Backport of the docker group removal (PR #8056, merged to quattro as b5ded31e)
onto the v4-0-1 release branch.
The docker group is root-equivalent: anything in it can docker run -v /:/host
and rewrite the host as root with no password. On a single-user box that is not
an escalation -- the owner is already a wheel user -- but it hands any code
running as the user, a rogue plugin or a poisoned dependency, a silent,
headless, passwordless path to root that sudo's password prompt would otherwise
gate.
Stop granting the group by default. The daemon still runs, the Docker TUI and
the Windows VM reach it through a polkit prompt, and the plain docker CLI runs
under sudo. Sudoless Docker becomes a warned opt-in under Setup > Security, and
no automatic path re-grants it: install and first-boot provisioning never record
or apply the group, and the Quattro upgrade no longer adds it. A migration takes
existing installs out of the group, reusing omarchy-remove-security-sudoless-
docker so the change and its notice have one source of truth.
The Windows VM keeps needing the root daemon for a privileged container, so it
runs without the group without becoming a new way in: the compose moves to a
root-owned directory written only by an elevated, input-validated writer, volume
paths are rebuilt from $HOME on migration rather than trusted from the
user-writable legacy file, the privileged sub-action is checked against an
allowlist before dispatch, pkexec elevates a verified root-owned command path,
mount sources are refused when they are or resolve through a symlink, and the
guest password moves to a private 0600 per-user file instead of a
world-readable compose. Existing installs auto-migrate the VM without a
redownload.
Two files had diverged from quattro and were resolved by hand:
bin/omarchy-windows-vm -- v4-0-1 still carries the "Starting Windows VM" toast
that #7585 dropped on quattro, and the new start path has no user-side status
check to hang it on: after this change the user cannot inspect the container
without privilege, which is the whole point. Took quattro's version. #7585's
reason holds here too -- the shell shows its own "Launching Windows…" OSD until
the RDP window appears (shell/services/AppLibrary.qml) -- and the failure
notification stays. The file is now byte-identical to quattro.
manual/28-windows-vm.md -- took the new paragraph on the root-owned compose,
without the neighbouring OEM-key paragraph, which documents omarchy windows key,
a command quattro has and this branch does not.
test/shell passes here: 186 files, including the three this adds.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DEMYa9UWtroz93DhMTtcV
3.7 KiB
Development Tools
Alternative Editors
Omarchy ships with Neovim by default, but if you'd like something a bit more mainstream and familiar, you can run the Omarchy Menu (Super + Space) and see the options under Install > Editor. We have VSCode, Cursor, Zed, Sublime Text, Helix, Vim, and Emacs listed there. If you don't find what you're looking for, checkout Install > Package, and see if it isn't in an Arch package (and if not, try Install > AUR to check the AUR).
Theme matching is offered for VSCode, Cursor, VSCodium, and Helix.
You can set the system-wide default editor under Setup > Defaults > Editor.
Environment
Omarchy supports setting up a whole host of development environments through the Install > Development section of the Omarchy Menu (Super + Space). You'll of course find Ruby on Rails, but also all three major runtimes for JavaScript (Node.js, Bun, Deno), as well as popular PHP frameworks like Laravel and Symfony. Oh, and there's Go, Rust, Python, Java, Elixir (with Phoenix), .NET, OCaml, Zig, Clojure, and Scala too. It's a very broad selection!
The majority of these environments are managed by Mise. It's a tool that lets you install and run multiple versions of a programming language on the same machine. It's like rbenv or rvm for Ruby or virtualenv for Python, but it works for a bunch of different environments.
To install, say, Ruby, you'd run mise use -g ruby, which will both install Ruby and set it as the global default. Or, if your project has a .ruby-version file, you can just run mise i in the root of that project.
Docker
Docker hardly needs any introduction. It allows you to run isolated containers, and Omarchy installs everything needed to run it well, including Docker itself and Docker Compose.
By default your user is not in the docker group. That group is effectively passwordless root — anything in it can docker run -v /:/host and take over the machine — so a single rogue script or dependency running as you would otherwise be one command away from root. So on the command line you run Docker with sudo (sudo docker ps, sudo docker compose up), and the graphical tools that talk to the daemon — the Docker TUI on Super + Shift + D and the Windows VM — ask for authorization when they need it. If you want the convenience of a groupless setup back and understand the tradeoff, enable it from Setup > Security > Sudoless Docker (or run omarchy-setup-security-sudoless-docker), which adds you to the docker group after a warning; then plain docker and the d alias work without sudo again.
Remember to checkout the Lazydocker command to manage your containers in a cool TUI using Super + Shift + D; it asks for authorization the first time unless you have enabled sudoless Docker.
You can setup the common databases for local development in Docker using Install > Development > Docker DB in the Omarchy menu.
GitHub CLI
The GitHub CLI let's you authenticate with your GitHub account and clone private repositories using it. It's wired up as one of the lazy-loading mise stubs, so the first time you run gh, it installs itself. To authenticate, run gh auth login. Then you can checkout private repositories using gh repo clone org/repo.
You can also perform a bunch of other GitHub operations using this command. Just run gh to see everything that's possible.
There's a lazy-installing stub for ghui for managing your pull requests in a TUI too. And lazygit is preinstalled, if you'd like to drive git itself from a TUI as well.