log
journalctl -xe
Open an issue on the Maze Linux GitHub with the log content.
Yes. Choose Manual Partitioning in the installer, leave the Windows EFI and C: partitions untouched, and install Maze to a separate partition or drive.
Maze does not install a boot menu that lists Windows — it boots its own signed image directly. Pick the OS from your firmware boot menu (usually F12 or Esc at POST), or set the default there.
You do not need to disable Secure Boot. Maze supports it and enables it by default — see Secure Boot.
sudo pacman -Syu
Run this regularly. To include AUR packages:
paru -Syu
A btrfs snapshot is taken automatically before and after every pacman
transaction, so you can see exactly what changed and undo it:
sudo snapper -c root status 42..0 # what changed
sudo snapper -c root undochange 42..0 # undo it
Don't use undochange across a kernel update — the kernel image is not in the
snapshot. sudo maze-rollback returns the whole system to a snapshot, but is not
yet reliable on every machine — see Snapshots & Rollback.
If the machine will not boot at all, use the recovery kernel: Won't Boot?
You can also downgrade a single package from the pacman cache:
sudo pacman -U /var/cache/pacman/pkg/<package-old-version>.pkg.tar.zst
Use the AUR with paru:
paru -S <package-name>
Or use Flatpak for sandboxed apps:
flatpak install flathub <app-id>
Two different places, and they are easy to confuse:
1. [mazelinux] — the online Maze repository
https://mazerepo.berkkucukk.com.tr/packages, configured in /etc/pacman.conf
and signed against mazelinux-keyring. This is where Maze's own applications
live and update from: entropy-shield, qlam, haze, hazedrop, maze-ai,
maze-connect, maze-cloak, maze-guard and friends.
2. localrepo — prebuilt packages baked into the ISO
A small set compiled before the ISO was built, so installation works offline:
calamares, claude-code, joplin-bin, obfs4proxy, session-desktop-bin,
shim-signed, upscayl-bin. That is the complete list.
Brave, Mullvad Browser and Mullvad VPN are not in either repository and are not installed by default.
Yes. AppArmor, the firewall, auditd, and MAC randomization are all active from first boot. Maze Guard autostarts on the desktop.
Yes. You are in full control:
sudo systemctl disable --now apparmor # disable and stop
sudo systemctl stop maze-guardd # stop without disabling
The Maze Control Center shows all services and gives you copyable commands to manage them.
No. The SSH server is installed but not enabled by default. Enable it only when you need it:
sudo systemctl enable --now sshd
Disable again when not in use:
sudo systemctl disable --now sshd
Open QLAM from the application menu for a graphical scan, or use the command line:
sudo freshclam # update definitions first
sudo clamscan -r /home/yourusername
Yes — by Maze Cloak (maze-cloak.service), not macchanger. It randomises
the address while scanning for networks, uses a different address per network
you join, and can rotate on a schedule. It pauses while a VPN is up so a
rotation cannot drop your tunnel.
systemctl status maze-cloak
No. The Maze Firefox profile disables all telemetry, crash reporting, data collection, Pocket, sponsored content, and Studies. This is set in the default profile and requires no manual configuration.
Use Tor Browser (torbrowser-launcher) for maximum anonymity. It routes all traffic through the Tor network and is pre-hardened against fingerprinting.
For everyday private browsing, Firefox with the Maze hardened profile and DNS-over-HTTPS is a good baseline.
For a VPN, install and configure ProtonVPN or import a WireGuard configuration file.
Ollama is already running as a systemd service. Just pull a model and start chatting:
ollama pull llama3
ollama run llama3
Or use linux-chan-ai for a terminal UI that manages models and chat in one place. No account, no cloud, no data sharing required.
Yes — once downloaded, models run entirely locally with no internet connection needed. The initial ollama pull requires internet to download the model weights.
Use a smaller model. phi3 (~2.3 GB) runs well on 8 GB RAM. llama3 (~4.7 GB) needs at least 8 GB with other apps closed, ideally 16 GB.
Maze ships with zram (compressed RAM swap), which helps when you approach your memory limit. Check memory usage with btop.
Yes, automatically when a compatible GPU is present. For Nvidia (CUDA):
sudo pacman -S nvidia nvidia-utils
For AMD, GPU acceleration requires ROCm 6.1+. Older AMD GPUs fall back to CPU inference automatically.
Yes. Go to System Settings → Appearance → Global Theme. The Maze OLED theme is the default. You can install and apply any KDE Plasma theme.
Switching Global Theme from System Settings may reset the panel layout. If this happens, log out and back in — the Maze skel defaults are applied on first login.
Right-click the desktop or panel → Add Widgets. The Maze panel includes a system monitor, network speed, weather, thermal monitor, clock, and app launcher by default.
| Arch Linux | Maze Linux |
|---|---|
| Text-only installer | Graphical installer (Calamares) |
| No GUI after install | Full KDE Plasma desktop |
| You configure security | Security stack pre-enabled |
| You set up privacy | Privacy tools pre-configured |
| No AI tooling | Ollama + AI utilities |
| No branding | Maze OLED theme, Plymouth splash, signed boot chain |
The underlying system is identical: same packages, same package manager, same AUR. Maze is Arch with all the assembly done for you.
No. That is the one-time security key approval. See First Boot / MOK.
No. Maze is designed to run with Secure Boot enabled.
No. A default install sends nothing — no telemetry, no usage statistics. The built-in Maze AI runs models locally via Ollama. The two optional apps that can reach the cloud (SentinAI, Linux Chan AI) are not installed by default and warn you on first use. See Privacy Reference.
Every update takes a snapshot and verifies the boot chain before you shut down. If it will not boot, start the recovery kernel — see Won't Boot?.
No. Maze is UEFI-only; the security chain depends on it.
Not by default. You can add the BlackArch repository:
sudo maze-enable-blackarch
Most likely a hardware kill switch is enabled. Run sudo maze-doctor — it says
so explicitly. See Kill Switches.
Open an issue on the Maze Linux GitHub repository. Include:
cat /etc/os-release)journalctl -xe, /var/log/Calamares.log, maze-doctor, etc.)The Maze Linux source is on GitHub. Pull requests, bug reports, wiki contributions, and testing on real hardware are all welcome.