Linux · Authentication · Infrastructure · Open-source engineering
Building security-sensitive Linux integrations with a focus on safe failure modes, reproducible validation and operationally boring recovery paths.
Passwordless SDDM login with OIDC Device Authorization, WebAuthn/passkeys, a Native Qt6 login experience and a structurally preserved password fallback.
- Debian 13 · SDDM · KDE Plasma 6
- PAM · OIDC · WebAuthn · FIDO2
- Go · C · QML · systemd
- signed Debian packages, SBOMs and protected CI
Project website · Roadmap · Latest release
🖨️ BambuStudio
A maintained BambuStudio fork with its own project presentation, release workflow and development roadmap.
- secure Linux authentication and identity boundaries
- Debian packaging and release engineering
- OIDC, WebAuthn/passkeys and PAM integration
- Qt/QML desktop UX with deterministic visual regression
- infrastructure automation, CI hardening and recoverable operations
- authentication authority belongs in the authentication stack, not the UI
- recovery paths should be designed before the happy path ships
- unsupported states should fail explicitly rather than be guessed
- tests should include real infrastructure where mocks are not enough
- documentation, rollback and release verification are part of the product
Public repositories show the parts of the lab that are useful to share. Private infrastructure details stay private.




